Chicago IT Support & Cyber Security | Forward Technologies

Chicago-based Forward Technologies delivers IT support and cyber security to businesses in the Chicago area and nationwide.

  • Home
  • Services
    • Outsourced IT Support for Small Business
    • DMARC Email Security
    • Development
      • Custom Google Reviews Display Plugin for WordPress
      • Web Development & Facelifts
    • Data Recovery Service
    • PPC Marketing Services
    • SEO Services
  • DMARC Email Security
  • Data Recovery Service
  • Blog
  • Contact Us

Microsoft Plugs One Secure Boot Flaw While Leaving Another Wide Open

June 11, 2025 by Edward Silha

A cartoon-style illustration of a worried programmer sitting at a desk with a laptop that has a red padlock icon. Behind him, a menacing robot labeled "VULNERABILITIES" holds two scrolls marked "EXPLOIT." A yellow "SECURE BOOT" sign with a padlock and boot icon hangs on the wall, symbolizing compromised device security. The background is a textured purple.Security researchers have identified two major exploits in the Secure Boot system, both capable of sidestepping one of the most important protections on modern PCs. Microsoft has issued a patch for one of them. The other remains untouched, even as it offers attackers a nearly universal method to bypass security during the startup process.

This week’s patch from Microsoft addresses a vulnerability known as CVE-2025-3052. It impacts over 50 manufacturers whose systems rely on Linux modules to support boot processes. The flaw allows someone with physical access to a device to disable Secure Boot entirely. Once that’s done, they can install malware that loads before the operating system starts. The attack is particularly concerning because it’s stealthy and persistent, and in cases where a hacker already has administrative access, it can be triggered remotely. [Read more…]

Filed Under: Blog, Cybersecurity Tagged With: Binarly, bootloader exploit, CVE-2025-3052, CVE-2025-47827, cybersecurity, DBX blocklist, digital signatures, DT Research, Eclypsium, firmware security, GRUB, IGEL, Linux kernel, malware, Microsoft, operating system security, Secure Boot, UEFI

Microsoft Extends Office Security Updates on Windows 10 Through 2028

May 18, 2025 by Edward Silha

Laptop screen displaying Microsoft Office apps on a Windows 10 desktopMicrosoft will continue rolling out security updates for Microsoft 365 apps on Windows 10 until October 2028, extending support three years past the operating system’s planned end-of-life.

The change follows the company’s earlier position, announced in January, that Office apps would stop receiving updates on Windows 10 starting in October 2025. At the time, Microsoft urged users to upgrade to Windows 11 to maintain access to updated versions of Word, Excel, and other Microsoft 365 tools.

[Read more…]

Filed Under: Blog, Tech In General Tagged With: end-of-life support, ESU program, extended security updates, Microsoft, Microsoft 365, Office 365, security patches, software updates, Windows 10, Windows 11

Microsoft OneDrive Update Prompts Security Fears Over Personal Account Syncing on Work Devices

May 9, 2025 by Edward Silha

FT BLOG OneDrive Personal SyncMicrosoft is quietly pushing out a OneDrive update that’s catching IT departments off guard. A new feature prompts users—by default—to connect their personal OneDrive accounts to corporate machines. No setup needed. The feature just appears and offers a quick, seamless sync between personal and business storage.

Here’s the obvious problem: once files from a corporate machine end up in a personal OneDrive account, they’re basically outside the company’s control. No logging. No tracking. No oversight. That means sensitive information could be moved or shared in ways the organization can’t monitor—and probably wouldn’t approve of. [Read more…]

Filed Under: Blog, Cybersecurity Tagged With: cloud storage, corporate devices, data exfiltration, data security, DisablePersonalSync, enterprise IT, IT policy, Microsoft, OneDrive, personal sync

Microsoft’s Passkey Push Comes with Strings Attached

May 2, 2025 by Edward Silha

Password or PasskeyMicrosoft is shifting new account signups away from passwords and toward passkeys. It’s part of a broader industry effort, with companies like Google and Apple also pushing for a future where stolen credentials are no longer a threat. This move sounds like progress, but there’s more going on beneath the surface.

Going forward, anyone creating a new Microsoft account will be guided to set up a passkey. Existing users will also see prompts asking them to make the switch. The goal is simple: reduce the security risks and user frustration tied to traditional passwords. Most people reuse weak logins. That leads to leaks, breaches, and a lot of expensive damage.

[Read more…]

Filed Under: Blog, Cybersecurity Tagged With: account security, credential theft, digital security, FIDO Alliance, Microsoft, Microsoft Authenticator, passkeys, passwordless login, phishing protection, tech industry standards

Social Media

  • Facebook
  • GitHub
  • LinkedIn
  • Periscope
  • Twitter

Forward Technologies
747 N LaSalle
STE 500B
Chicago, IL 60654
(312) 715-7806

Copyright © 2025 — Forward Technologies • All rights reserved. • Privacy Policy •