/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft pushes a fix for a critical flaw in a cryptographic component present in all versions of Windows; NSA says it alerted Microsoft to the bug

rather than weaponizing it Robert Hackett / Fortune : The NSA patches up its reputation with a gift to Microsoft Mark Wyciślik-Wilson / BetaNews : Microsoft turns the screws on Windows 7 users with full-screen upgrade warnings Woody Leonhard / Computerworld : Patch Tuesday aftermath: The NSA Crypt32 threat is real, but not yet imminent us-cert.gov : Alert (AA20-014A)  —  Critical Vulnerabilities in Microsoft Windows Operating Systems Lily Hay Newman / Wired : Windows 10 Has a Security Flaw So Severe the NSA Disclosed It Phillip Tracy / LaptopMag : Critical Windows 10 security flaw discovered by NSA: What to do now Kenneth White / First Principles : Microsoft's Chain of Fools Jessica Davis / HealthITSecurity : NSA Discloses, Urges Patch of Critical Microsoft Windows 10 Vulnerability Department of Homeland Security : Emergency Directive 20-02  —  Mitigate Windows Vulnerabilities … Lance Whitney / TechRepublic : Microsoft rolls out patch for serious Windows bug highlighted by NSA Cliff Saran / ComputerWeekly.com : Last Windows 7 patch updates critical remote desktop flaw Panda Security Mediacenter : The new critical vulnerability in Windows 10 has a solution: UPDATE NOW Sean Gallagher / Ars Technica : Windows 7: “I'm not dead yet!” Bogdan Popa / Softpedia News : Three Things You Need to Know About Windows 7 Moving Forward Kate Fazzini / CNBC : Microsoft patches Windows 10 after the NSA quietly told it about a major vulnerability Animesh Jain / Qualys Blog : 50 Vulns, 8 Critical, Adobe Vulns Bruce Schneier / Schneier on Security : Critical Windows Vulnerability Discovered by NSA Jessica Guynn / USA Today : What you need to know about the Microsoft Windows 10 patch Chris Smith / BGR : NSA discloses critical Windows 10 security bug instead of using it to spy on us Jack Turner / Tech.co : NSA Issues Warning On Windows 10 Exploit PYMNTS.com : NSA Alerts Microsoft To Windows Security Flaw Cohen Coberly / TechSpot : Microsoft issues fix for critical Windows flaw disclosed by the NSA Pierluigi Paganini / Security Affairs : Microsoft addresses CVE-2020-0601 flaw, the first issue ever reported by NSA Phil Muncaster / infosecurity-magazine.com : Microsoft Patches Serious Crypto Flaw Found by NSA Duncan Riley / SiliconANGLE : Microsoft patches critical Windows vulnerability uncovered by the NSA Sergiu Gatlan / BleepingComputer : NSA's First Public Vulnerability Disclosure: An Effort to Build Trust Mark Hachman / PCWorld : Microsoft, NSA confirm killer Windows 10 bug, but a patch is available Tweets: NSA / @nsagov : This #PatchTuesday you are strongly encouraged to implement the recently released CVE-2020-0601 patch immediately. https://media.defense.gov/... pic.twitter.com/log6OU93cV Will Dormann / @wdormann : I get the impression that people should perhaps pay very close attention to installing tomorrow's Microsoft Patch Tuesday updates in a timely manner. Even more so than others. I don't know... just call it a hunch? ¯\_(ツ)_/¯ @briankrebs : Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed “Turn a New Leaf,” aimed at making more of the agency's vulnerability research available to major software vendors and ultimately to the public. Dmitri Alperovitch / @dalperovitch : This is a critical issue. Everyone should patch Win10/Win 2016 ASAP. Do not wait! Also big kudos to NSA for voluntarily disclosing to Microsoft. This is the type of vuln I am sure the offensive side would have loved to use for years to come https://twitter.com/... @swiftonsecurity : COMMENTARY ON CVE-2020-0601: I have been speaking to several players on this on background and there are a few things they want to highlight / clarify based on the public discourse so far. @briankrebs : Sources say Microsoft on Tuesday will fix an extraordinarily scary flaw in all Windows versions, in a core cryptographic component that could be abused to spoof the source of digitally signed software. Apparently DoD & a few others got an advance patch https://krebsonsecurity.com/ ... Cem Paya / @randomoracle : Some speculation on CVE-2020-0601. Earlier version of Windows cryptography API only supported a handful of elliptic curves from NIST suite-B. It could not handle say an arbitrary prime-curve in Weierstrass form with user defined parameters 1/N Matthew Green / @matthew_d_green : I know it's trite to say this (again). But if the cryptographic A-team is willing to accept random elliptic curve parameters from strangers, imagine what kind of mistakes the B-team will make when you ask them to design crypto backdoors. @x0rz : The NSA carefully decided to disclose the vulnerability they found (in-house): 1) probably not the vuln of the year, 2) a way for the NSA to redeem itself after the Eternal Blue disaster, 3) overall a good PR operation, 4) this is one of many bugs they are finding <iceberg.jpg>. https://twitter.com/... Ambassador Johnson / @usambuk : This is important: If you use Microsoft Windows, make sure you update your software today. Do not delay! https://twitter.com/... Mary Branscombe / @marypcbuk : frankly, pay attention to getting your IT in a state where you can update *every* Patch Tuesday in a timely manner https://twitter.com/... Julian E. Barnes / @julianbarnes : NSA used to find a computer flaw and develop a cyber weapon to exploit it. But with the latest flaw they have found they are telling the world. http://www.nytimes.com/... Simon Pope / @skjpope : The best thing to do is get into the rhythm of updating your systems and not fixating on individual vulnerabilities. If you have a good rhythm - and get your systems updated as soon as possible every month - you're doing what you should to help protect yourselves. https://twitter.com/... Thaidn / @xorninja : Wow. So this is not a boring parsing bug. My guess is that Windows blindly trusted curve parameters from a rogue certificate. This is interesting because https://tools.ietf.org/... states that “ This choice [specified curve parameters] MUST NOT be used” https://twitter.com/... @swiftonsecurity : Microsoft clarifies details of the private Security Update Validation Program (SUVP). Updates are not allowed in full Prod environments, in order to reduce risks of pre-release disclosure of patch binaries. They are only provided for testing and validation under NDA. https://twitter.com/... @briankrebs : NSA: If enterprise-wide patching of this vuln not possible we recommend prioritize patching systems that perform TLS validation, or host critical infrastructure like domain controllers, DNS servers, VPN servers, etc. Matthew Green / @matthew_d_green : Well that looks pretty suspicious. https://media.defense.gov/... pic.twitter.com/3BQCSYq8uN Sven Herpig / @z_edian : “The disclosure represents a major shift in the NSA's approach, choosing to put computer security ahead of building up its arsenal of hacking tools” Not sure whether one instance qualifies as “major shift”. Maybe they just weighed the equities which were in favor of disclosure. https://twitter.com/... Elliot Alderson / @fs0c131y : Interesting. I'm very interested to know how communication experts see this “Saturn a New Leaf” initiative. What are the advantages for the agency? https://twitter.com/... https://twitter.com/... @swiftonsecurity : This is a fast-checkmate flaw for a hugely resourced and patient global actor like the NSA, but it's a far greater systemic threat to the United States, which explains why this was properly disclosed to Microsoft. @swiftonsecurity : Innumerable protocols and transactions are protected with x509. Enterprise voice, VPN, really everything these days is being wrapped up in HTTPS and sent over the Internet. And they all rely on Windows' correct implementation, which is at fault here. @swiftonsecurity : When NSA says CVE-2020-0601 enables Remote Code Execution, they mean that trusted communication channels like automatic update downloads and non-validated input between systems could be modified in-transit by a MitM, to cause RCE or other malevolent ends. @swiftonsecurity : Because both TLS communication stream encryption and Authenticode file validation are impacted by this flaw in PKI validation, the normal ways this is guarded against for program updates, are both compromised. There are a few that go beyond this, but it's exceptionally rare. @swiftonsecurity : The gravest impacts of this are established societal and industrial infrastructure. Bank communications. Infrastructure control. Heavy industry. This is a much different threat than is traditionally discussed or news consumers really understand the ramifications of. @swiftonsecurity : This vulnerability is not about a wormable global takedown of computers, but instead resourced attackers who own network transit points being able to modify communication streams at-will. Basically, nation-state APTs who routinely compromise foreign network infrastructure. Kim Zetter / @kimzetter : “Microsoft Windows CryptoAPI..fails to validate ECC certs in a way that properly leverages..protections that ECC crypto should provide..attacker may be able to craft a cert that appears to have..ability to be traced to a trusted root certificate authority” https://kb.cert.org/... Nicholas Weaver / @ncweaver : Oh FUCK!!!!! https://media.defense.gov/... It literally is “here are some ECC parameters, use these...” and windows being like “sure, ok” Kim Zetter / @kimzetter : Finally: NSA on Microsoft vuln “The certificate validation vuln allows an attacker to undermine how Windows verifies cryptographic trust and can enable remote code execution..NSA assesses..vuln to be severe..sophisticated cyber actors will understand..underlying flaw very quickly https://twitter.com/... Kenn White / @kennwhite : Not just spoofing Authenticode - intercept and tampering with TLS payloads. CERT scores it a 9.4 CVSS. https://www.kb.cert.org/... Dmitri Alperovitch / @dalperovitch : Yes. People downplaying this vulnerability are not cosidering all the potential exploitation vectors, which are numerous https://twitter.com/... Catalin Cimpanu / @campuscodi : Microsoft fixes Windows crypto bug reported by the NSA * CVE-2020-0601 — Windows CryptoAPI spoofing * MSFT says bug can be used to fake file digital signatures and for MitM attacks * NSA & MSFT say they didn't see any exploits in the wild https://www.zdnet.com/... https://twitter.com/... @briankrebs : NSA says they discovered the flaw on their own and that Microsoft will report that MS has seen no active exploitation of this vulnerability so far. @briankrebs : Microsoft has released an advisory for this vulnerability in Win10, Server 2016 and '19. It rated this as a “spoofing” flaw that is “important” in severity, but puts exploitability rating at 1, it's second most severe, i.e. “exploitation more likely.” https://portal.msrc.microsoft.com/ ... @nytimes : The NSA has alerted Microsoft to a vulnerability in the Windows operating system, a departure from its usual practice of keeping quiet and exploiting the flaw to develop cyberweapons, people familiar with the matter said https://www.nytimes.com/... Eric Geller / @ericgeller : We have no idea how often the NSA keeps vulnerabilities secret from vendors so they can exploit them. But it's not surprising that, when they disclose a big one, they'll want to crow about it. Seems like whatever's coming on this Patch Tuesday is big. https://twitter.com/... @briankrebs : The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked. @briankrebs : Not a coincidence. NSA says in their call with media this morning this vulnerability is one they reported to Microsoft.

Krebs on Security Brian Krebs

Context & Ripple Effects

This is the rare case of the NSA acting as a bug reporter rather than a bug buyer: the agency says it found CVE-2020-0601, a flaw in the Windows cryptographic component that underpins code signing and encrypted connections across every Windows version, and alerted Microsoft so a fix could ship. The precedent for outside researchers forcing Microsoft's hand goes back years — Google's disclosure of a Windows vulnerability ahead of patching drew a similar critical Windows 8.1 fix batch in 2015.

What makes this disclosure different is who made it and how fast the government moved behind it: DHS issued an emergency directive ordering federal agencies to mitigate, and US-CERT published Alert AA20-014A the same day. The NSA would repeat the playbook — four NSA-discovered critical Exchange flaws landed in Microsoft's April 2021 patches — suggesting this was a policy turn, not a one-off.

First-order effects

  • Every Windows administrator from enterprises to federal agencies must deploy the CryptoAPI patch immediately, because the flaw lets attackers forge trusted certificates and sign malware that Windows treats as legitimate.
  • DHS's emergency directive converts the patch from best practice into a compliance deadline for US civilian agencies, with CISA tracking mitigation.

Second-order effects

  • Security vendors and certificate authorities have to re-examine anything downstream of Windows' crypto validation — Authenticode-signed software, VPN and encrypted-connection tooling — since the flaw undermines the trust anchor itself rather than one app.
  • Rival platform vendors face pressure to demonstrate their own code-signing chains aren't vulnerable to the same elliptic-curve parameter trick, turning a Windows patch into an industry-wide audit.

Third-order effects

  • If the NSA keeps disclosing instead of stockpiling — as its later Exchange findings suggest — Patch Tuesday becomes a semi-formal channel between US signals intelligence and Microsoft, reshaping how offensive cyber capabilities are weighed against defensive disclosure.
  • Emergency directives tied to vendor patches normalize a faster federal response cadence, where a single cryptographic flaw can trigger government-wide mitigation within days rather than standard patch cycles.

The trend: US intelligence agencies are shifting from hoarding critical software flaws to disclosing them to vendors, turning monthly patch cycles into a joint government-industry defense mechanism.

Discussion

  • @nsagov NSA on x
    This #PatchTuesday you are strongly encouraged to implement the recently released CVE-2020-0601 patch immediately. https://media.defense.gov/... pic.twitter.com/log6OU93cV
  • @wdormann Will Dormann on x
    I get the impression that people should perhaps pay very close attention to installing tomorrow's Microsoft Patch Tuesday updates in a timely manner. Even more so than others. I don't know... just call it a hunch? ¯\_(ツ)_/¯
  • @briankrebs @briankrebs on x
    Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed “Turn a New Leaf,” aimed at making more of the agency's vulnerability research available to major software vendors and ultimately to the public.
  • @dalperovitch Dmitri Alperovitch on x
    This is a critical issue. Everyone should patch Win10/Win 2016 ASAP. Do not wait! Also big kudos to NSA for voluntarily disclosing to Microsoft. This is the type of vuln I am sure the offensive side would have loved to use for years to come https://twitter.com/...
  • @swiftonsecurity @swiftonsecurity on x
    COMMENTARY ON CVE-2020-0601: I have been speaking to several players on this on background and there are a few things they want to highlight / clarify based on the public discourse so far.
  • @briankrebs @briankrebs on x
    Sources say Microsoft on Tuesday will fix an extraordinarily scary flaw in all Windows versions, in a core cryptographic component that could be abused to spoof the source of digitally signed software. Apparently DoD & a few others got an advance patch https://krebsonsecurity.com…
  • @randomoracle Cem Paya on x
    Some speculation on CVE-2020-0601. Earlier version of Windows cryptography API only supported a handful of elliptic curves from NIST suite-B. It could not handle say an arbitrary prime-curve in Weierstrass form with user defined parameters 1/N
  • @matthew_d_green Matthew Green on x
    I know it's trite to say this (again). But if the cryptographic A-team is willing to accept random elliptic curve parameters from strangers, imagine what kind of mistakes the B-team will make when you ask them to design crypto backdoors.
  • @x0rz @x0rz on x
    The NSA carefully decided to disclose the vulnerability they found (in-house): 1) probably not the vuln of the year, 2) a way for the NSA to redeem itself after the Eternal Blue disaster, 3) overall a good PR operation, 4) this is one of many bugs they are finding <iceberg.jpg>. …
  • @usambuk Ambassador Johnson on x
    This is important: If you use Microsoft Windows, make sure you update your software today. Do not delay! https://twitter.com/...
  • @marypcbuk Mary Branscombe on x
    frankly, pay attention to getting your IT in a state where you can update *every* Patch Tuesday in a timely manner https://twitter.com/...
  • @julianbarnes Julian E. Barnes on x
    NSA used to find a computer flaw and develop a cyber weapon to exploit it. But with the latest flaw they have found they are telling the world. http://www.nytimes.com/...
  • @skjpope Simon Pope on x
    The best thing to do is get into the rhythm of updating your systems and not fixating on individual vulnerabilities. If you have a good rhythm - and get your systems updated as soon as possible every month - you're doing what you should to help protect yourselves. https://twitter…
  • @xorninja Thaidn on x
    Wow. So this is not a boring parsing bug. My guess is that Windows blindly trusted curve parameters from a rogue certificate. This is interesting because https://tools.ietf.org/... states that “ This choice [specified curve parameters] MUST NOT be used” https://twitter.com/...
  • @swiftonsecurity @swiftonsecurity on x
    Microsoft clarifies details of the private Security Update Validation Program (SUVP). Updates are not allowed in full Prod environments, in order to reduce risks of pre-release disclosure of patch binaries. They are only provided for testing and validation under NDA. https://twit…
  • @briankrebs @briankrebs on x
    NSA: If enterprise-wide patching of this vuln not possible we recommend prioritize patching systems that perform TLS validation, or host critical infrastructure like domain controllers, DNS servers, VPN servers, etc.
  • @matthew_d_green Matthew Green on x
    Well that looks pretty suspicious. https://media.defense.gov/... pic.twitter.com/3BQCSYq8uN
  • @z_edian Sven Herpig on x
    “The disclosure represents a major shift in the NSA's approach, choosing to put computer security ahead of building up its arsenal of hacking tools” Not sure whether one instance qualifies as “major shift”. Maybe they just weighed the equities which were in favor of disclosure. h…
  • @fs0c131y Elliot Alderson on x
    Interesting. I'm very interested to know how communication experts see this “Saturn a New Leaf” initiative. What are the advantages for the agency? https://twitter.com/... https://twitter.com/...
  • @swiftonsecurity @swiftonsecurity on x
    This is a fast-checkmate flaw for a hugely resourced and patient global actor like the NSA, but it's a far greater systemic threat to the United States, which explains why this was properly disclosed to Microsoft.
  • @swiftonsecurity @swiftonsecurity on x
    Innumerable protocols and transactions are protected with x509. Enterprise voice, VPN, really everything these days is being wrapped up in HTTPS and sent over the Internet. And they all rely on Windows' correct implementation, which is at fault here.
  • @swiftonsecurity @swiftonsecurity on x
    When NSA says CVE-2020-0601 enables Remote Code Execution, they mean that trusted communication channels like automatic update downloads and non-validated input between systems could be modified in-transit by a MitM, to cause RCE or other malevolent ends.
  • @swiftonsecurity @swiftonsecurity on x
    Because both TLS communication stream encryption and Authenticode file validation are impacted by this flaw in PKI validation, the normal ways this is guarded against for program updates, are both compromised. There are a few that go beyond this, but it's exceptionally rare.
  • @swiftonsecurity @swiftonsecurity on x
    The gravest impacts of this are established societal and industrial infrastructure. Bank communications. Infrastructure control. Heavy industry. This is a much different threat than is traditionally discussed or news consumers really understand the ramifications of.
  • @swiftonsecurity @swiftonsecurity on x
    This vulnerability is not about a wormable global takedown of computers, but instead resourced attackers who own network transit points being able to modify communication streams at-will. Basically, nation-state APTs who routinely compromise foreign network infrastructure.
  • @kimzetter Kim Zetter on x
    “Microsoft Windows CryptoAPI..fails to validate ECC certs in a way that properly leverages..protections that ECC crypto should provide..attacker may be able to craft a cert that appears to have..ability to be traced to a trusted root certificate authority” https://kb.cert.org/...
  • @ncweaver Nicholas Weaver on x
    Oh FUCK!!!!! https://media.defense.gov/... It literally is “here are some ECC parameters, use these...” and windows being like “sure, ok”
  • @kimzetter Kim Zetter on x
    Finally: NSA on Microsoft vuln “The certificate validation vuln allows an attacker to undermine how Windows verifies cryptographic trust and can enable remote code execution..NSA assesses..vuln to be severe..sophisticated cyber actors will understand..underlying flaw very quickly…
  • @kennwhite Kenn White on x
    Not just spoofing Authenticode - intercept and tampering with TLS payloads. CERT scores it a 9.4 CVSS. https://www.kb.cert.org/...
  • @dalperovitch Dmitri Alperovitch on x
    Yes. People downplaying this vulnerability are not cosidering all the potential exploitation vectors, which are numerous https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Microsoft fixes Windows crypto bug reported by the NSA * CVE-2020-0601 — Windows CryptoAPI spoofing * MSFT says bug can be used to fake file digital signatures and for MitM attacks * NSA & MSFT say they didn't see any exploits in the wild https://www.zdnet.com/... https://twitter…
  • @briankrebs @briankrebs on x
    NSA says they discovered the flaw on their own and that Microsoft will report that MS has seen no active exploitation of this vulnerability so far.
  • @briankrebs @briankrebs on x
    Microsoft has released an advisory for this vulnerability in Win10, Server 2016 and '19. It rated this as a “spoofing” flaw that is “important” in severity, but puts exploitability rating at 1, it's second most severe, i.e. “exploitation more likely.” https://portal.msrc.microsof…
  • @nytimes @nytimes on x
    The NSA has alerted Microsoft to a vulnerability in the Windows operating system, a departure from its usual practice of keeping quiet and exploiting the flaw to develop cyberweapons, people familiar with the matter said https://www.nytimes.com/...
  • @ericgeller Eric Geller on x
    We have no idea how often the NSA keeps vulnerabilities secret from vendors so they can exploit them. But it's not surprising that, when they disclose a big one, they'll want to crow about it. Seems like whatever's coming on this Patch Tuesday is big. https://twitter.com/...
  • @briankrebs @briankrebs on x
    The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked.
  • @briankrebs @briankrebs on x
    Not a coincidence. NSA says in their call with media this morning this vulnerability is one they reported to Microsoft.