PSA: Update Windows 10 Right Now, NSA Posts Critical Vulnerability


You know a security issue is going to be a big problem when the National Security Agency is posting an APB for people to update their computers as soon as possible.

The United States Department of Defense has issued a critical security warning advising users of Windows 10 to ensure that their operating systems are up to date. The NSA identified a vulnerability that will allow malicious software to be installed on a machine by fooling Windows into thinking that it is an official update. The most up to date versions of Windows have allegedly patched this bug, and the department warns that it expects exploits to start cropping up in the very near future.

NSA has discovered a critical vulnerability (CVE-2020-0601) affecting Microsoft Windows®1 cryptographic functionality. The certificate validation vulnerability allows an attacker to undermine how Windows verifies cryptographic trust and can enable remote code execution. The vulnerability affects Windows 10 and Windows Server 2016/2019 as well as applications that rely on Windows for trust functionality. Exploitation of the vulnerability allows attackers to defeat trusted network connections and deliver executable code while appearing as legitimately trusted entities. Examples where validation of trust may be impacted include:

  • HTTPS connections
  • Signed files and emails
  • Signed executable code launched as user-mode processes

The vulnerability places Windows endpoints at risk to a broad range of exploitation vectors. NSA assesses the vulnerability to be severe and that sophisticated cyber actors will understand the underlying flaw very quickly and, if exploited, would render the previously mentioned platforms as fundamentally vulnerable. The consequences of not patching the vulnerability are severe and widespread. Remote exploitation tools will likely be made quickly and widely available. Rapid adoption of the patch is the only known mitigation at this time and should be the primary focus for all network owners.

Source: NSA

Perfect World Entertainment Publishing Gigantic


Gigantic_Swifties_02

Perfect World Entertainment today announced a new partnership deal to publish Gigantic, the free to play action MOBA by Motiga Games, on its Arc client. Gigantic will join first party titles including Champions Online, Neverwinter, and Star Trek Online, as Perfect World Entertainment continues to ramp up its efforts to introduce quality games to the PC and console market.

Gigantic is described as “a free-to-play action MOBA developed by Motiga that pits teams of five heroes and their massive guardians against each other in highly intense battles across a variety of maps. The game combines explosive combat with fast-paced teamwork, strategy, and skill, as players fight to defeat the opposing guardian with spells, guns, and swords.”

“2016 continues to be a year of growth for Perfect World Entertainment,” said Bryan Huang, CEO of Perfect World Entertainment. “As we expand our line-up of partnered developers, we always want to ensure that our team is publishing quality content for gamers. The passion that the Motiga team has makes them a perfect partner for PWE as we accomplish our goal of bringing quality products to the industry.”

Motiga plans to have Gigantic ready for release on PC, the Windows 10 store, and Xbox One. The accompanying trailer shows a game that looks to be similar to SMITE, albeit with more action elements.

Neverwinter Coming To The Windows Store


NW_Win10_Announce-(5)

Perfect World Entertainment has announced that Dungeons & Dragons MMO Neverwinter will be heading to the Windows Store for Windows 10 users. When the game does launch, you’ll be able to boot it as an app from the store, introducing the game to a new audience of gamers. For everyone else, nothing will change. Neverwinter will still be available via Arc.

For more information on Neverwinter, check out MMO Fallout’s coverage and on the official website.

(Source: Perfect World press release)