Cybersecurity
Security Agency Discovers Serious Flaw in Microsoft Windows
(Bloomberg) –The National Security Agency alerted Microsoft Corp. that it had found a vulnerability in Windows operating systems that could enable cyber intrusions, according to two people familiar with the matter.
The news comes hours before Microsoft is scheduled to release a security update, which is part of a company practice of disclosing newly found software vulnerabilities in hardware.
There isn’t an active cyber-attack, according to Microsoft.
Anne Neuberger, the NSA’s director of cybersecurity, has scheduled a press briefing on Tuesday, amid an agency push to be more transparent and friction between tech companies and the government in recent years over vulnerability disclosure.
The flaw lies in a part of Windows software known as Crypt32.dll, according to one of the people who requested anonymity because the information isn’t yet public. That file is used by the Windows and Windows Server operating systems — to implement “many of the Certificate and Cryptographic Messaging functions in the CryptoAPI, such as CryptSignMessage” — according to Microsoft. This means that the flaw could affect a broad range of users.
Microsoft has a policy of regularly releasing security updates on the second Tuesday of each month, and this update aligns with that schedule, according to a Monday statement by Jeff Jones, a Senior Director at the company.
“We follow the principles of coordinated vulnerability disclosure (CVD) as the industry best practice to protect our customers from reported security vulnerabilities,” Jones said in the statement. “To prevent unnecessary risk to customers, security researchers and vendors do not discuss the details of reported vulnerabilities before an update is available.”
News of the NSA’s discovery was previously reported by The Washington Post and Krebs on Security, a cybersecurity blog.
-
Banking & Finance1 month agoOman Oil Marketing Company Concludes Its Annual Health, Safety, Environment, and Quality Week, Reaffirming People and Safety as a Top Priority
-
News2 months agoOIG Appoints New CEO to Lead Its Next Chapter of Excellence
-
News2 months agoReport: How India & The Middle East Are Exploiting Immense Economic Synergies
-
Uncategorized2 months agoOman’s ISWK Cambridge Learners Achieve ‘Top in the World’ and National Honours in June 2025 Cambridge Series
-
Economy2 months agoPrime Minister of India Narendra Modi to Visit the Sultanate of Oman on 17-18 December
-
News1 month agoJamal Ahmed Al Harthy Honoured as ‘Pioneer in Youth Empowerment through Education and Sport’ at CSR Summit & Awards 2025
-
Economy2 months agoOman’s Net Wealth Reaches $300 Billion in 2024, Poised for Steady Growth
-
News2 months agoIHE Launches Eicher Pro League of Trucks & Buses in Oman
