Category: Software

  • Time to block Windows Automatic Update — with a new twist for Win10 Pro | Computerworld

    If you’ve ever had issues with Windows updates — haven’t we all — this is the article for you. It tells you how to delay the updates until Microsoft gets the bugs out. After all, they’re not paying you to test their software. With their last earnings, they can afford to hire and pay employees…

  • Backdoor in Captcha Plugin Affects 300K WordPress Sites

    Check your WordPress sites for this plugin and remove it   The WordPress repository recently removed the plugin Captcha over what initially appeared to be a trademark issue with the current author using “WordPress” [Editors note: the original page has been removed, we’re now linking to a screen shot.] in their brand name. <…> A backdoor file…

  • Microsoft Will End Final Free Windows 10 Upgrade Program On December 31 – ExtremeTech

    If you’ve been procrastinating taking the plunge to windows 10, now’s the time to do it… Should you need a Windows 10 upgrade after the December 31st cutoff, you’ll probably have to pay for it. A license for the Home edition starts at about $75 for a system builder OEM copy that is tied to…

  • MS Office Built-in Feature Allows Malware Execution Without Macros Enabled

    This exploit uses the users’ common sense against themselves. Security researchers at Cisco’s Talos threat research group have discovered one such attack campaign spreading malware-equipped Microsoft Word documents that perform code execution on the targeted device without requiring Macros enabled or memory corruption. This Macro-less code execution in MSWord technique, described in detail on Monday by a…

  • Hackers pounce on 3 vulnerable WordPress plugins – Naked Security

    Remember the old saying about bad things coming in threes? Flaw hunters Wordfence would probably agree with the sentiment after uncovering some nasty zero-day flaws in a trio of WordPress plugins. Not a great start, then, but much worse is that the vulnerabilities were already being exploited when the company discovered them by chance during recent…

  • Beware! Don’t Fall for FireFox “HoeflerText Font Wasn’t Found” Banking Malware Scam

    For all you FireFox users… The malicious scam campaign, “The ‘HoeflerText’ font wasn’t found,” is back, which was previously targeting Google Chrome users to trick them into installing Spora ransomware on their computers. This time the campaign has been re-designed to target Mozilla Firefox users with a banking trojan, called Zeus Panda. Interestingly, the attackers…

  • Unpatched WordPress Flaw Could Allow Hackers To Reset Admin Password

    For all you do-it-yourself-ers, this is why it’s important to stay current on your core, theme, and plugin updates.  If you can’t find the time, hire me, or another professional, to do it consistently.  Most updates should not be considered “optional.”  They are done to stay ahead of hackers or fix exploit flaws. WordPress, the…

  • How to Make Windows Troubleshoot Your PC’s Problems for You

    Why not let Windows do all the heavy lifting when you have a problem? Windows includes a variety of “troubleshooters” designed to quickly diagnose and automatically solve various computer problems. Troubleshooters can’t fix everything, but they’re a great place to start if you encounter a problem with your computer. Troubleshooters are built into the Control Panel…

  • How to Open Office Files Without Being Hacked

    Here are some good safety tips for opening Word documents, especially since Microsoft seems to be so slow at patching known exploits.  The easiest and most foolproof (so far) method is to open your documents in an online service: either Office online or Google Docs.  This way the desktop exploits can’t be utilized. Microsoft Office…

  • Beware of an Unpatched Microsoft Word 0-Day Flaw being Exploited in the Wild

    As a general rule, you should never open a file from anyone that you aren’t expecting.  If your best friend or family member sends you a file you didn’t ask for, email them and make sure they sent it. This exploit bypasses the disabled macro settings and is very devious. According to researchers, this zero-day…