Skip to main content
  1. Home
  2. Computing
  3. News

You definitely want to install these 90 Windows security patches

Add as a preferred source on Google
Windows 11 logo on a laptop.
Microsoft

Microsoft has issued security updates to address 90 vulnerabilities, some of which hackers are actively exploiting, in a blog post yesterday. These flaws allow hackers to bypass security features and gain unauthorized access to your PC’s system, highlighting the need to keep your Windows computer updated.

Nine are rated Critical, 80 of the flaws are rated Important, and only one is rated Moderate in severity. In addition, the software giant has patched 36 vulnerabilities in its Edge browser in the past month to avoid issues with its browser. Users will be happy to know that the patches are for six actively exploited zero-days, including CVE-2024-38213. This lets attackers bypass SmartScreen protections but requires the user to open a malicious file. TrendMicro’s Peter Girnus, who discovered and reported the flaw, proposed it could be a workaround for CVE-2023-36025 or CVE-2024-21412 that DarkGate malware operators misused.

Recommended Videos

“An attacker could leverage this vulnerability by enticing a victim to access a specially crafted file, likely via a phishing email,” Scott Caveza, staff research engineer at Tenable, said about CVE-2024-38200. He said, “Successful exploitation of the vulnerability could result in the victim exposing New Technology Lan Manager (NTLM) hashes to a remote attacker. NTLM hashes could be abused in NTLM relay or pass-the-hash attacks to further an attacker’s foothold into an organization.”

The development has caught the eye of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add these Flaws to the Known Exploited Vulnerabilities (KEV) catalog. Federal agencies have until September 3, 2024, to apply these fixes. The update also takes care of a privilege escalation flaw found in the Print Spooler component (CVE-2024-38198, CVSS score:7.8) that gives attackers system privileges.

  • CVE-2024-38189 (CVSS score: 8.8) — Microsoft Project Remote Code Execution Vulnerability
  • CVE-2024-38178 (CVSS score: 7.5) — Windows Scripting Engine Memory Corruption Vulnerability
  • CVE-2024-38193 (CVSS score: 7.8) — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
  • CVE-2024-38106 (CVSS score: 7.0) — Windows Kernel Elevation of Privilege Vulnerability
  • CVE-2024-38107 (CVSS score: 7.8) — Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
  • CVE-2024-38213 (CVSS score: 6.5) — Windows Mark of the Web Security Feature Bypass Vulnerability
  • CVE-2024-38200 (CVSS score: 7.5) — Microsoft Office Spoofing Vulnerability
  • CVE-2024-38199 (CVSS score: 9.8) — Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
  • CVE-2024-21302 (CVSS score: 6.7) — Windows Secure Kernel Mode Elevation of Privilege Vulnerability
  • CVE-2024-38202 (CVSS score: 7.3) — Windows Update Stack Elevation of Privilege Vulnerability
Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Twitch is using your streams to train Amazon’s AI, and you’re opted in by default
Turns out your favorite stream might secretly be teaching Amazon's AI a thing or two.
Twitch logo

Twitch has quietly started feeding your streams, VODs, and clips into Amazon's AI training pipeline, and the opt-out button is tucked so deep in your settings that most people will never stumble on it.

As Kotaku reports, streaming reporter Zach Bussey spotted a new toggle inside Twitch's account settings on August 12 that lets you block your content from training Amazon's generative AI tools. The screenshot spread quickly, and so did the direct link to the exact settings page, mostly because Twitch never bothered to announce the change in the first place.

Read more
Qualcomm reveals Snapdragon C specs for budget laptops, and Intel could have a serious headache
More speed, better battery, and a price built for everyone.
Qualcomm Snapdragon C

Qualcomm wants to fix the biggest problem with budget laptops: performance and battery life. In May of this year, the company showed off its entry-tier new Snapdragon C Platform, made for budget laptops starting at $300, promising speed, battery life, and AI smarts that budget shoppers usually have to skip.

Now, the chip giant has just revealed the specs for its latest chip and if what it shows comes true, Intel is going to have a big headache on its hands. But competition is good for consumers, so they will be the real winners here. 

Read more
This GitHub project wants to strip AI watermarks from your content, and things are getting interesting
This open-source tool is trying to remove the fingerprints AI leaves behind
Electronics, Phone, Mobile Phone

AI companies are increasingly looking for ways to mark content generated by their models. Now, someone has built an open-source tool designed to remove some of those marks.

A GitHub project called watermarks-remover is designed to strip different types of AI provenance signals from text and files. According to its documentation, it can work with invisible Unicode characters, statistical text watermarks and metadata embedded in formats including PNG, JPEG, SVG, PDF, DOCX, ODT, HTML and Markdown.

Read more