## The Information Highway

# The Information Highway

## [Microsoft says recent Windows 11 updates break SSH connections](https://lbttechgroup.com/index.php/blog/microsoft-says-recent-windows-11-updates-break-ssh-connections)
Microsoft has confirmed that last month's Windows security updates are breaking SSH connections on some Windows 11 22H2 and 23H2 systems.

## [D-Link won’t fix critical flaw affecting 60,000 older NAS devices](https://lbttechgroup.com/index.php/blog/d-link-wont-fix-critical-flaw-affecting-60-000-older-nas-devices)
More than 60,000 D-Link network-attached storage devices that have reached end-of-life are vulnerable to a command injection vulnerability with a publicly available exploit.

## [Unpatched Mazda Connect bugs let hackers install persistent malware](https://lbttechgroup.com/index.php/blog/unpatched-mazda-connect-bugs-let-hackers-install-persistent-malware)
Attackers could exploit several vulnerabilities in the Mazda Connect infotainment unit, present in multiple car models including Mazda 3 (2014-2021), to execute arbitrary code with root permission.

## [Palo Alto Networks warns of potential PAN-OS RCE vulnerability](https://lbttechgroup.com/index.php/blog/palo-alto-networks-warns-of-potential-pan-os-rce-vulnerability)
Today, cybersecurity company Palo Alto Networks warned customers to restrict access to their next-generation firewalls because of a potential remote code execution vulnerability in the PAN-OS management interface.

## [HPE warns of critical RCE flaws in Aruba Networking access points](https://lbttechgroup.com/index.php/blog/hpe-warns-of-critical-rce-flaws-in-aruba-networking-access-points)
Hewlett Packard Enterprise (HPE) released updates for Instant AOS-8 and AOS-10 software to address two critical vulnerabilities in Aruba Networking Access Points.

## [Black Basta ransomware poses as IT support on Microsoft Teams to breach networks](https://lbttechgroup.com/index.php/blog/black-basta-ransomware-poses-as-it-support-on-microsoft-teams-to-breach-networks)
The BlackBasta ransomware operation has moved its social engineering attacks to Microsoft Teams, posing as corporate help desks contacting employees to assist them with an ongoing spam attack.

## [Microsoft ends development of Windows Server Update Services (WSUS)](https://lbttechgroup.com/index.php/blog/microsoft-ends-development-of-windows-server-update-services-wsus)
Microsoft has officially announced that Windows Server Update Services (WSUS) is now deprecated, but plans to maintain current functionality and continue publishing updates through the channel.

## [Microsoft to start force-upgrading Windows 22H2 systems next month](https://lbttechgroup.com/index.php/blog/microsoft-to-start-force-upgrading-windows-22h2-systems-next-month)
Microsoft announced that Windows 11 installs reaching the end of support next month, on October 8, will be force-upgraded to Windows 11 23H2.

## [QR codes bypass browser isolation for malicious C2 communication](https://lbttechgroup.com/index.php/blog/qr-codes-bypass-browser-isolation-for-malicious-c2-communication)
Mandiant has identified a novel method to bypass browser isolation technology and achieve command-and-control operations through QR codes.

## [Microsoft expands Recall preview to Intel and AMD Copilot+ PCs](https://lbttechgroup.com/index.php/blog/microsoft-expands-recall-preview-to-intel-and-amd-copilot-pcs)
Microsoft is now testing its AI-powered Recall feature on AMD and Intel-powered Copilot+ PCs enrolled in the Windows 11 Insider program.

## [Microsoft says having a TPM is "non-negotiable" for Windows 11](https://lbttechgroup.com/index.php/blog/microsoft-says-having-a-tpm-is-non-negotiable-for-windows-11)
Microsoft made it abundantly clear this week that Windows 10 users won't be able to upgrade to Windows 11 unless their systems come with TPM 2.0 support, stating it's a "non-negotiable" requirement.

## [FBI shares tips on how to tackle AI-powered fraud schemes](https://lbttechgroup.com/index.php/blog/fbi-shares-tips-on-how-to-tackle-ai-powered-fraud-schemes)
The FBI warns that scammers are increasingly using artificial intelligence to improve the quality and effectiveness of their online fraud schemes, ranging from romance and investment scams to job hiring schemes.

## [BT unit took servers offline after Black Basta ransomware breach](https://lbttechgroup.com/index.php/blog/bt-unit-took-servers-offline-after-black-basta-ransomware-breach)
Multinational telecommunications giant BT Group (formerly British Telecom) has confirmed that its BT Conferencing business division shut down some of its servers following a Black Basta ransomware breach.
