Security Bits logo - a green padlock with the words Security Bits to the right and in tiny letters below ithat it says 10101010 indicating a digital lock

Security Bits β€” 25 May 2025

Feedback & Followups

  • πŸ‡ͺπŸ‡Ί Following the near-miss with the US-funded critically important CVE database earlier this year (CISA nearly let funding lapse without notice, and even then only temporarily extended the existing funding rather than actually renewing it), the EU announced an independent alternative vulnerability database the world could rely on now that America has squandered its hard-earned trust, that DB has gone live β€” www.theregister.com/… (Snark from Bart: a shockingly efficient response for the sometimes lumbering EU bureaucracy πŸ™‚)

❗ Action Alerts

Worthy Warnings

Notable News

  • 🧯There is a new speculative execution bug that has been demonstrating stealing secrets from RAM (keys, passwords etc.) in a lab, it does bypass the existing optionally enabled mitigations (which all have performance impacts), but it was responsibly disclosed so Intel have issued a microcode update (with only an additional 3% performance hit) and cloud providers will be rolling that out, but as usual the risk to home users is extremely low (Intel only, neither AMD nor ARM affected this time) β€” www.bleepingcomputer.com/…
  • Microsoft have announced that they will continue to support the Office365 apps on Windows 10 for 3 years after it goes End-of-Life (EOL) this October, this not note mean home users can safely put off upgrading to Windows 11, this change is only helpful for businesses that opt to pay for Windows 10 Extended Security Updates (ESU), which is only available on some versions of Windows, and not cheap! β€” www.bleepingcomputer.com/…
  • Signal now blocks Microsoft Recall screenshots on Windows 11 β€” www.bleepingcomputer.com/…
    • Snark from Bart: this is achieved using the Windows DRM APIs, so apparently there is at least one good use for DRM πŸ˜‰
  • Google have added a great new security feature to Chrome on Windows. If you try to run it with admin privileges (say while logged in as a local admin), it will automatically surrender those privileges on launch, greatly limiting the damage of any future code execution bugs β€” www.bleepingcomputer.com/…
    • To make this story even a little sweeter, this enhancement was developed by Microsoft for Edge, a Chromium browser, as open source, and Microsoft helped Google back-port it to their browser!

Just Because it’s Cool 😎

Palate Cleansers

Legend

When the textual description of a link is part of the link, it is the title of the page being linked to, when the text describing a link is not part of the link, it is a description written by Bart.

Emoji Meaning
🎧 A link to audio content, probably a podcast.
❗ A call to action.
flag The story is particularly relevant to people living in a specific country, or, the organisation the story is about is affiliated with the government of a specific country.
πŸ“Š A link to graphical content, probably a chart, graph, or diagram.
🧯 A story that has been over-hyped in the media, or, “no need to light your hair on fire” πŸ™‚
πŸ’΅ A link to an article behind a paywall.
πŸ“Œ A pinned story, i.e. one to keep an eye on that’s likely to develop into something significant in the future.
🎩 A tip of the hat to thank a member of the community for bringing the story to our attention.
🎦 A link to video content.

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top