this post was submitted on 16 Dec 2024
65 points (97.1% liked)

Cybersecurity

5833 readers
71 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 10 points 1 day ago (1 children)

Here's microsoft's info: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49071

MS says they mitigated it without user intervention. Allegedly someone with privileges for Windows Defender could access an index file and send file contents over a network. I couldn't tell if the file contents were just the index itself or file contents from elsewhere on the machine but I think it's the former.

Anyway, MS says it's fixed and pay no attention to the man behind the curtain.

[โ€“] [email protected] 8 points 1 day ago

Probably found it when a computer was just sending Recall images out to a C&C server. Nothing to see here! xD