AUTO-UPDATED

This Week in Security: Another Record Patch Tuesday, LAME is More Secure, Secure Boot is Less Secure, and Milk Malware

Microsoft’s July Patch Tuesday sets a new record for security fixes, while researchers uncover critical vulnerabilities in Dell BIOS, Windows boot loaders, and the LegacyHive registry exploit.

Key Points

  • Microsoft released over 60 patches for critical Windows vulnerabilities, including fixes for BitLocker bypasses, DHCP privilege escalation, and an AI prompt injection in Edge.
  • Researchers identified a Dell BIOS vulnerability allowing administrator password extraction, with passwords of 12 characters or fewer stored in plaintext.
  • ESET discovered 11 Microsoft-signed boot loaders that allow attackers to bypass Secure Boot protections and execute arbitrary code.
  • The LegacyHive exploit, disclosed by researcher NightmareEclipse, enables unauthorized access to the registry settings and configuration files of other Windows users.
  • Fairlife Dairy suspended U.S. production operations following a ransomware attack, with no current timeline for facility restoration.
  • The LAME MP3 encoder received its first update in nearly a decade, addressing long-standing stack buffer overflow and integer underflow vulnerabilities.

Why it Matters

These developments highlight a significant increase in the discovery of complex, high-impact vulnerabilities across both hardware firmware and core operating system components. For organizations and individual users, the rapid pace of these disclosures underscores the critical necessity of maintaining updated systems to mitigate risks from supply chain exploits and persistent firmware-level threats.
Hackaday Published by Mike Kershaw
Read original