Connect with us

Technology

Windows flaw lets hackers sneak into your PC over Wi-Fi

Published

on

Windows flaw lets hackers sneak into your PC over Wi-Fi

A new security issue was found in the Windows Wi-Fi driver that let hackers break into your PC through wireless networks. 

This flaw, which is now fixed, allowed attackers to run malicious programs on affected computers. It impacted all modern versions of Windows and Windows Server, and the hackers didn’t need to have any previous access to the target computer.

Fortunately, Microsoft has released a security update that addresses this Wi-Fi driver vulnerability. However, it’s crucial to keep your software up to date and follow best practices to minimize the risk of such attacks.

We’ll provide tips below on what you should do to protect yourself if a similar issue arises in the future.

GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE

Advertisement

Windows laptop computers  (Microsoft)

What you need to know about the security flaw

Microsoft labeled the vulnerability CVE-2024-30078 with a maximum severity of “Important.” It is described as a “Windows Wi-Fi Driver Remote Code Execution Vulnerability.” If we break down these terms, you’d understand that the flaw allows an attacker within Wi-Fi range of your computer to send a specially crafted network packet to the target and exploit your PC.

This vulnerability is dangerous because it can bypass all security checks, doesn’t need special permissions and requires no action from the user. For example, imagine you’re at a cafe using its public Wi-Fi. You’d expect some security measures to protect your device. But with this vulnerability, an attacker could easily sneak malware onto your laptop without you knowing. You wouldn’t have to click anything or give permission — just being connected to the Wi-Fi is enough. This could happen at any public hot spot, like at hotels, airports or cafes, putting many people at risk.

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

Microsoft admitted there weren’t any known active attacks utilizing this security hole. However, it described the vulnerability itself as fairly easy to exploit. While Microsoft downplays the immediate risk, these announcements can sometimes attract malicious hackers. The vulnerability affects every supported version of Windows, including unpatched versions of Windows 10 and Windows 11. It also affects all Windows Server versions from 2008 onward.

Advertisement
woman with laptop

A woman working  (Kurt “CyberGuy” Knutsson)

DON’T LET SNOOPS NEARBY LISTEN TO YOUR VOICEMAIL WITH THIS QUICK TIP

Microsoft’s response to its security vulnerability

On June 11, Microsoft released a patch that eliminates the security vulnerability. This patch also addresses 49 CVEs across Windows and its components, Office and its components, Azure Dynamic Business Central and Visual Studio. This is applicable if you are using a version of Windows that still receives security updates. If you are using an end-of-life version of Windows without an extended service contract, it is recommended to update to a supported version as soon as possible.

Update your Windows software now

In light of the recently discovered and patched Wi-Fi driver vulnerability, it is crucial for all Windows users to promptly update their software to ensure maximum protection against potential cyber threats. Keeping your operating system and other software up to date is one of the most effective ways to safeguard your devices from known vulnerabilities and security flaws. To update your Windows software and benefit from the latest security patches, follow these simple steps:

For Windows 10 and Windows 11

  • Click on the Start menu and select “Settings” (or press the Windows key + I shortcut).
  • In the Settings window, click on “Update & Security.”
  • Under the “Windows Update” section, click on “Check for updates.”
  • If updates are available, including the patch for the Wi-Fi driver vulnerability, Windows will download and install them automatically.
  • Once the installation is complete, you may be prompted to restart your computer to apply the updates.

For Windows 8.1 and earlier versions

  1. Open the Control Panel and navigate to “System and Security.”
  2. Under the “Windows Update” section, click on “Check for updates.”
  3. If updates are available, including the patch for the Wi-Fi driver vulnerability, select them and click “Install updates.”
  4. Follow the on-screen instructions to complete the installation process.
  5. Restart your computer if prompted to apply the updates.

By keeping your Windows software up to date, you not only protect yourself from the recently discovered Wi-Fi driver vulnerability but also ensure that your system is fortified against other known security threats. Regular software updates are essential for maintaining a secure and reliable computing environment. Remember, cybercriminals are constantly seeking new ways to exploit vulnerabilities, so it’s crucial to stay vigilant and promptly install updates as they become available. 

A LAPTOP

Windows laptop  (Microsoft)

CYBER SCAMMERS USE AI TO MANIPULATE GOOGLE SEARCH RESULTS 

Six ways to protect yourself from Wi-Fi cyberattacks

There are many ways a Wi-Fi network can be exploited by bad actors. However, you can protect yourself by following these steps.

Advertisement

1. Enable encryption: WPA2 and WPA3 (Wi-Fi-protected access) are the standard encryptions now. If your network is using WEP (wired equivalent privacy) security, this is outdated. New routers should automatically come with WPA2 or WPA3 encryption, but you may have to enable it to be sure your router is secure. Your wireless network manual will show you how to enable this on your particular network, but be sure to do so so your Wi-Fi requires a password.

2. Update your Wi-Fi password often: When you first set up a new router, it will come with a pre-set Wi-Fi router name and password. Be sure to change this as soon as you set it up and use a strong password. Always make sure your network requires a password to log in. It’s also important to change this information regularly. This makes it harder for anyone to hack into your network. Use these Best Password Managers for 2024 to help create and store your passwords.

3. Update firmware and software: As with computers and phones, it’s essential to keep your software up to date to help protect against security threats. Always run the latest software. Some routers will call this firmware, so make sure to keep that updated.

4. Install a strong antivirus program: Hackers often gain access to devices by sending infected emails or documents or tricking users into clicking a link that downloads malware. You can avoid all of this by installing antivirus software that will detect any potential threat before it can take over your device or router. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android & iOS devices.

5. Pick a secure router: If you’re in the market for a new router, check out my list of top routers. These routers are recommended not only for their security features but also for their compatibility with VPN service providers.

Advertisement

6. Use a VPN: A Virtual Private Network (VPN) can provide an additional layer of security, especially when accessing your network remotely. For best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android and iOS devices 

Remember, while no system can be completely invulnerable, these steps can significantly reduce the risk of cyberattacks on your Wi-Fi network.

Kurt’s key takeaway

The Wi-Fi driver flaw on Windows is particularly concerning because it gives bad actors an open invitation to exploit your computer. Since Microsoft has now made the vulnerability public, cybercriminals may try to exploit it even though the Redmond-based company says it has patched it. As a rule of thumb, avoid using public Wi-Fi networks you don’t trust. If necessary, connect to a VPN, turn off file sharing, and disable auto-connect.

Do you often use public Wi-Fi networks? If yes, do you take any measures to protect your digital privacy and safety? Let us know by writing us at Cyberguy.com/Contact

Advertisement

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter

Ask Kurt a question or let us know what stories you’d like us to cover

Follow Kurt on his social channels

Answers to the most asked CyberGuy questions:

Copyright 2024 CyberGuy.com.  All rights reserved.

Advertisement

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

This Matter-enabled smart ceiling light costs under $100

Published

on

This Matter-enabled smart ceiling light costs under $100

Developed by Apple, Amazon, Google, and Samsung (and others), Matter is an open-sourced, IP-based connectivity software layer for smart home devices. It works over Wi-Fi, ethernet, and the low-power mesh networking protocol Thread and currently supports over 30 device types. These include lighting, thermostats, locks, refrigerators, dishwashers, dryers, ovens, smoke alarms, air quality monitors, EV chargers, and more.

A smart home gadget with the Matter logo can be set up and used with any Matter-compatible ecosystem via a Matter controller and controlled by them simultaneously, a feature called Multi-Admin.

Amazon Alexa, Google Home, Samsung SmartThings, and Apple Home are some major smart home platforms supporting Matter, along with hundreds of device manufacturers.

Continue Reading

Technology

Facebook, Instagram are using your data to train AI: Learn how to protect it

Published

on

Facebook, Instagram are using your data to train AI: Learn how to protect it

Meta may have paused its plans to train artificial intelligence models for the lucky ones living in Europe, where laws protect people using Facebook and Instagram better than Americans. Here in the good ole USA, both Facebook and Instagram have already been combing through public posts from U.S. accounts to train and improve its AI capabilities, including its chatbot, since last year.

The proposed privacy policy update for European Union and U.K. users, originally scheduled for June 26, would have allowed Meta to use publicly shared content for AI training. However, users and regulatory agencies opposed this plan, leading to its indefinite postponement in those regions.

In contrast, Meta has been incorporating public data from U.S. accounts into its generative AI features without offering an opt-out option. But I’ve got some privacy tweaks for you to make on both social networks we will get to in a second.

We reached out to Meta, and a company spokesperson provided us with this statement: “Across the internet, public information is being used to train AI. This is not unique to our services. We’re committed to building AI responsibly and believe it’s important that people understand how we train the models that power our generative AI product.”

GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE

Advertisement

Facebook account on a smartphone (Kurt “CyberGuy” Knutsson)

What you need to know about Meta’s AI training

AI chatbots and other large language models, such as those creating images, use your personal data for training. Companies like Google and OpenAI trained their AI models using data shared on the internet. It’s important to note that these companies did not feed your social media data directly to AI. Instead, they relied on data posted by publishers and small websites. They also made agreements with large publishers and companies like News Corp and Reddit to use their content legally.

However, Meta’s AI training is different. The company will use every personal detail of your life that you posted publicly. This includes photos and videos in your feed and captions on your posts and Reels. Meta can only use this information if you have a public account. Private accounts, Facebook and Instagram stories, and Threads data will be spared. Meta says it also doesn’t use anything from private, direct messaging on Facebook and Instagram, even for people with public accounts.

Users in the U.S. and other countries without national data privacy laws don’t have a sure way to stop Meta from using their data to train AI. Interestingly, people in the U.S. might never have known that Meta is using their personal data to train AI if it weren’t for the European Union (EU). The EU has laws that make companies disclose how they get, use and keep data – and offer opt-outs. Because of these laws, Meta had to email EU users about the policy change.

DON’T FALL FOR THAT ‘LOOK WHO DIED’ FACEBOOK MESSAGE TRAP

Advertisement

How to stop Meta from using your data to train AI

You can’t stop Meta from training its AI on your personal data unless you make your Facebook or Instagram account private. The other option to stop the social media giant from using your personal data is to delete your public posts. Deleting stuff might be a little too much, but below, I show you how to make your account private on both Instagram and Facebook.

If you have a Facebook account:

Open your Facebook account on your phone or computer. Note: I am using my phone for this tutorial.

  • Select the Menu
  • Tap Settings & privacy
  • Select Settings
Facebook, Instagram are using your data to train AI: Learn how to protect it

Steps to stop Meta’s AI from training with your data (Kurt “CyberGuy” Knutsson)

  • Scroll to where it says Audience and visibility
  • Click Posts
  • Then select an option other than Public, such as Friends or Only Me
Facebook, Instagram are using your data to train AI: Learn how to protect it

Steps to stop Meta’s AI from training with your data (Kurt “CyberGuy” Knutsson)

If you have an Instagram account:

  • Select the profile tab in the bottom right
  • Tap the three lines in the top right corner to open Settings and activity
Facebook, Instagram are using your data to train AI: Learn how to protect it

Steps to stop Meta’s AI from training with your data (Kurt “CyberGuy” Knutsson)

  • Tap Account privacy and toggle your account to private so it appears blue
Facebook, Instagram are using your data to train AI: Learn how to protect it

Steps to stop Meta’s AI from training with your data (Kurt “CyberGuy” Knutsson)

SCAMMERS ARE USING FAKE NEWS AND MALICIOUS LINKS TO TARGET YOU IN AN EMOTIONAL FACEBOOK PHISHING TRAP

How to remove data from the internet

While you can stop Meta from using your data by making your account private, other tech companies can still use your publicly available data. Invest in a data removal service to remove your data online. No service promises to remove all your data from the internet, but having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period. Remove your personal data from the internet with my top picks here.

Kurt’s key takeaway

Tech companies are chasing after your data to get ahead in the AI race. Google already uses data from multiple platforms to train its AI, and OpenAI was one of the first to do this. Meta wants in on the action by using your Facebook and Instagram posts. This isn’t fair, and U.S. users should have the same control over their data as those in the EU. It’s time for the government to introduce stricter data protection laws to stop big tech giants from exploiting Americans’ data.

Advertisement

Would you consider making your social media accounts private to prevent companies like Meta from using your data? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most asked CyberGuy questions:

Advertisement

Copyright 2024 CyberGuy.com. All rights reserved.

Continue Reading

Technology

Tesla Cybertuck recalled again, this time over faulty wiper and trim

Published

on

Tesla Cybertuck recalled again, this time over faulty wiper and trim

Tesla is again issuing a physical recall of its Cybertruck. This time it’s recalling 11,688 of its electric pickups due to a faulty windshield wiper that could reduce visibility for the driver, and 11,383 Cybertrucks due to trim in the truck bed that could come loose and create a road hazard for others.

Issues with the gigantic wiper had surfaced in owner forums in recent weeks and reportedly delayed Cybertruck deliveries on short notice. The NHTSA recall notice for the wiper says that “excessive electrical current can cause the front windshield wiper motor controller to fail.” Tesla service will replace the wiper motor, free of charge. 

Regarding the trim, “Tesla service will apply adhesion promoter and pressure sensitive tape or replace missing applique as necessary, free of charge,” according to a separate NHTSA notice.

Continue Reading

Trending