"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2020-01-14T13:18:32Z"
data-video-section="politics"
data-canonical-url="https://www.cnn.com/videos/politics/2020/01/14/russians-hack-burisma-brian-fung-live-newday-ldn-vpx.cnn"
data-branding-key=""
data-video-slug="russians hack burisma brian fung live newday ldn vpx"
data-first-publish-slug="russians hack burisma brian fung live newday ldn vpx"
data-video-tags="burisma,companies,continents and regions,crime, law enforcement and corrections,criminal offenses,digital crime,digital security,eastern europe,europe,government and public administration,impeachment,military,political scandals,politics,russia,scandals,technology,ukraine"
data-details="">
Video Ad Feedback
Russians hack company at center of impeachment scandal
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2020-01-14T13:18:32Z"
data-video-section="politics"
data-canonical-url="https://www.cnn.com/videos/politics/2020/01/14/russians-hack-burisma-brian-fung-live-newday-ldn-vpx.cnn"
data-branding-key=""
data-video-slug="russians hack burisma brian fung live newday ldn vpx"
data-first-publish-slug="russians hack burisma brian fung live newday ldn vpx"
data-video-tags="burisma,companies,continents and regions,crime, law enforcement and corrections,criminal offenses,digital crime,digital security,eastern europe,europe,government and public administration,impeachment,military,political scandals,politics,russia,scandals,technology,ukraine"
data-details="">
Video Ad Feedback
Russians hack company at center of impeachment scandal
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2024-03-31T00:30:19Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2024/03/30/cocoa-chocolate-pricing-surge-easter-rodriguez-nr-vpx.cnn"
data-branding-key=""
data-video-slug="cocoa chocolate pricing surge easter rodriguez nr vpx"
data-first-publish-slug="cocoa chocolate pricing surge easter rodriguez nr vpx"
data-video-tags="agricultural commodities,agriculture,agriculture, forestry, and commercial fishing,banking, finance and investments,business and industry sectors,business, economy and trade,commodity markets,consumer products,domestic alerts,domestic-business,easter,financial markets and investing,food and drink,food products,holidays and observances,iab-agriculture,iab-business,iab-business and finance,iab-business banking & finance,iab-commodities,iab-desserts and baking,iab-economy,iab-financial industry,iab-food & drink,iab-industries,international alerts,international-business,kinds of foods and beverages,price increases,sweets and desserts"
data-details="">
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2024-03-22T12:43:25Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2024/03/22/trump-truth-social-prepares-to-go-public-egan-cnntm-vpx.cnn"
data-branding-key=""
data-video-slug="trump truth social prepares to go public egan cnntm vpx"
data-first-publish-slug="trump truth social prepares to go public egan cnntm vpx"
data-video-tags="companies,domestic alerts,domestic-business,domestic-us politics,donald trump,iab-computing,iab-internet,iab-politics,iab-social networking,iab-technology & computing,international alerts,international-business,international-us politics,political figures - us,social media,society,trump media & technology group"
data-details="">
Video Ad Feedback
Donald Trump may be on the verge of a massive financial win
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2024-03-21T05:30:53Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2024/03/21/china-nongfu-spring-boycott-stewart-lkl-hnk-vpx.cnn"
data-branding-key=""
data-video-slug="china nongfu spring boycott stewart lkl hnk vpx"
data-first-publish-slug="china nongfu spring boycott stewart lkl hnk vpx"
data-video-tags="beverages,bottled water,boycotts,business and industry sectors,business, economy and trade,consumer products,food and drink,iab-food & drink,iab-non-alcoholic beverages,kinds of foods and beverages"
data-details="">
Video Ad Feedback
See why some Chinese people are boycotting a popular brand
The National Security Agency recently alerted Microsoft to a major flaw in its Windows operating system that could let hackers pose as legitimate software companies, agency officials said on Tuesday.
Microsoft
(MSFT) issued a software update on Tuesday to fix the vulnerability, as part of its normal schedule for releasing softwarepatches.
News of the vulnerability and patch were first reported by independent journalist Brian Krebs, who said Microsoft provided its software fix to the military and key infrastructure companies ahead of Tuesday’s public release.
Microsoft said in a statement Monday night that it provides advance versions of its updates to some users under a special testing program. Jeff Jones, a senior director at Microsoft, declined to discuss specifics of the flaw “to prevent unnecessary risk to customers.”
The company did not immediately respond to a request for comment on Tuesday.
The NSA’s rare announcement of the flaw, along with its decision to warn Microsoft rather than exploit the bug for intelligence purposes, underscores the magnitude of the threat it could pose to businesses, consumers and government agencies worldwide.
The NSA said that, while it has shared vulnerability information with the private sector in the past, this marks the first time that it has come forward publicly to do so. The agency said thedecision reflects an effort to build trust with cybersecurity researchers.
“Part of building trust is showing the data,” Anne Neuberger, the NSA’s director of cybersecurity, told reporters on a conference call Tuesday. Because the NSA has never allowed itself to be linked to a vulnerability disclosure, she said, “it’s hard for entities to trust that we take this seriously. And ensuring vulnerabilities can be mitigated is an absolute priority.”
The NSA did not use the vulnerability to exploit adversaries, and the bug was turned over to Microsoft as soon as it was discovered, Neuberger added. She said the NSA has not detected any other entities using the bug.
The Department of Homeland Security said on the call that it would issue a bulletin to federal agencies advising them to install the Microsoft patches immediately.
The flaw concerns a core Windows function that verifies the legitimacy of apps and programs, a feature known as CryptoAPI.
“It’s the equivalent of a building security desk checking IDs before permitting a contractor to come up and install new equipment,” said Ashkan Soltani, a security expert and former chief technologist for the Federal Trade Commission.
By compromising that validation feature, hackers could easily impersonate “good” software companies to install bad software, Soltani said, potentially allowing them to spy on computer users or hold their devices hostage for ransom.