• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Flame Hijacks Windows Update

evilsofa

[H]F Junkie
Joined
Jan 1, 2007
Messages
10,077
I always thought the ultimate nightmare scenario for Windows security was for a malware writer to figure out how to infect PCs using Windows Update.

You might have noticed on Monday (June 4) a single Win7 update that Microsoft sent out through Windows Update. Turns out they were blocking fraudulent certificates used by the Flame malware, which were allowing it to use Microsoft Update to infect other PCs on an infected PC's network.

http://www.securelist.com/en/blog/2...dle_Flame_malware_spreading_vector_identified
 
Well I have the patch installed. Guess you just need to make some good backups!
 
This is a worry, if this is the future may as well turn off your PC
 
This is why I disable windows update service. Once in a while I will manually run the update manually. I do the same for all systems that have auto updates. I rather know when something is being changed and have control over it then to let an automated process do it.
 
This is why I disable windows update service. Once in a while I will manually run the update manually. I do the same for all systems that have auto updates. I rather know when something is being changed and have control over it then to let an automated process do it.

I would rather have my pc up to date with out having to think about it. Got the patch and was "safe" from the threat before it was publicly discussed.
 
I would rather have my pc up to date with out having to think about it. Got the patch and was "safe" from the threat before it was publicly discussed.
And if you got the flame update first (because public discussion =/= possibly found in the wild)? I think that's the point he was making.

But i agree, more automagic -> less to worry about.
 
And if you got the flame update first (because public discussion =/= possibly found in the wild)? I think that's the point he was making.

But i agree, more automagic -> less to worry about.

For me personally it would be easy to tell if an out of band update was applied which was not from microsoft. Tech news sites and forums always talk about updates when they come out, so if I got an update and there was no discussions going on then it would indicate an issue which would need attention. What to do about it is kind of up in the air.
Flamer has been out since 2010 and possibly 2007 from some of the reading i have done, just getting attention now.
 
Back
Top