https://isc.sans.edu/podcastdetail/9732

RE: https://infosec.exchange/@jerry/115210004914492043
This is a good and welcome step for Mastodon....
Afternoon attack and defense teams, one and all. By me @Forbes: Great analysis from @CheckPointSW into the new VanHelsing RaaS attack platform.
Apple has released iOS 18.3.1, an emergency security update to patch a zero-day vulnerability that the company says was exploited in targeted and "extremely sophisticated" attacks.
#apple #ios18 #ios1831 #0day #vulnerability #security
https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/
Microsoft 365 has introduced a new feature in its admin center to improve network connectivity for M365 Copilot. This comes after users experienced broken experiences due to blocked WebSocket connections in their network infrastructure, with tenant admins having no visibility into these failed connections. With the new feature, tenant admins can now see when their network impacts user connections to M365 apps and view the failure rate percentage for failed HTTPS and WebSocket connections. The report will highlight any blocked network connections that could affect various M365 applications.
In addition, tenant admins can also view the network assessment points for Microsoft 365 Copilot based on the network latency experienced by users. A lower latency results in higher assessment points, providing a clearer picture of any high latency issues that may be affecting user experience with M365 Copilot. To learn more about this new feature and how it can help optimize your customer's network connectivity setup essential for M365 applications, check out the full article. #microsoft365 #M365Copilot https://techcommunity.microsoft.com/t5/deployment-networking/optimizing-customer-network-connectivity-for-microsoft-365/m-p/4374772#M1445
There is a lot to take in this week in keeping your systems up-to-date.
The image below shows all the companies that have released updates.
Please take the time to check that your systems are updated or set to update.
Excellent article from Selena Larson (https://mastodon.social/@selenalarson) on the need to focus on cyber criminals, rather than states, to protect companies.
If you are not protected from these then you are going to be fair game.
Ensure you have the basics right - get #CyberEssentials
Hopefully you all saw that Apple released some security updates at the end of last week.
It would be worthwhile checking to see if your devices have updated, and if not, update them, in order to keep yourself as safe as possible.
Just reading through Microsoft's Secure Future Initiative report (https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/SFI_September_2024_progress_report.pdf) and they have "eliminated 5.75 MILLION inactive tenants"...
That's an awful lot of lifecycle management that has been missed.