Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: ft Clear Filter

MagSafe Monday: KraftGeek’s JustTap Tripod is perfect for Continuity Camera

At first glance, the KraftGeek JustTap Tripod might seem like it’s only useful for content creation, but in my testing, it’s a lot more than that. It’s obviously great for mobile creators who don’t want to worry about whether their mount fits their case, but I also found it super useful for getting your iPhone at the perfect angle when using it as a Mac webcam. Some of my favorite gear Abode Home Security System Abode is the best home security system and includes compatibility with HomeKit. Ma

1990 Networking: LAN Manager 2.0

In 1990, Microsoft released LAN Manager (LM) 2.0, a member of a long line of Microsoft’s networking products that started with MS-NET circa 1984 and eventually morphed into Windows NT file sharing. Microsoft LAN Manager 2.0 admin interface LAN Manager 1.0 was released in 1988 as an OEM-only product, with the largest OEM being 3Com and their 3+Open. Microsoft collaborated with 3Com and the two companies jointly published the NDIS specification for network drivers. However, the relationship sour

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching U.S. federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers. The U.S. government and partners in Canada and Australia are investigating the compromise of SharePoint servers, which provide a platform for sharing and managing d

SharePoint vulnerability with 9.8 severity rating under exploit across globe

Authorities and researchers are sounding the alarm over the active mass exploitation of a high-severity vulnerability in Microsoft SharePoint Server that’s allowing attackers to make off with sensitive company data, including authentication tokens used to access systems inside networks. Researchers said anyone running an on-premises instance of SharePoint should assume their networks are breached. The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 1

Microsoft hit with SharePoint attack affecting global businesses and governments

A Microsoft store in New York, US, on Friday, Oct. 25, 2024. Microsoft has warned of "active attacks" targeting its SharePoint collaboration software, with security researchers noting that organizations worldwide stand to be affected by the breach. The Cybersecurity and Infrastructure Security Agency said Sunday in a release that the vulnerability provides unauthenticated access to systems and full access to SharePoint content, enabling bad actors to execute code over the network. CISA said t

Xbox cloud games will soon follow you across Xbox, PC, and Windows handhelds

is a senior editor and author of Notepad , who has been covering all things Microsoft, PC, and tech for over 20 years. Microsoft is starting to test updates to the Xbox PC app and Xbox consoles that will allow cloud games to follow you across devices. A new play history section of the Xbox PC app and Xbox console home UI will display cloud games as part of the recently played titles list and this will roam across Xbox consoles, PCs, and handhelds. Cloud-playable games are now starting to show

Microsoft hit with SharePoint attack — one version still vulnerable

A Microsoft store in New York, US, on Friday, Oct. 25, 2024. Microsoft has warned of "active attacks" targeting its SharePoint collaboration software, with security researchers noting that organizations worldwide stand to be affected by the breach. The Cybersecurity and Infrastructure Security Agency said Sunday in a release that the vulnerability provides unauthenticated access to systems and full access to SharePoint content, enabling bad actors to execute code over the network. CISA said t

Microsoft Fix Targets Attacks on SharePoint Zero-Day

On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the Sharepoint flaw to breach U.S. federal and state agencies, universities, and energy companies. In an advisory about the SharePoint security hole, a.k.a. CVE-2025-53770, Microsoft said it is aware of active attacks targeting on-premises SharePoint

Microsoft fixes two SharePoint zero-days under attack, but it's not over - how to patch

sankai/Getty Microsoft has patched two critical zero-day SharePoint security flaws that have already been exploited by hackers to attack vulnerable organizations. Responding to the exploits, the software giant has issued fixes for SharePoint Server Subscription Edition and SharePoint Server 2019 but is still working on a patch for SharePoint Server 2016. Designated as CVE-2025-53771 and CVE-2025-53770, the two vulnerabilities apply only to on-premises versions of SharePoint, so organizations t

Installing apps on Linux? 4 ways it's different than any other OS - and mistakes to avoid

Elyse Betters Picaro / ZDNET When I first started using Linux in the late 90s, there was really only one way to install an application. You would download the app, unpack the archive, run the ./configure command, build the app with make, and then install it with make install. Inevitably, when you ran through that course, you would stumble because of dependencies and have to locate the dependency, run through the same process as you just did (only with the new software), and then find out the ne

Microsoft Sharepoint server vulnerability puts an estimated 10,000 organizations at risk

A major zero-day security vulnerability in Microsoft's widely used SharePoint server software has been exploited by hackers, causing chaos within businesses and government agencies, multiple outlets have reported. Microsoft announced that it had released a new security patch "to mitigate active attacks targeting on-premises [and not online] servers," but the breach has already effected universities, energy companies, federal and state agencies and telecommunications firms. The SharePoint flaw i

New zero-day bug in Microsoft SharePoint under widespread attack

The U.S. federal government and cybersecurity researchers say a newly discovered security bug found in Microsoft’s SharePoint is under attack. U.S. cybersecurity agency CISA sounded the alarm this weekend that hackers were actively exploiting the bug. Microsoft has not yet provided patches for all affected SharePoint versions, leaving customers across the world largely unable to defend against the ongoing intrusions. Microsoft said the bug, known officially as CVE-2025-53771, affects versions

Over 1,000 CrushFTP servers exposed to ongoing hijack attacks

Over 1,000 CrushFTP instances currently exposed online are vulnerable to hijack attacks that exploit a critical security bug, providing admin access to the web interface. The security vulnerability (CVE-2025-54309) is due to mishandled AS2 validation and impacts all CrushFTP versions below 10.8.5 and 11.3.4_23. The vendor tagged the flaw as actively exploited in the wild on July 19th, noting that attacks may have begun earlier, although it has yet to find evidence to confirm this. "July 18th,

Microsoft SharePoint servers are under attack because of a major security flaw

Hackers have exploited vulnerabilities in Microsoft’s SharePoint software, placing tens of thousands of on-premises servers used by global businesses and agencies at risk. Microsoft issued an alert on Saturday disclosing that it was aware of “active attacks,” and that it was working to patch the zero-day exploit. Researchers at Eye Security first identified the vulnerability on July 18th, which allows hackers to access certain on-premises versions of SharePoint and steal keys that can let them

Microsoft wants to fix ‘slow or sluggish’ performance in Windows 11

is a senior editor and author of Notepad , who has been covering all things Microsoft, PC, and tech for over 20 years. Ever since Windows 11 first debuted in October 2021, there have been complaints about its performance on certain types of hardware. Whether it was gaming on new hybrid performance CPUs showing no improvement on Windows 11, or claims that Windows 11 simply feels lethargic compared to Windows 10, Microsoft has tried to fix the problems with updates to the OS. Now, it wants direct

Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks

Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in "ToolShell" attacks. In May, during the Berlin Pwn2Own hacking contest, researchers exploited a zero-day vulnerability chain called "ToolShell," which enabled them to achieve remote code execution in Microsoft SharePoint. These flaws were fixed as part of the July Patch Tuesday updates; However, threat actors were

What my mother didn’t talk about (2020)

We did not visit Poland often. Only when someone died. I have not been able to bring part of my mother’s ashes to Poland yet because of the pandemic. They sit in my living room, waiting to join my other dead relatives in her village of Bedoń. I live in California, 3,000 miles away from where I grew up, and when my mother couldn’t sleep she’d call me. I always picked up. “I think I know how I got sick,” she said once. My mother had an aversion to being sick and to anyone knowing about it. Her

Java was not underhyped in 1997 (2021)

Java Criminally Underhyped? Not Back in 1997. Earlier today, a fun little moment of Twitter serendipity alerted me to an article by Jackson Roberts, a computer science student at the University of Colorado, entitled “Java is criminally underhyped”. It’s a really interesting article, and Jackson’s observations correlate with a lot of my own thinking about languages and platforms, although I am squarely in the .NET / CLR camp on that particular front. But Jackson ends his article: I am curious

What My Mother Didn't Talk About (2020)

We did not visit Poland often. Only when someone died. I have not been able to bring part of my mother’s ashes to Poland yet because of the pandemic. They sit in my living room, waiting to join my other dead relatives in her village of Bedoń. I live in California, 3,000 miles away from where I grew up, and when my mother couldn’t sleep she’d call me. I always picked up. “I think I know how I got sick,” she said once. My mother had an aversion to being sick and to anyone knowing about it. Her

Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, has been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide. In May, Viettel Cyber Security researchers chained two Microsoft SharePoint flaws, CVE-2025-49706 and CVE-2025-49704, in a "ToolShell" attack demonstrated at Pwn2Own Berlin to achieve remote code execution. While Microsoft patched both ToolShell flaws as part of the July Patch T

How the 'Minecraft' Score Became Big Business for Its Composer

In 2009, in between full-time shifts at a local factory, then-19-year-old musician Daniel Rosenfeld composed a score for an independent video game. “It was just a side hustle, maybe not even that. It was a hobby, really,” explains Rosenfeld, who records under the name C418. The game, Minecraft, turned out to be successful beyond Rosenfeld’s wildest dreams. In 2014, Microsoft purchased Minecraft’s Swedish developer, Mojang Studios, for $2.5 billion, and through 2023, it had sold 300 million copi

Astronomers Detect Entirely New Type of Plasma Wave Above Jupiter’s North Pole

Since entering Jupiter’s orbit in 2016, NASA’s Juno spacecraft has been hard at work unveiling the many mysteries of our solar system’s largest planet. And its latest discovery may be one of the most intriguing yet: an entirely new type of plasma wave near Jupiter’s poles. In a paper published Wednesday in Physical Review Letters, astronomers describe an unusual pattern of plasma waves in Jupiter’s magnetosphere—a magnetic “bubble” shielding the planet from external radiation. Jupiter’s excepti

The curious case of the Unix workstation layout

Scroll through the blog: ‹ Newer | List All | Older › The Curious Case of the UNIX workstation layout Posted on 2025-07-19 Contents Background Cathode Ray Dude recently did an excellent video about the history of the PC case, particularly the early- and mid-1990s, and the various mainboard layouts that pre-date the ATX standard. You should watch it. Here it is. The rest of this blog will contain some spoilers for that video. UNIX workstations I have a bunch of 1990's RISC/UNIX workstatio

The Curious Case of the Unix workstation layout

Scroll through the blog: ‹ Newer | List All | Older › The Curious Case of the UNIX workstation layout Posted on 2025-07-19 Contents Background Cathode Ray Dude recently did an excellent video about the history of the PC case, particularly the early- and mid-1990s, and the various mainboard layouts that pre-date the ATX standard. You should watch it. Here it is. The rest of this blog will contain some spoilers for that video. UNIX workstations I have a bunch of 1990's RISC/UNIX workstatio

Microsoft says it will no longer use engineers in China for Department of Defense work

In Brief Following a Pro Publica report that Microsoft was using engineers in China to help maintain cloud computing systems for the U.S. Department of Defense, the company said it’s made changes to ensure this will no longer happen. The existing system reportedly relied on “digital escorts” to supervise the China-based engineers. But according to Pro Publica, those escorts — U.S. citizens with security clearances — sometimes lacked the technical expertise to properly monitor the engineers. I

Microsoft Will Erase Your Passwords in 2 Weeks: What to Do Now

Microsoft is axing passwords starting in August -- and if you use its Authenticator app, you'll want to be prepared. For years, Microsoft Authenticator has been a go-to for managing multifactor authentication and saved passwords. However, starting next month, it will no longer support passwords and will move to passkeys instead. That means your logins will soon rely more on things like PINs, fingerprint scans or facial recognition. Using a passkey can make your account safer, and it's a move I

New CrushFTP zero-day exploited in attacks to hijack servers

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. CrushFTP is an enterprise file transfer server used by organizations to securely share and manage files over FTP, SFTP, HTTP/S, and other protocols. According to CrushFTP, threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun

Debcraft – Easiest way to modify and build Debian packages

Debian packaging is notoriously hard. Far too many new contributors give up while trying, and many long-time contributors leave due to burnout from having to do too many thankless maintenance tasks. Some just skip testing their changes properly because it feels like too much toil. Debcraft is my attempt to solve this by automating all the boring stuff, and making it easier to learn the correct practices and helping new and old packagers better track changes in both source code and build artifac

CrushFTP zero-day exploited in attacks to gain admin access on servers

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. CrushFTP is an enterprise file transfer server used by organizations to securely share and manage files over FTP, SFTP, HTTP/S, and other protocols. According to CrushFTP, threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun