Subject: Major security vulnerability in Windows 10 & Windows Server

AlertsUSA Logo - Allow Images
SMS Alert Text:

NSA discovers major security vulnerability in Windows 10, as well as Windows Server 2016 & 2019. DHS urges installation of MS security patch. More via email.

Supplemental Info:

The National Security Agency has alerted Microsoft in recent weeks to a significant issue affecting its Windows 10 operating system. U.S. government officials describe the vulnerability in Windows 10 - ubiquitous within corporations and among consumers - as "especially severe" and one that Microsoft customers should work to fix immediately by updating their systems.

The vulnerability is found in a decades-old Windows cryptographic component known as CryptoAPI. The flaw can be exploited to allow the spoofing of the digital signature of software, allowing the installation of malware that is posing as a legitimate application.

Operating systems impacted include Windows 10 (all versions), as well as Windows Server 2016 & 2019.

In a sign of how severe officials considered the flaw, the Department of Homeland Security issued an emergency directive on this afternoon instructing federal agencies to take a series of steps to apply patches to their systems immediately. DHS also said it would hold calls with private industry partners warning about the risks posed by the flaw.

Although Emergency Directive 20-02 applies only to certain Executive Branch departments and agencies, CISA strongly recommends state and local governments, the private sector, and others also patch these critical vulnerabilities as soon as possible. Review the following resources for more information: 
A security update was released by Microsoft on January 14, 2020, and customers who have already applied the update, or have automatic updates enabled, should already be protected.

Service Notes:

This email message is a component of the AlertsUSA Homeland Security Threat and Incident Notification Service for mobile devices. You have paid for this service and are encouraged to archive these messages.

Service Issues? Let Us Know
service@AlertsUSA.com

Discount Subscription Link (share w/ friends):
https://AlertsUSA.com/discount.html

Threat Journal Newsletter:
https://ThreatJournal.com

Connect With Us:
Twitter: https://twitter.com/AlertsUSA
LikeTwitterPinterestGooglePlusLinkedInForward
AlertsUSA, Inc, 29488 Woodward Ave #423, Royal Oak, Michigan 48073, United States
You may unsubscribe or change your contact details at any time.