Midfoils Tech 

225 Followers
267 Following
217 Posts
Translating all things "cyber" into practical business focused security advice and guidance
SANS Stormcast Wednesday, December 10th, 2025: Microsoft, Adobe, Ivanti, Fortinet, and Ruby patches.
https://isc.sans.edu/podcastdetail/9732

RE: https://infosec.exchange/@jerry/115210004914492043

This is a good and welcome step for Mastodon....

Afternoon attack and defense teams, one and all. By me @Forbes: Great analysis from @CheckPointSW into the new VanHelsing RaaS attack platform.

#infosec

https://www.forbes.com/sites/daveywinder/2025/03/24/new-windows-threat-demands-5000-in-return-for-hack-attack-access/

New Windows Threat Demands $5,000 In Return For $500,000 Attack

VanHelsing is charging hackers $5,000 to start attacking enterprises with a brand new service that has snagged three victims in just two weeks with $500,000 ransoms.

Forbes

Apple has released iOS 18.3.1, an emergency security update to patch a zero-day vulnerability that the company says was exploited in targeted and "extremely sophisticated" attacks.

#apple #ios18 #ios1831 #0day #vulnerability #security
https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/

Apple fixes zero-day exploited in 'extremely sophisticated' attacks

Apple has released emergency security updates to patch a zero-day vulnerability that the company says was exploited in targeted and "extremely sophisticated" attacks.

BleepingComputer

Microsoft 365 has introduced a new feature in its admin center to improve network connectivity for M365 Copilot. This comes after users experienced broken experiences due to blocked WebSocket connections in their network infrastructure, with tenant admins having no visibility into these failed connections. With the new feature, tenant admins can now see when their network impacts user connections to M365 apps and view the failure rate percentage for failed HTTPS and WebSocket connections. The report will highlight any blocked network connections that could affect various M365 applications.

In addition, tenant admins can also view the network assessment points for Microsoft 365 Copilot based on the network latency experienced by users. A lower latency results in higher assessment points, providing a clearer picture of any high latency issues that may be affecting user experience with M365 Copilot. To learn more about this new feature and how it can help optimize your customer's network connectivity setup essential for M365 applications, check out the full article. #microsoft365 #M365Copilot https://techcommunity.microsoft.com/t5/deployment-networking/optimizing-customer-network-connectivity-for-microsoft-365/m-p/4374772#M1445

There is a lot to take in this week in keeping your systems up-to-date.

The image below shows all the companies that have released updates.

Please take the time to check that your systems are updated or set to update.

#CyberEssentials

Excellent article from Selena Larson (https://mastodon.social/@selenalarson) on the need to focus on cyber criminals, rather than states, to protect companies.

https://rusi.org/explore-our-research/publications/commentary/why-biasing-advanced-persistent-threats-over-cybercrime-security-risk

If you are not protected from these then you are going to be fair game.

Ensure you have the basics right - get #CyberEssentials

Why Biasing Advanced Persistent Threats over Cybercrime is a Security Risk

Once reserved for nation-state actors, advanced and persistent cyber tactics are now common among cybercriminals, making them equally devastating in today’s threat landscape.

Hopefully you all saw that Apple released some security updates at the end of last week.

It would be worthwhile checking to see if your devices have updated, and if not, update them, in order to keep yourself as safe as possible.

https://support.apple.com/en-us/100100

Apple security releases - Apple Support

This document lists security updates and Rapid Security Responses for Apple software.

Apple Support
Integrating honeypots and tripwires into your enterprise defenses is smart. They provide clear, early warnings that demand investigation.

Just reading through Microsoft's Secure Future Initiative report (https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/SFI_September_2024_progress_report.pdf) and they have "eliminated 5.75 MILLION inactive tenants"...

That's an awful lot of lifecycle management that has been missed.