July 2016 Quarterly Update from Oracle (276 vulnerabilities patched)

Uncategorized
   Oracle Patches 276 Vulnerabilities with July 2016 Update, including 13 for JavaSE Oracle's official update cycle is quarterly (unofficially, it's been as frequently as daily at times, before Adobe Flash stepped up to the plate as the target du jour for attackers) and the updates for July have just been published.  For most of our customers, the primary impact is JavaSE (which we'll discuss in more detail below) but updates were also released for most everything in the Oracle fleet.  There's a good write-up on ThreatPost here.   Java - The latest version of Java is 8 update 101 and patches 13 vulnerabilities, 9 of which are remotely exploitable without authentication.  If you have JavaSE installed and it is not the latest version (or if you have multiple versions installed),…
Read More

July 2016 News and Updates

Monthly Newsletters, Uncategorized
   What's New Windows 10 - Microsoft's aggressive push to get every Windows 7 and Windows 8 computer upgraded to Windows 10 has gone from light speed to ludicrous speed.  Per Microsoft, Windows 7 is still supported until January of 2020 and we have had very good results with the Never10 utility from GRC.  If you have Windows 8, Windows 10 may be a better option.  Otherwise, it may be worth delaying the Windows 10 upgrade. DEF CON 24 - Piratica has invited the crew from Cyber Tech Cafe to join them at DEF CON 24 this year (4 August to 7 August) in Las Vegas.  Most of us will be leaving Thursday evening but we will be leaving a skeleton crew behind Friday and Monday to cover things.  Everyone will…
Read More

June 2016 News and Updates

Monthly Newsletters, Uncategorized
   What's New Windows 10 - Microsoft's aggressive push to get every Windows 7 and Windows 8 computer upgraded to Windows 10 has gone from light speed to ludicrous speed.  Per Microsoft, Windows 7 is still supported until January of 2020 and we have had very good results with the Never10 utility from GRC.  If you have Windows 8, Windows 10 may be a better option.  Otherwise, it may be worth delaying the Windows 10 upgrade. Helpdesk Changes - We are excited to announce that the changes that we mentioned a few months ago to the Cyber Tech Cafe helpdesk are going well.  If all goes well, we should have some exciting news in the next 10 to 14 days. DEF CON 24 - Piratica has invited the crew from Cyber…
Read More

Beware, Windows 10 updates now apparently being installed with or without permission

Uncategorized
We are seeing a disturbing trend of Windows 7 computers being involuntarily upgraded to Windows 10 and even trying to trick users into installing Windows 10 by using the red "X" button at the top right of the screen (historically used to close a window with no action but frequently abused by viruses and other malware to confirm an install), documented here by BBC.   Windows 7 is still supported by Microsoft until 14 January 2020, documented here on the Microsoft website. Windows 10 is a significant change from previous versions ('rolling' updates, new user interface and [not the least] privacy concerns) Like any major upgrade, the upgrade to Windows 10 is not flawless or error free and could cause downtime or compatibility problems with hardware and software not designed…
Read More

May 2016 News and Updates

Monthly Newsletters, Uncategorized
   What's New DEF CON 24 - Piratica has invited the crew from Cyber Tech Cafe to join them at DEF CON 24 this year (4 August to 7 August) in Las Vegas.  Most of us will be leaving Thursday evening but we will be leaving a skeleton crew behind Friday to cover things.  Everyone will be back for normal business hours Monday. Updates Executive Summary - May delivered several updates from Microsoft to patch critical vulnerabilities in Windows, Internet Explorer, Edge, Office and .NET.  I've noticed it a few times and more frequently lately, but MS16-064 was an update to Adobe Flash Player for Windows 8.1, Server 2012, Server 2012 R2, RT 8.1 and Windows 10.  Two important things to note here is that Microsoft is issuing Flash Player updates…
Read More

April 2016 News and Updates

Monthly Newsletters, Uncategorized
   What's New Disable Windows 10 Notification - Our policy regarding Operating System (or any other major) upgrade has always been to proceed with caution and upgrade when a) you have a need to, b) your environment (hardware, software, etc.) supports it and c) it's stable.  Microsoft has been pushing Windows 10 since it's release and has gotten more and more aggressive with the rollout with each monthly update cycle.  Our policy is still, if you are currently on Windows 7 and have no business requirement to upgrade, stay with Windows 7.  If you have Windows 8.x, Windows 10 is a slight upgrade but Windows 7 is battle tested, well supported by third parties and is scheduled to be supported by Microsoft until January of 2020.  All of that said,…
Read More

Oracle re-issues Java patch from 2013 to patch a vulnerability considered ‘trivially exploitable’

Uncategorized
Emergency Java Patch Re-Issued for 2013 Vulnerability According to this article on ThreatPost, Oracle has re-released an update for a vulnerability initially reported and believed to be patched in 2013.  Details on the flaw are publicly available and, due to the ease of weaponizing it, it's expected to be integrated into attacks soon if not already.    Updates are available and all users are encouraged to update as soon as possible. The update can be downloaded from Oracle here. Cyber Tech Cafe MyIT clients are currently being updated automatically.
Read More

March 2016 News and Updates

Monthly Newsletters, Uncategorized
   What's New Hacker Playdate - The Q2 2016 Hacker Playdate "Business Edition" is scheduled for 23 April 2016 at the Bartow County Library.  Huge thank you to the Bartow County Library for all of their support and for the new venue.  Additional details are available here. Ransomware & Rogue Tech - We continue to see computers that are infected with ransomware that encrypts the data and demands a ransom (generally payable by Bitcoin) and rogue tech support calls.  Backup your data.  Don't let strangers onto your computer.  That is all (for now) :)  Windows 10 -  We are seeing a LOT of folks who are installing Windows 10 'accidentally'.  Two very important things to note on this are that you have 30 days from the time you do the…
Read More

February 2016 News and Updates

Monthly Newsletters, Uncategorized
   What's New Hacker Playdate - The Q1 2016 Hacker Playdate, despite some weather concerns, was a huge success.  Many thanks again to our sponsors and participants Cisco ASA Vulnerabilit - A vulnerability in Cisco ASAs (firewalls) was disclosed last week that could allow a remote attacker full access to an affected Cisco ASA.  Scans for vulnerable devices have been very aggressive since the disclosure Cisco, to my knowledge, has not released an update to patch the hole.  Some sites have reportedly disabled host-to-site IPSec VPNs as a result.  Additional information is available at SANS here. DMA Locker - We have reported on ransomeware (I believe that this was our first article on it back in 2013) and it looks like the genre has experienced another evolution.  This latest variant encrypts…
Read More