NSA Windows 10 security disclosure raises questions
Summary
Amit Yoran, chairman and CEO at Tenable and a founding director of the US’s Computer Emergency Readiness Team (Cert), said it was rare, if not unprecedented, for a government agency to disclose its discovery of a critical vulnerability with a supplier. None of these questions change what organisations need to do at this point to protect themselves, but their answers might tell us a lot more about the environment we operate in.” Chris Morales, head of security analytics at Vectra, said: “I would be interested to understand what makes this exploit worth reporting to Microsoft instead of keeping for their personal arsenal, as they have in the past. This was picked up on by independent security researcher Brian Krebs, who worked his own sources to reveal that Microsoft planned to release a fix for an “extraordinarily serious vulnerability in a core cryptographic component present in all versions of Windows”. Krebs said his sources had told him Microsoft had, in fact, already shipped a patch to branches of the US military and to other key high-value customers and targets, including those with responsibility for managing global internet infrastructure. Coming on the day that Microsoft formally discontinued support for Windows 7, Krebs’ blog was swiftly picked up across the cyber security sector, prompting a wave of media stories beforeo the NSA’s disclosure in a press call on 14 January.