Blog - Page 26 of 170 - Techbest - Top Tech Reviews In Australia

Microsoft Addresses Serious “BadSuccessor” Zero-Day Authentication Vulnerability


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Microsoft’s August Patch Update: Resolving the ‘BadSuccessor’ Zero-Day Issue

Quick Overview

  • Microsoft tackles ‘BadSuccessor’, a zero-day vulnerability, in its August 2025 Patch Wednesday rollout.
  • This issue impacts Windows Server 2025’s use of the Kerberos protocol.
  • Security expert Yuval Gordon recorded the vulnerability, recognized as CVE-2025-53779.
  • Despite its possible seriousness, Microsoft initially classified it as moderate.
  • The August update resolves 107 vulnerabilities, encompassing critical remote code execution defects.

Microsoft Tackles ‘BadSuccessor’ Vulnerability

Microsoft addresses "BadSuccessor" zero-day authentication flaw

In the most recent Patch Wednesday update for August 2025, Microsoft has introduced a vital correction for a zero-day vulnerability known as “BadSuccessor.” This flaw, which became public prior to having a patch available, affects the implementation of the Kerberos network authentication protocol in Windows Server 2025.

Detection and Documentation

The flaw was initially documented in May 2025 by Akamai security professional Yuval Gordon. Listed as CVE-2025-53779, this privilege escalation vulnerability permits attackers to compromise any user within Active Directory. Gordon’s findings suggested that taking advantage of this vulnerability is quite simple, raising alarms about its possible consequences.

Microsoft’s Reaction

After receiving a notification from Gordon, Microsoft’s Security Response Centre (MSRC) validated the flaw. Nevertheless, early evaluations categorized the vulnerability as moderate, which postponed immediate action. Despite this, security companies, such as Rapid7 and Qualys, have emphasized the flaw’s capacity to promote attackers to domain administrator capabilities.

Patch Wednesday: Tackling Major Vulnerabilities

In addition to addressing BadSuccessor, Microsoft’s August patch bundle resolves a total of 107 vulnerabilities. These encompass significant remote code execution flaws in Windows, Microsoft Office, the Hyper-V hypervisor, and the Message Queuing component. Although there is no proof of active exploitation of the BadSuccessor vulnerability, the extensive nature of the update highlights the vital need for strong cybersecurity practices.

Conclusion

Microsoft’s August 2025 Patch Wednesday is a pivotal update in confronting the ‘BadSuccessor’ zero-day vulnerability. Initially deemed moderate, this flaw was subsequently acknowledged for its significant severity, especially regarding the risk to Active Directory environments. The update not only mitigates this particular vulnerability but also enhances defenses against a variety of other critical security threats.

Q: What is the ‘BadSuccessor’ vulnerability?

A: ‘BadSuccessor’ is a zero-day privilege escalation vulnerability in the Kerberos authentication protocol of Windows Server 2025, enabling attackers to compromise Active Directory users.

Q: How was the vulnerability identified?

A: The vulnerability was identified by Akamai security researcher Yuval Gordon in May 2025 and subsequently reported to Microsoft’s Security Response Centre.

Q: What is the importance of the August Patch Wednesday update?

A: The update addresses 107 vulnerabilities, including critical issues, thereby ensuring enhanced security across numerous Microsoft products.

Q: Was the ‘BadSuccessor’ vulnerability being actively exploited?

A: There is no evidence indicating active exploitation of the ‘BadSuccessor’ vulnerability at this moment.

Q: Why did Microsoft initially classify the vulnerability as moderate?

A: Microsoft’s initial evaluation did not regard the vulnerability as severe enough for swift action, although subsequent assessments by security firms highlighted its possible ramifications.

Q: What other vulnerabilities were resolved in the August update?

A: Along with ‘BadSuccessor’, the update rectified critical remote code execution bugs in Windows, Microsoft Office, Hyper-V, and the Message Queuing component.

Q: How can users protect themselves from such vulnerabilities?

A: Users should consistently update their software, promptly apply security patches, and adopt effective cybersecurity strategies to mitigate potential risks.

OnePlus Buds Nord 3 Pro Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

OnePlus Buds Nord 3 Pro, Starry Black

AI Revolutionizes Government Networking: Transitioning from Infrastructure Cost to Strategic Resource


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

  • AI converts government networking from an expense to a vital strategic resource.
  • State governments encounter issues related to staffing deficits and outdated infrastructure.
  • Networking driven by AI provides enhanced security and service efficiency.
  • HPE Aruba Networking acknowledged as a frontrunner in AI-enhanced networking solutions.
  • Government entities gain from insights based on data and adaptable cloud alternatives.

The AI Transformation in Government Networking

The AI Transformation in Government Networking: From Infrastructure Expense to Vital Resource

Revamping Government Infrastructure

Historically, network infrastructure has been viewed merely as a basic connectivity tool by state agencies, but that view is shifting. AI-driven networking solutions present a valuable opportunity for state governments to allocate scarce resources towards a significant return on investment, boosting security and service provision.

AI in Networking: A Necessary Advancement

Given the ongoing staffing deficits and aging infrastructure, AI in networking offers a strategic option for governmental agencies. “Previously, the network was merely seen as an expense. This is no longer true,” remarks Elissa McCormick, Senior Manager at HPE Aruba Networking.

Managing Varied Devices and Security Regulations

As various devices inundate government networks, conventional networking strategies become strained. AI’s capabilities prove essential by utilizing behavioral analysis to identify device trends and automatically implement suitable security measures.

Transformational Operations through AI

AI tackles governmental obstacles by reducing time dedicated to regular operational tasks. Rather than IT teams resolving network problems manually, AI solutions identify issues and offer resolutions, enhancing operational productivity.

Scalable Data-Driven Excellence

HPE’s AI networking harnesses data from millions of devices, facilitating precise anomaly identification and bolstering security and compliance. This intelligence is vital for overseeing IoT devices and avoiding unanticipated data leaks.

Acknowledgment and Adaptability in AI-Driven Solutions

HPE Aruba Networking is recognised by Gartner as a leader in AI-driven solutions. The adaptability provided by HPE allows government agencies to determine how they utilize networking solutions, aligning with varying data sovereignty needs.

Conclusion

Networking powered by AI is revolutionizing government infrastructure from an expenditure to a strategic resource. With improved security, efficiency, and flexibility, state governments can more effectively satisfy the rising expectations of citizens while addressing infrastructure challenges.

Q&A Session

Q: What obstacles do state governments encounter with traditional networking?

A: They face issues like staffing shortages, aging systems, and management of varied devices.

Q: In what way does AI enhance government networking?

A: AI provides superior security, operational effectiveness, and insights based on data, evolving networks into strategic resources.

Q: What recognition has HPE Aruba Networking attained?

A: It has been recognised as a leader by Gartner in the Magic Quadrant for Enterprise Wired and Wireless LAN Infrastructure.

Q: How does AI assist in managing diverse devices on government networks?

A: AI employs behavioral analysis to discern device trends and automatically implements relevant security policies.

Q: What flexibility do AI-powered solutions provide to government agencies?

A: They allow for flexibility in data management, enabling agencies to select cloud or local data centers depending on their requirements.

SUDIO N2 Wireless Earphones Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

SUDIO N2 (Purple) Wireless Earphones, Open Earphones, Bluetooth 5.3, iOS and Android Compatible, IPX4 Level, Waterproof Design, Scandinavian Design, SDGs, Sustainable, Gift

Researchers Discover Fresh Weaknesses in TETRA Secured Wireless Communications


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

vulnerabilities in TETRA Encrypted Wireless Communications

Quick Overview

  • Recent vulnerabilities in TETRA networks influence encryption robustness.
  • Serious weaknesses could enable attackers to insert harmful data.
  • Australian mining firms heavily rely on TETRA for their communication needs.
  • Experts urge for independent evaluations of TETRA networks.

Revealing New Weaknesses in TETRA Networks

Security researchers from Midnight Blue in the Netherlands have disclosed a series of critical vulnerabilities within TETRA (Terrestrial Trunked Radio) communication networks. These issues, unveiled via reverse-engineering and termed 2TETRA:2BURST, compromise the end-to-end encryption (E2EE) utilized by security agencies and elite forces.

Researchers detect vulnerabilities in TETRA wireless encryption

Insights into the Vulnerabilities

The investigation reveals six new security weaknesses, supplementing five that were previously recognized in 2023. The most critical, CVE-2025-52941, involves a compromised AES-128 encryption algorithm, diminishing its strength to a concerning 56 bits. Another weakness, CVE-2025-52943, targets networks employing multiple encryption methods, permitting attackers to take advantage of less secure keys to decrypt communications believed to be protected.

Consequences for the Industry

These vulnerabilities could allow intruders to interfere with industrial control systems within TETRA networks, leading to threats in sectors such as mining operations. This situation could result in unauthorized control over vital equipment such as SCADA systems.

Difficulties in Addressing the Issues

In contrast to conventional software vulnerabilities, these issues originate from essential design flaws in TETRA, which lack message authentication and replay resistance. The particular weaknesses affect the Sepura Embedded E2EE solution, yet other versions may also be vulnerable.

A Call for Openness

The cryptographic principles of TETRA have remained undisclosed for many years, impeding independent security assessments. Announcements to publish these principles were made in 2023, signaling a departure from the “security by obscurity” tactic adopted earlier by ETSI, which standardized TETRA back in 1995.

Effects on Australian Industries

TETRA networks function in more than 100 nations, constituting the foundation for emergency communications. In Australia, mining firms have widely incorporated TETRA for remote operations over the last decade, emphasizing the urgency for swift security evaluations.

Conclusion

The recent identification of vulnerabilities in TETRA networks by Midnight Blue underscores significant security issues for encrypted communications internationally. The flaws, which involve compromised encryption algorithms, threaten essential infrastructures and necessitate immediate independent assessments.

Q&A Section

Q: What is TETRA?

A: TETRA (Terrestrial Trunked Radio) is a communication standard commonly employed by emergency services and various industry sectors for secure radio communications.

Q: What new vulnerabilities have been discovered in TETRA networks?

A: The vulnerabilities encompass weakened encryption algorithms and flaws that could permit attackers to inject harmful data, jeopardizing communication security.

Q: What is the significance of publishing TETRA algorithms?

A: Publishing the algorithms concludes a long-standing “security by obscurity” approach, allowing independent security researchers to assess and find potential weaknesses.

Q: How do these vulnerabilities impact Australian industries?

A: Mining companies in Australia, reliant on TETRA for remote operations, may face the threat of unauthorized control over crucial systems, making comprehensive security evaluations essential.

PrismXR Vega T1 Low Latency Wireless Earbuds Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

PrismXR Vega T1 Low Latency Wireless Earbuds [video game] [video game]

University of Western Australia Requires All Staff and Students to Change Their Passwords


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Brief Overview

  • The University of Western Australia has initiated a password reset for all employees and students due to a security incident.
  • There was a detection of unauthorized access to password data.
  • All employees and students are temporarily restricted from access until their passwords are reset.
  • Ongoing investigations indicate that no other systems are thought to have been breached.
  • IT and security personnel responded rapidly to control and recover from the situation.
  • Relevant authorities have been alerted.

University Security Incident Triggers Measures

The University of Western Australia (UWA) has mandated a password reset for every one of its employees and students following the detection of unauthorized access to a database containing password information. This measure is a direct response to a suspected security breach aimed at ensuring the security of UWA’s digital ecosystem.

University of Western Australia resets all staff and student passwords

Prompt Action and Control

Upon discovering the breach, UWA promptly locked all employees and students out of its systems, instructing them to reset their passwords for access restoration. Throughout the weekend, dedicated IT and security teams labored diligently to manage the incident. The university’s prompt action highlights its dedication to safeguarding personal and institutional information.

Continuing Investigation and Updates

As investigations are in progress, the university has indicated that it believes no other systems or sensitive data were at risk. Communication with impacted individuals has been consistent, ensuring transparency and offering guidance on necessary security actions.

System Security and Preventative Strategies

UWA employs a centralized access management system for its community members. Although it remains unconfirmed if this system was specifically targeted, the university is undertaking all required measures. They have notified the pertinent authorities and are enhancing their cyber security measures to avert future incidents.

Recap

The University of Western Australia has proactively responded to a potential security breach involving password data. By resetting passwords and effectively communicating with its community, UWA is placing a high priority on security and transparency. Ongoing investigations are aimed at ensuring the protection of its digital assets.

Q&A Session

Q: Why was a password reset implemented at UWA?

A: UWA observed unauthorized access to password data and took precautionary action by resetting passwords.

Q: Are other systems at UWA impacted by this incident?

A: Current investigations indicate that no other systems or data have been breached.

Q: How is UWA informing staff and students about the incident?

A: UWA is utilizing official communication channels to update its community and provide instructions for password resets.

Q: What measures is UWA implementing to avoid future breaches?

A: UWA is enhancing its security procedures and working with authorities to fortify its cyber defenses.

Q: Do staff and students need to reset their passwords right away?

A: Yes, staff and students need to reset their passwords as directed to regain access to UWA systems.

Q: Which parties have been informed about the incident?

A: UWA has notified the relevant authorities and continues to keep its employees and students updated.

JBL Endurance Race TWS, IE, Black Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

JBL Endurance Race TWS, IE, Black

Westpac Adopts AIOps and Event-Driven Automation Technologies


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Rapid Overview

  • Westpac implements event-driven automation and AIOps within a broad infrastructure automation initiative.
  • The financial institution is moving from AWX to Red Hat Ansible Automation Platform (AAP) for enterprise-level assistance.
  • Partnership with Red Hat bolsters training, engineering solutions, and shapes product trajectories.
  • Event-driven automation enhances IT resource oversight and elevates customer satisfaction.
  • AIOps harnesses AI to streamline processes, mitigating outages and improving services.

Automation Progress

Westpac is advancing its infrastructure automation efforts by embracing event-driven automation and AIOps. This shift, featured during a Red Hat Ansible event in Sydney by Sean Dudding, illustrates a deliberate move to transform and improve the customer experience through automation.

Dudding stressed that the bank’s main objective is to provide automation that aids internal teams in effectively managing IT resources, which in turn benefits millions of Australian customers.

Transitioning from AWX to Ansible Automation Platform

At first, Westpac relied on AWX, a complimentary, open-source controller for Ansible automation tasks. Nonetheless, the bank has now shifted to the enterprise-supported Red Hat Ansible Automation Platform (AAP). This shift was motivated by the necessity for around-the-clock support and further advantages such as improved training options and direct engineering partnership with Red Hat.

Dudding pointed out that collaborating with Red Hat allows Westpac to impact product roadmaps, guaranteeing that the bank’s requirements are satisfied while also influencing the future progress of Red Hat products.

Primary Advantages of AAP

The choice to embrace AAP extends beyond support to include the intangible benefits of collective knowledge and engineering collaboration. The bank has asked for improvements to the event-driven automation engine, facilitating modifications to event streams for a robust automated infrastructure.

This strategic alliance with Red Hat has also nurtured deeper connections between the organizations, enabling a smoother integration of automation solutions.

Enhancements in Event-Driven Automation and AIOps

By hosting AAP on Red Hat OpenShift with cross-site load balancing, Westpac emphasises event-driven automation and AIOps. Dudding noted the potential of event-driven automation to oversee trusted event sources, initiating automation as specific events unfold. This strategy leverages existing engineering advancements to maximise return on investment.

Furthermore, AIOps is advancing to activate automated processes via AI, which significantly lowers the likelihood of outages and enhances customer services. This progression highlights Westpac’s dedication to utilising technology to boost operational efficiency and the customer experience.

Conclusion

Westpac’s integration of event-driven automation and AIOps signifies a crucial achievement in its infrastructure automation strategy. By adopting the Red Hat Ansible Automation Platform, the bank secures enterprise support and improved collaboration prospects, propelling a revolutionary approach to IT resource management and customer service enhancement.

Q: What is the principal objective of Westpac’s automation program?

A: The main objective is to transform the infrastructure landscape and enhance the customer journey through automation.

Q: What prompted Westpac to shift from AWX to AAP?

A: Westpac transitioned to AAP for enterprise-level support and additional advantages such as improved training and collaboration with Red Hat.

Q: In what way does event-driven automation benefit Westpac?

A: It enables Westpac to monitor event sources and initiate automation, thus optimising IT resource management and improving the customer experience.

Q: What is AIOps’ role in Westpac’s strategy?

A: AIOps employs AI to automate tasks, reducing outages and enhancing service quality.

Q: How has the collaboration with Red Hat aided Westpac?

A: The collaboration offers training, engineering joint efforts, and influence over Red Hat’s product direction, benefiting Westpac’s automation efforts.

Q: What infrastructure backs Westpac’s automation platform?

A: The Ansible Automation Platform is hosted on Red Hat OpenShift with cross-site load balancing for enhanced reliability.

“Wireless Gaming Earphones Review”


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Cyber Wireless Gaming Earphones (for PS5 / Switch/PC) Black