By continuing to use the site or forum, you agree to the use of cookies, find out more by reading our GDPR policy

Windows 10 version 1909 codenamed ’19H2′, which is a minor update that is supposed to roll out later this year to all Windows 10 users, might arrive as early as next week. Windows 10 version 1909 is shipping to several Insiders on the Release Preview Ring and today ESDs for all languages have been spotted on WSUS. We have gathered the list of all available ESDs from private forums and according to the data, Windows 10 version 1909 Build 18363.356 ESD is currently available on Windows Server Update Services server (WSUS). The version number in ESD is listed as ‘18363.356.190918-2052.19h2’. The presence of ESD (electronic software delivery) on WSUS indicates this could well be the final release candidate (RTM). However, it’s likely that Microsoft won’t ship Build 18363.356 to the general public since a newer Build 18363.387 is available for Release Preview Ring testers. Microsoft is also holding an event on October 2 to announce Surface 7, Surface Pro 7, Surface Laptop 3 and Surface Centaurus. By the looks of things, Microsoft might announce Windows 10 version 1909 on October 2 and the update would begin rolling out on October 3 or sooner. Windows 10 19H2 won’t come with several new features, as Microsoft has focused more on performance and reliability areas of the OS in this release, including significant improvements for the Windows Update mechanism. Windows 10 19H2 doesn’t yet have a name and it’s unclear if it will be launched as ‘October 2019 Update’, retaining the traditional naming scheme. More information should be shared on October 2. According to Microsoft, this new version of Windows will install just like a regular patch for Windows 10 May 2019 Update PCs. We covered the key features of Windows 10 version 1909 in a previous article. One of the significant change is the implementation of a rotation policy that would distribute work more fairly on PCs with favored cores. This could boost performance and offer faster process execution. Follow this thread on OUR FORUM.

Windows ships with a full volume encryption tool called BitLocker. The feature used to trust any SSD that claimed to offer its own hardware-based encryption, but that changed in the KB4516071 update to Windows 10 released on September 24, which now assumes that connected SSDs don't actually encrypt anything. "SwiftOnSecurity" called attention to this change on September 26. The pseudonymous Twitter user then reminded everyone of a November 2018 report that revealed security flaws, such as the use of master passwords set by manufacturers, of self-encrypting drives. That meant people who purchased SSDs that were supposed to help keep their data secure might as well have purchased a drive that didn't handle its own encryption instead. Those people were actually worse off than anticipated because Microsoft set up BitLocker to leave these self-encrypting drives to their own devices. This was supposed to help with performance--the drives could use their own hardware to encrypt their contents rather than using the CPU--without compromising the drive's security. Now it seems the company will no longer trust SSD manufacturers to keep their customers safe by themselves. Here's the exact update Microsoft said it made in KB4516071: "Changes the default setting for BitLocker when encrypting a self-encrypting hard drive. Now, the default is to use software encryption for newly encrypted drives. For existing drives, the type of encryption will not change." People can also choose not to have BitLocker encrypt these drives, too, but the default setting assumes they don't want to take SSD manufacturers at their word. We have plenty more posted on OUR FORUM.

Microsoft and Cisco Talos identified a new malware which has affected thousands of computers in the US as well as in Europe. The companies stated that this malware has an ability to turn the PCs into proxies for performing malicious activity. This malware was named by Microsoft as Nodersok while the Cisco Talos called it Divergent. This threat has many of its own components to carry out malicious activities but it also takes advantage of existing tools. It should be mentioned that this malware leverages widely used Node.js framework and WinDivert, which is a user-mode packet capture-and-divert package for Windows 2008, Windows 7, Windows 8, Windows 10 and Windows 2016 to turn infected machines into proxies for malicious behavior. Microsoft and Cisco Talos both the companies released the threat report on this malware on Wednesday, September 25 in separate blog posts. As per the Microsoft researchers once Nodersok turns the systems into unwitting proxies "it uses them as "a relay to access other network entities (websites, C&C servers, compromised machines, etc.), which can allow them to perform stealthy malicious activities." While both the companies had a different opinion as to exactly what it does, Cisco Talos researchers said that "This malware can be leveraged by an attacker to target corporate networks and appears to be primarily designed to conduct click-fraud. It also features several characteristics that have been observed in other click-fraud malware, such as Kovter." The company believes that this malware is still to be in active development. Follow this thread to OUR FORUM to learn more.