Cookie Laws within the EU Allow Cookies
Competitive personal insurance for your family home, car and holidays

Call us on
020 8309 1717
   
 
CLIENT CYBER ADVISORY UPDATE
Published on the 24th January 2020

Cyber Security Threat!!!!

The US National Security Agency has announced the discovery of a serious security vulnerability within Windows 10 and Windows Server 2016/2019 that exploits a component known as CryptoAPI. Microsoft has released a patch to fix it and all users of these operating systems are advised to implement this patch immediately.

 

Developers use digital signatures to prove that their software is legitimate and has not been tampered with. However, this security vulnerability could allow an attacker to spoof legitimate software, undermining how Windows verifies trust and allowing the running of malicious software, like ransomware, in the background. According to Microsoft, the user would have no way of knowing a file was malicious, because the digital signature would appear to be from a trusted provider.

 

The vulnerability affects Windows 10 and Windows Server 2016/2019 as well as applications that rely on Windows for trust functionality, such as HTTPS connections, signed files and emails, and signed executable code launched as user-mode processes.

 

Businesses running affected systems should install all patches from January 2020 as soon as possible, prioritizing endpoints that provide essential services.

 

Links to critical patches are contained within the Security Guidance Advisory from Microsoft

 

Thanks for your time and attention,




 
Recent Posts
  Underinsurance
The issues facing business.

30th November 2023
Read more >>
  Tips for storing classic cars
Important matters to consider for the storage of your...

12th September 2023
Read more >>
  Car Thefts
Recent spike in luxury vehicle thefts

2nd May 2023
Read more >>
  2022 Highway Code changes – do you know the rules?
If approved by parliament, these changes to the Highway...

1st February 2022
Read more >>
Archived Posts >>
Search posts
 
   
Services for UK based residents and businesses only.

Authorised and regulated by the Financial Conduct Authority.