0patch
@0patch
Microscopic cures for big security holes. 0patch (pronounced 'zero patch') Bluesky: https://bsky.app/profile/0patch.bsky.soci Mastodon: @[email protected]
Long Live Windows 10... With 0patch blog.0patch.com/2024/06/long-l…

Our researchers have confirmed this issue on freshly installed fully updated Windows Server 2025 domain controller, using a regular domain user as attacker. Instant domain controller BSOD by any domain user.
Welp... reported an issue to msrc, demonstrating that kerberos TGS request with a malformed PA-FOR-X509-USER struct will crash the LSASS on any win2025 domain controller. Got the default response :/ Dunno how I feel abt this, but this was the first and last time I'm doing this.
How MSPs Can Handle Windows 10 End of Support with 0patch blog.0patch.com/2025/05/how-ca…

A server update and maintenance operation is underway today, lasting until 1:00 PM CEST (GMT+2). During this period, 0patch Central will be unavailable and agent registration and syncing will not work; patches will keep getting applied.