https://www.theregister.com/2021/04/13/patch_tuesday_april/ The Register(r) -- Biting the hand that feeds IT search [ ] # # Sign in Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem All On-PremServersStorageNetworksHPCPersonal Tech (X) Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) SecurityOffbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice AdobeGoogle CloudGoogle Cloud's ApigeeNutanixRapid7Red hatSophosVeeam Virtru (X) # # # [front] Security NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches 114 fixes for the Windows world - plus fixes from SAP, Adobe, FreeBSD, etc Thomas Claburn in San Francisco Tue 13 Apr 2021 // 19:47 UTC Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy --------------------------------------------------------------------- Patch Tuesday April showers bring hours of patches as Microsoft delivers its Patch Tuesday fun-fest consisting of over a hundred CVEs, including four Exchange Server vulnerabilities reported to the company by the US National Security Agency (NSA). Forty-four different products and services are affected, mainly having to do with Azure, Exchange Server, Office, Visual Studio Code, and Windows. Among the vulnerabilities, four have been publicly disclosed and a fifth is being actively exploited. Nineteen of the CVEs have been designated critical. [front] "This month's release includes a number of critical vulnerabilities that we recommend you prioritize, including updates to protect against new vulnerabilities in on-premise Exchange Servers," Microsoft said in its blog post. "These new vulnerabilities were reported by a security partner through standard coordinated vulnerability disclosure and found internally by Microsoft. We have not seen the vulnerabilities used in attacks against our customers. [front] Clicking through Microsoft's coy links to CVE-2021-28480 (9.8 severity), CVE-2021-28481 (9.8 severity), CVE-2021-28482 (8.8 severity), and CVE-2021-28483 (9.0 severity), you'll find the unspecified security partner is the NSA. sap hq in dresden SAP: It takes exploit devs about 72 hours to turn one of our security patches into a weapon against customers READ MORE Exchange Server 2013 CU23, Exchange Server 2016 CU19 and CU20, and Exchange Server 2019 CU8 and CU9 are affected by this set of problems. "NSA urges applying critical Microsoft patches released today, as exploitation of these #vulnerabilities could allow persistent access and control of enterprise networks," the signals intelligence agency said via Twitter. The NSA assist comes a month after Microsoft fixed four Exchange Server zero-day flaws, claiming that a China-based hacking group, dubbed "Hafnium," exploited the vulnerabilities to steal data from US defense contractors, law firms, and medical researchers. Pointing to the two 9.8 severity Exchange flaws, Dustin Childs, director of communications for the Zero Day Initiative, in a blog post said, "Both code execution bugs are unauthenticated and require no user interaction. Since the attack vector is listed as 'Network,' it is likely these bugs are wormable - at least between Exchange servers." 2 of these are logic pre-auth RCEs btw, so if you don't patch fast you're going to have a bad time. https://t.co/99tAMrHlgS -- Pwn All The Things (@pwnallthethings) April 13, 2021 Six of the 114 Microsoft CVEs correspond to Microsoft Edge and were inherited via a recent Chromium update. Of the remainder, Childs notes that 27 are identified as "Remote Procedure Call Runtime Remote Code Execution Vulnerability," with 12 of these designated critical and 15 rated important. "In RPC vulnerabilities seen in the past, an attacker would need to send a specially crafted RPC request to an affected system," he explained. "Successful exploitation results in executing code in the context of another user." Among the rest, only CVE-2021-28310, identified as a Win32k Elevation of Privilege Vulnerability, is known to be under active exploitation. And the rest SAP reported a higher number of security advisories than usual: 23, of which 11 are medium severity, five are high severity, and three are designated "Hot News" because SAP evidently can't bring itself to say "critical." Among these three, one flaw managed to score a perfect 10 CVSS score. SAP hasn't made the details publicly available but security firm Onapsis explains that it's an update that fixes 62 vulnerabilities in Google's Chromium browser, which is used in SAP Business Client. Forescout has identified a set of nine vulnerabilities, dubbed NAME:WRECK, affecting DNS-related code in four TCP/IP stacks - FreeBSD, Nucleus NET, IPnet and NetX - which are used in an estimated 100 million or more devices. The bugs can be exploited to crash boxes or execute arbitrary code. The patch for FreeBSD is here. If you're using equipment powered by the vulnerable software, get it patched or block off access to its at-risk services. This open-source script can detect vulnerable machines on your network. The runner-up is a 9.9 severity flaw designated CVE-2021-27602, which SAP describes as a remote code execution vulnerability in Source Rules of SAP Commerce, versions 1808, 1811, 1905, 2005, and 2011. The last of the top three is a 9.6 severity missing authorization check in SAP NetWeaver AS JAVA (migration service) that earned the CVE-2021-21481. Adobe meanwhile issued four advisories - APSB21-28 for Photoshop, APSB21-26 for Digital Editions, APSB21-23 for Bridge, and APSB21-20 for RoboHelp - addressing ten CVEs. Four of these are critical - two of these in Photoshop and the other two in Bridge. Google at the beginning of the month dropped 39 CVEs covering Android and components from MediaTek and Qualcomm. Two were designated critical. [front] "The most severe of these issues is a critical security vulnerability in the System component that could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process," Google's security bulletin said. (r) Get our Tech Resources * MORE * Microsoft * Security * Software Corrections Send us news 2 Comments reddit Twitter Facebook linkedin WhatsApp email Get our Security newsletter [front] Most Read 1. Quality control, Soviet style: Here's another fine message you've gotten me into 2. Stuxnet sibling theory surges after Iran says nuke facility shut down by electrical fault 3. FCC urges Americans to run internet speed app to counter Big Cable's broadband data fudging 4. Nominet chooses civil war over compromise by rejecting ex-BBC Trust chairman 5. Bless you: Yep, it's IBM's new name for tech services spinoff and totally not a hayfever medicine [front] --------------------------------------------------------------------- [front] * After years of dragging its feet, FCC finally starts tackling America's robocall scourge New law implementation, cease-and-desist letters, and mobile companies asked to detail free blocking tools Kieren McCarthy in San Francisco Tue 13 Apr 2021 // 22:34 UTC The FCC is finally taking concrete action on the scourge of robocalls after years of dithering on the issue. In an announcement on Tuesday, America's telecoms watchdog said it had written to cellular network operators asking them to detail the free robocall blocking tools they provide to consumers. It also released two cease-and-desist letters against two robcalling hosts and said it would track the agency's actions in implementing a new anti-robocall law. Just as with an announcement yesterday pushing an internet speed measuring app, the measures taken are soft, rather than strong enforcement, but indicate a clear shift in priorities under the FCC new chair Jessica Rosenworcel. Continue reading * Who'd have thought the US senator who fist pumped Jan 6 insurrectionists would propose totally unworkable anti-Big Tech law? This one seems as well thought-out as his Capitol rally salute Kieren McCarthy in San Francisco Tue 13 Apr 2021 // 21:44 UTC US Senator Josh Hawley (R-MO) has proposed his latest anti-Big Tech legislation: a complete ban on mergers and acquisitions for companies valued at over $100bn if it may harm competition in any way possible. The "Trust-Busting for the Twenty-First Century Act" [PDF] will "take back control from big business and return it to the American people," the senator announced, and it will "crack down on mergers and acquisitions by mega-corporations and strengthen antitrust enforcement to pursue the breakup of dominant, anti-competitive firms." The law is intended to put constraints on Apple, Google, Facebook, and Amazon - in keeping with Hawley's political brand of attacking tech companies - and he provides examples of actions that would be prevented, such as Google purchasing Waze and incorporating into its Maps app. Continue reading * 1Password targets developers with Secrets Automation, acquisition of SecretHub Existing users covered until 2022 Tim Anderson Tue 13 Apr 2021 // 20:53 UTC Password specialist 1Password has acquired SecretHub, a secrets management platform aimed at IT engineers, and made a new service called Secrets Automation, previously in beta, generally available. The proliferation of passwords and SSH keys in modern IT has brought with it a tricky management problem, not only for people but also for machine-to-machine communications. Developers may struggle to keep secrets such as database logins secure, when their code will not function without them. In 2019 researchers at North Carolina State University scanned code publicly committed to GitHub and found that "not only is secret leakage pervasive -- affecting over 100,000 repositories -- but that thousands of new, unique secrets are leaked every day." In June 2020, security researcher Craig Hays deliberately leaked server credentials in a GitHub repository and observed an unauthorised login just 34 minutes later. Continue reading * What's Red and scale-y and shacked up with NEC? A new Red Hat network function virtualization solution, apparently Living on the Edge as SA networks roll out Matthew Hughes Tue 13 Apr 2021 // 19:01 UTC The move to 5G has allowed vendors and carriers to fundamentally rethink how their networks are structured. Once the norm, tightly integrated vendor-specific hardware is gradually being supplanted by virtualized alternatives that run happily on standards-agnostic kit. Jumping on the bandwagon is Japanese provider NEC, which today said it would use RedHat's OpenShift Kubernetes platform for its upcoming 5G hardware. The company said it plans to use OpenShift across its 5G Core and RAN products, intended for both public and private use, as well its Edge and AI platforms. On the edge, NEC sells a compact data processing device called the UPF mini. The hardware has already been selected for NTT DoCoMo's 5G SA (StandAlone) network, with the device positioned on existing base stations. The company also sells a software-based AI analysis platform for private and local networks, which NEC claimed can help mitigate performance slowdowns caused by congestion. Continue reading * In the enterprise, Kubernetes has to play by the same rules as other platforms Shortcuts? What shortcuts! Timothy Prickett Morgan Tue 13 Apr 2021 // 18:00 UTC Sponsored Without a doubt, Kubernetes is the most important thing that has happened in enterprise computing in the past two decades, rivalling the transformation that swept over the datacenter with server virtualization, first in the early 2000s on RISC/Unix platforms and then during the Great Recession when commercial-grade server virtualization became available on X86 platforms at precisely the moment it was most needed. All things being equal, the industry would have probably preferred to go straight to containers, which are lighter weight than server virtualization and which are designed explicitly for service-oriented architectures - now called microservices - but it is the same idea of chopping code into smaller chunks so it can be maintained, extended, or replaced piecemeal. This is precisely why Google spent so much time in the middle 2000s creating what are now seen as relatively rudimentary Linux containers and the Borg cluster and container controllers. Seven years ago, as it was unclear what the future platform might look like; OpenStack, which came out of NASA and Rackspace Hosting, was a contender, and so was Mesos, which came out of Twitter, but Kubernetes, inspired by Borg and adopting a universal container format derived from Docker, has won. Continue reading * Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins It's like the 2000s all over again, sighs Bitdefender Gareth Corfield Tue 13 Apr 2021 // 17:12 UTC Cracked copies of Microsoft Office and Adobe Photoshop are stealing browser session cookies and Monero cryptocurrency wallets from tightwads who install the pirated software, Bitdefender has warned. As many Reg readers will no doubt be aware, cracked software is a legitimate application that has had its registration or licensing features removed. Often distributed through BitTorrent in the days of yore, cracked software (also known as warez) appeal mainly to freeloaders who are happy to use a particular suite without paying for a licence. With Microsoft Office and Adobe Photoshop being two of the most popular software suites in their niches, cracked versions were always going to be popular. Continue reading * Microsoft's Surface Laptop 4 now includes AMD options for biz customers, boasts up to 19 hours of battery life Surface Headphones 2+ also available and a range of 'Modern' kit coming in the next few months Richard Speed Tue 13 Apr 2021 // 16:15 UTC Microsoft has opened the order books on the fourth generation of its Surface Laptop, replete with Intel-baiting AMD chippery in the line-up. Blessedly free of an overexcited Microsoft bigwig describing himself as "pumped" at the sight of some relatively pedestrian hardware, Microsoft's Surface Laptop 4 has arrived in 13.5 and 15-inch guise with a variety of Intel and AMD silicon to choose from. The new AMD chips are an important update; previously, consumers could select a Surface Laptop 3 not powered by Intel, but businesses were directed Chipzilla's way. This time around a range of updated Intel and AMD silicon is on offer to both customer types. Continue reading * You know what? Fork this: AWS renames its take on Elasticsearch to OpenSearch following trademark fight Beta expected in a matter of weeks, production release planned for summer Tim Anderson Tue 13 Apr 2021 // 15:29 UTC AWS has introduced the OpenSearch project, the new name for its open-source fork of Elasticsearch and Kibana. OpenSearch is "the new home for our previous distribution of Elasticsearch (Open Distro for Elasticsearch)," according to a post yesterday, and the code is licensed under Apache 2.0. The Kibana fork is called OpenSearch Dashboards. The projects are on GitHub, where they are described as "in alpha state." The contributors said: "We've been removing non-Apache 2.0 compliant code and doing a full rename of the project." Continue reading * Northrop Grumman's MEV-2 gives Intelsat satellite a new lease on life until the next rescue in another five years After 17 years into a 13-year mission, that's not bad Richard Speed Tue 13 Apr 2021 // 14:12 UTC Northrop Grumman's second Mission Extension Vehicle (MEV) has docked with Intelsat's IS-10-02 satellite, potentially extending the life of the latter by five years. Launched in 2004, IS-10-02 delivers broadband and media services over Europe, the Middle East, Africa, and South America. Half of its Ku band payload is owned by Telenor Satellite, which contributed to the MEV mission. Dubbed MEV-2, the spacecraft's mission differed from last year's successful demonstration with Intelsat's IS-901 satellite. This time around the docking occurred directly in the satellite's operational GEO orbit location, a first for the MEV fleet. Continue reading * Unity devs warned of breaking changes ahead in video game engine as team gets to grips with mutating face of .NET Support has fallen behind and fixing it is a challenge Tim Anderson Tue 13 Apr 2021 // 13:15 UTC Unity software developer Josh Peterson has spoken about the future of .NET support in the widely used game development engine. Use in game development is one of the bright spots for C# popularity, according to a survey late last year, but its use in Unity is somewhat messy. The C# scripting engine is based on Mono but developers may also use .NET Framework when running on Windows. Mono is the old open-source implementation of .NET, from before Microsoft itself came out with .NET Core. Microsoft acquired the stewardship of Mono with Xamarin in 2016, and Mono now shares substantial code with .NET Core, but it remains distinct and the runtime is still used in some scenarios. Continue reading * Salesforce's get-back-to-work strategy starts with 'Volunteer Vaccinated Cohorts' on designated floors Sounds kind of like a vaccination passport for California offices Lindsay Clark Tue 13 Apr 2021 // 12:32 UTC Salesforce has waded into the heated debate over vaccine passports, suggesting they may be a means of getting employees back into the office. Just don't call them vaccine passports. According to the SaaSy CRM vendor, Volunteer Vaccinated Cohorts of protected employees will be able to join groups of 100 or fewer people to work on designated floors in certain offices, starting with San Francisco, Palo Alto, and Irvine from next month. In the US and Europe, debate rages about vaccine passports or any means of restricting access to events or services according to an individual's vaccination status. New York State created its own digital pass while Florida and Texas attempted to outlaw them, for example. Continue reading [front] ABOUT US* * Who we are * Under the hood * Contact us * Advertise with us MORE CONTENT* * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING* * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2021 Do not sell my personal information Cookies Privacy Ts&Cs