News Gist .News

Articles | Politics | Finance | Stocks | Crypto | AI | Technology | Science | Gaming | PC Hardware | Laptops | Smartphones | Archive

Microsoft Fixes Dns Authentication Issue with Entra Id

Microsoft has resolved an issue with its Entra ID authentication tool that briefly prevented users from logging into different Azure cloud services. The problem stemmed from a recent DNS change, which removed a domain utilized in the authentication process for Microsoft Entra ID's seamless single sign-on feature. The service is now fully recovered and customers should no longer encounter DNS resolution failures.

See Also

Microsoft Updates Terms on Data Privacy Amid EU Probe Δ1.74

Microsoft is updating its commercial cloud contracts to improve data protection for European Union institutions, following an investigation by the EU's data watchdog that found previous deals failed to meet EU law. The changes aim to increase Microsoft's data protection responsibilities and provide greater transparency for customers. By implementing these new provisions, Microsoft seeks to enhance trust with public sector and enterprise customers in the region.

Microsoft Resolves Global Outage Affecting Tens of Thousands Δ1.73

A global outage at Microsoft left tens of thousands of users unable to access their Outlook email accounts and other programs, with the issue affecting services such as Microsoft Exchange, Teams, 365, and Azure. The outage was most concentrated in major US cities including New York, Chicago, and Los Angeles. Microsoft has restored service after an investigation into the cause of the problem.

India's Angel One Says Assessing Impact After Security Breach Δ1.72

Indian stock broker Angel One has confirmed that some of its Amazon Web Services (AWS) resources were compromised, prompting the company to hire an external forensic partner to investigate the impact. The breach did not affect clients' securities, funds, and credentials, with all client accounts remaining secure. Angel One is taking proactive steps to secure its systems after being notified by a dark-web monitoring partner.

Microsoft Quietly Updates Copilot to Cut Down on Unauthorized Windows Activations Δ1.69

Microsoft has implemented a patch to its Windows Copilot, preventing the AI assistant from inadvertently facilitating the activation of unlicensed copies of its operating system. The update addresses previous concerns that Copilot was recommending third-party tools and methods to bypass Microsoft's licensing system, reinforcing the importance of using legitimate software. While this move showcases Microsoft's commitment to refining its AI capabilities, unauthorized activation methods for Windows 11 remain available online, albeit no longer promoted by Copilot.

Mastercard Outage Resolved After Users Report Issues with Payments, Purchases Δ1.68

Mastercard has resolved an issue affecting some transactions after cardholders reported being unable to make online payments or purchases for a brief period Sunday morning. Hundreds of cardholders in the U.S., United Kingdom, Japan, Italy, and Australia were among those who began reporting issues early Sunday morning. The company stated that all systems are now working as normal.

5 Easy Browser Tweaks That Secure Your Web Surfing Δ1.68

Modern web browsers offer several built-in settings that can significantly enhance data security and privacy while online. Key adjustments, such as enabling two-factor authentication, disabling the saving of sensitive data, and using encrypted DNS requests, can help users safeguard their personal information from potential threats. Additionally, leveraging the Tor network with specific configurations can further anonymize web browsing, although it may come with performance trade-offs.

Broadcom Releases Fixes for Multiple VMware Security Flaws Δ1.68

Broadcom has released patches for three critical vulnerabilities in its VMware products, which are already being exploited in the wild. The bugs were described as VM escape flaws and affect all supported versions of VMware ESX, vSphere, Cloud Foundation, and Telco Cloud Platform. These issues were deemed severe enough to warrant immediate attention from users, who are urged to apply the fixes as soon as possible.

UBlock Origin Users Face Uncertainty After Chrome Removal Δ1.68

uBlock Origin, a popular ad-blocking extension, has been automatically disabled on some devices due to Google's shift to Manifest V3, the new extensions platform. This move comes as users are left wondering about their alternatives in the face of an impending deadline for removing all Manifest V2 extensions. Users who rely on uBlock Origin may need to consider switching to another browser or ad blocker.

Microsoft Withdraws From CoreWeave Agreements Due to Delivery Issues Δ1.68

Microsoft has withdrawn some of its agreements with cloud computing provider CoreWeave over delivery issues and missed deadlines, the Financial Times reported on Thursday citing unnamed sources. The company provides computing capacity from data centers, a partnership worth billions of dollars, through ongoing contracts with CoreWeave, which competes against cloud providers such as Microsoft's Azure and Amazon's AWS. Founded in 2017, CoreWeave has laid groundwork for what could be one of the biggest IPOs in recent times.

Microsoft Walks Away From Cloud Computing Deal Due to Delivery Issues Δ1.67

Microsoft has moved away from some of its agreements with cloud computing provider CoreWeave over delivery issues and missed deadlines, the Financial Times reported on Thursday citing unnamed sources. A partnership worth billions of dollars, Microsoft provides computing capacity from data centers through a contract with CoreWeave. The company competes against major players like Azure and AWS in the cloud computing market.

Microsoft Teams and Other Windows Tools Hijacked to Hack Corporate Networks Δ1.67

Hackers are exploiting Microsoft Teams and other legitimate Windows tools to launch sophisticated attacks on corporate networks, employing social engineering tactics to gain access to remote desktop solutions. Once inside, they sideload flawed .DLL files that enable the installation of BackConnect, a remote access tool that allows persistent control over compromised devices. This emerging threat highlights the urgent need for businesses to enhance their cybersecurity measures, particularly through employee education and the implementation of multi-factor authentication.

Software Bug at Firm Left NHS Data 'Vulnerable to Hackers' Δ1.67

The NHS is investigating claims that a software flaw at Medefer compromised patient data security, as the issue was discovered in November but may have existed for several years. Medefer has stated that no patient data breach occurred and that the flaw was promptly addressed, although cybersecurity experts have raised concerns about the company's response to the vulnerability. The situation underscores the critical importance of robust cybersecurity measures in handling sensitive medical information, especially within the healthcare sector.

Apple Appeals to Overturn UK Government's 'Back Door' Order Δ1.66

Apple has appealed a British government order to create a "back door" in its most secure cloud storage systems. The company removed its most advanced security encryption for cloud data, called Advanced Data Protection (ADP), in Britain last month, in response to government demands for access to user data. This move allows the UK government to access iCloud backups, such as iMessages, and hand them over to authorities if legally compelled.

Microsoft Names Cybercriminals Who Created Explicit Deepfakes Δ1.66

Microsoft has identified and named four individuals allegedly responsible for creating and distributing explicit deepfakes using leaked API keys from multiple Microsoft customers. The group, dubbed the “Azure Abuse Enterprise”, is said to have developed malicious tools that allowed threat actors to bypass generative AI guardrails to generate harmful content. This discovery highlights the growing concern of cybercriminals exploiting AI-powered services for nefarious purposes.

Zapier Data Breach Raises Concerns Over Customer Information Security. Δ1.66

Zapier, a popular automation tool, has suffered a cyberattack that resulted in the loss of sensitive customer information. The company's Head of Security sent a breach notification letter to affected customers, stating that an unnamed threat actor accessed some customer data "inadvertently copied to the repositories" for debugging purposes. Zapier assures that the incident was isolated and did not affect any databases, infrastructure, or production systems.

Under the Hood of Data Sovereignty Δ1.66

Organizations are increasingly grappling with the complexities of data sovereignty as they transition to cloud computing, facing challenges related to compliance with varying international laws and the need for robust cybersecurity measures. Key issues include the classification of sensitive data and the necessity for effective encryption and key management strategies to maintain control over data access. As technological advancements like quantum computing and next-generation mobile connectivity emerge, businesses must adapt their data sovereignty practices to mitigate risks while ensuring compliance and security.

Microsoft Launches New Hyper-Powered Disaster Recovery Service for Cloud PCs Δ1.66

Microsoft has introduced the Windows 365 Disaster Recovery Plus (DRP) option, which significantly enhances data recovery capabilities with recovery times up to eight times quicker than the previous Cross-region Disaster Recovery (CRDR) solution. This new offering allows users to select their preferred geographic region for data sovereignty while providing access to a temporary Cloud PC during outages, although it does not preserve applications or data. The enhanced service aims to mitigate data loss risks and improve operational efficiency for organizations relying on Cloud PCs.

Microsoft Discoveries Vulnerable Software Attack. Δ1.66

Microsoft has confirmed that its Windows drivers and software are being exploited by hackers through zero-day attacks, allowing them to escalate privileges and potentially drop ransomware on affected machines. The company patched five flaws in a kernel-level driver for Paragon Partition Manager, which were apparently found in BioNTdrv.sys, a piece of software used by the partition manager. Users are urged to apply updates as soon as possible to secure their systems.

Breaking Into Code: Security Threat Impacts Customer Data at Zapier Δ1.66

Zapier has disclosed a security incident where an unauthorized user gained access to its code repositories due to a 2FA misconfiguration, potentially exposing customer data. The breach resulted from an "unauthorized user" accessing certain "certain Zapier code repositories" and may have accessed customer information that had been "inadvertently copied" to the repositories for debugging purposes. The incident has raised concerns about the security of cloud-based platforms.

Technical Issues Resolved Across Whatsapp and Other Meta Apps Δ1.66

WhatsApp's recent technical issue, reported by thousands of users, has been resolved, according to a spokesperson for the messaging service. The outage impacted users' ability to send messages, with some also experiencing issues with Facebook and Facebook Messenger. Meta's user base is massive, making any glitches feel like they affect millions worldwide.

X Platform Outage Appears to Ease, Downdetector Shows Δ1.66

An outage on Elon Musk's social media platform X appeared to ease after thousands of users in the U.S. and the UK reported glitches on Monday, according to outage-tracking website Downdetector.com. The number of reports in the U.S. dropped to 403 as of 6:24 a.m. ET from more than 21,000 incidents earlier, user-submitted data on Downdetector showed. Reports in the UK also decreased significantly, with around 200 incidents reported compared to 10,800 earlier.

Microsoft Hits Back Against UK Competition Lawsuits, Slams AWS and Google Once Again Δ1.66

Microsoft has responded to the CMA’s Provision Decision Report by arguing that British customers haven’t submitted that many complaints. The tech giant has issued a 101-page official response tackling all aspects of the probe, even asserting that the body has overreacted. Microsoft claims that it is being unfairly targeted and accused of preventing its rivals from competing effectively for UK customers.

Untrusted Device Errors on Chromecast? What to Know - Including Potential Workarounds Δ1.65

Second-generation Chromecast and Chromecast Audio devices are currently experiencing authentication issues, presenting users with error messages indicating they are untrusted or cannot be verified. Despite users attempting various troubleshooting methods, including factory resets and network changes, the problem persists, leading to speculation about the potential discontinuation of support for older devices. Google has acknowledged the issue and is reportedly working on a fix, though details remain scarce.

Microsoft Warns of Chinese Hackers Targeting Cloud Apps to Steal Business Data Δ1.65

Microsoft's Threat Intelligence has identified a new tactic from Chinese threat actor Silk Typhoon towards targeting "common IT solutions" such as cloud applications and remote management tools in order to gain access to victim systems. The group has been observed attacking a wide range of sectors, including IT services and infrastructure, healthcare, legal services, defense, government agencies, and many more. By exploiting zero-day vulnerabilities in edge devices, Silk Typhoon has established itself as one of the Chinese threat actors with the "largest targeting footprints".

Nationwide Oracle Outage Hits US Federal Health Record Systems Δ1.65

Oracle's Federal electronic health records (EHR) software recently suffered a nationwide outage, causing six Veterans Affairs hospitals to revert to contingency procedures in order to continue treating patients as normal. The outage started at 08:37 ET on March 4 and lasted for five hours, affecting users across various government agencies, including the Department of Defense, US Coast Guard, and NOAA. Oracle has launched a full root cause analysis to determine what triggered this outage.