Midfoils Tech :donor:

Translating all things "cyber" into practical business focused security advice and guidance

Midfoils Tech :donor: boosted:
happygeek :unverified: + :verified: = $0happygeek@infosec.exchange
2025-03-24

Afternoon attack and defense teams, one and all. By me @Forbes: Great analysis from @CheckPointSW into the new VanHelsing RaaS attack platform.

#infosec

forbes.com/sites/daveywinder/2

Midfoils Tech :donor: boosted:
TechHelpKB.com 📚techhelpkb
2025-02-11

Apple has released iOS 18.3.1, an emergency security update to patch a zero-day vulnerability that the company says was exploited in targeted and "extremely sophisticated" attacks.


bleepingcomputer.com/news/appl

Midfoils Tech :donor: boosted:
2025-02-07

Microsoft 365 has introduced a new feature in its admin center to improve network connectivity for M365 Copilot. This comes after users experienced broken experiences due to blocked WebSocket connections in their network infrastructure, with tenant admins having no visibility into these failed connections. With the new feature, tenant admins can now see when their network impacts user connections to M365 apps and view the failure rate percentage for failed HTTPS and WebSocket connections. The report will highlight any blocked network connections that could affect various M365 applications.

In addition, tenant admins can also view the network assessment points for Microsoft 365 Copilot based on the network latency experienced by users. A lower latency results in higher assessment points, providing a clearer picture of any high latency issues that may be affecting user experience with M365 Copilot. To learn more about this new feature and how it can help optimize your customer's network connectivity setup essential for M365 applications, check out the full article. #microsoft365 #M365Copilot techcommunity.microsoft.com/t5

Midfoils Tech :donor:midfoilstech@infosec.exchange
2025-01-16

There is a lot to take in this week in keeping your systems up-to-date.

The image below shows all the companies that have released updates.

Please take the time to check that your systems are updated or set to update.

#CyberEssentials

Midfoils Tech :donor:midfoilstech@infosec.exchange
2025-01-13

Excellent article from Selena Larson (mastodon.social/@selenalarson) on the need to focus on cyber criminals, rather than states, to protect companies.

rusi.org/explore-our-research/

If you are not protected from these then you are going to be fair game.

Ensure you have the basics right - get #CyberEssentials

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-10-08

Hopefully you all saw that Apple released some security updates at the end of last week.

It would be worthwhile checking to see if your devices have updated, and if not, update them, in order to keep yourself as safe as possible.

support.apple.com/en-us/100100

Screenshot of the paged linked to in the text of the toot:

Apple security updates and Rapid Security Responses
Name and information link

Available for

Release date

Apple TV 1.5.0.152 for Windows

Windows 10 22H2 and later

03 Oct 2024

iOS 18.0.1 and iPadOS 18.0.1

iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later

03 Oct 2024

macOS Sequoia 15.0.1

This update has no published CVE entries.

macOS Sequoia

03 Oct 2024

watchOS 11.0.1

This update has no published CVE entries.

Apple Watch Series 6 and later

03 Oct 2024

visionOS 2.0.1

This update has no published CVE entries.

Apple Vision Pro

03 Oct 2024

Safari 18.0.1

This update has no published CVE entries.

macOS Ventura and macOS Sonoma

03 Oct 2024
Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-10-08
Midfoils Tech :donor: boosted:
2024-10-08

Integrating honeypots and tripwires into your enterprise defenses is smart. They provide clear, early warnings that demand investigation.

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-09-24

Just reading through Microsoft's Secure Future Initiative report (cdn-dynmedia-1.microsoft.com/i) and they have "eliminated 5.75 MILLION inactive tenants"...

That's an awful lot of lifecycle management that has been missed.

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-09-10

The National Cyber Security Centre have published a post celebrating the 100th Cyber Advisor -> ncsc.gov.uk/blog-post/ncsc-cyb

If you would like to speak to one of these rarities please get in contact with us as we have one!

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-09-04

And @tendaoffcial has not yet responded to the report of a security issue in their firmware, but keep an eye out for an update
2/2

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-09-04

Wednesday appears to be router day... @zyxel have issued updates for a large number of their routers -> zyxel.com/global/en/support/se

D-Link has issued a security advisory for an EOL router (supportannouncement.us.dlink.c) but you should be replacing this model if you still use it...
1/2

Screenshot of Zyxel router models effected....

NWA50AX	7.00(ABYW.1) and earlier	7.00(ABYW.2)
NWA50AX PRO	7.00(ACGE.1) and earlier	7.00(ACGE.2)
NWA55AXE	7.00(ABZL.1) and earlier	7.00(ABZL.2)
NWA90AX	7.00(ACCV.1) and earlier	7.00(ACCV.2)
NWA90AX PRO	7.00(ACGF.1) and earlier	7.00(ACGF.2)
NWA110AX	7.00(ABTG.1) and earlier	7.00(ABTG.2)
NWA130BE	7.00(ACIL.1) and earlier	7.00(ACIL.2)
NWA210AX	7.00(ABTD.1) and earlier	7.00(ABTD.2)
NWA220AX-6E	7.00(ACCO.1) and earlier	7.00(ACCO.2)
NWA1123-AC PRO	6.28(ABHD.0) and earlier	6.28(ABHD.3)
NWA1123ACv3	6.70(ABVT.4) and earlier	6.70(ABVT.5)
WAC500	6.70(ABVS.4) and earlier	6.70(ABVS.5)
WAC500H	6.70(ABWA.4) and earlier	6.70(ABWA.5)
WAC6103D-I	6.28(AAXH.0) and earlier	6.28(AAXH.3)
WAC6502D-S	6.28(AASE.0) and earlier	6.28(AASE.3)
WAC6503D-S	6.28(AASF.0) and earlier	6.28(AASF.3)
WAC6552D-S	6.28(ABIO.0) and earlier	6.28(ABIO.3)
WAC6553D-E	6.28(AASG.2) and earlier	6.28(AASG.3)
WAX300H	7.00(ACHF.1) and earlier	7.00(ACHF.2)
WAX510D	7.00(ABTF.1) and earlier	7.00
Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-08-14

Welcome to update day!

Please check that your systems are updating after patches were released yesterday by Microsoft, Adobe and others. Android released their's earlier in August.

Details for MSFT -> buff.ly/3UbZCAL - This includes 6 in the wild attacks (buff.ly/3wcPuKs)

Midfoils Tech :donor: boosted:
2024-07-30

Lots of Apple updates.
You know the drill...
support.apple.com/en-us/HT2141

Midfoils Tech :donor: boosted:
2024-07-15

Microsoft has announced the general availability of its Entra Suite, a comprehensive secure access solution for workforces. The cloud-based suite offers a Zero Trust user access solution that allows organizations to converge access policy engine across identities, endpoints, and private and public networks. It secures employee access to any cloud or on-premises application and resource from any location while enforcing least privilege access.

The Microsoft Entra Suite includes products like Entra Private Access, Internet Access, ID Governance, ID Protection and Verified ID which all contribute towards unifying Conditional Access policies for identities and networks; ensuring least privilege access for all users accessing resources & apps; improving user experience for both in-office & remote workers; reducing complexity & cost of managing security tools from multiple vendors. To learn more about this new offering from Microsoft check out their official announcement [here](aka.ms/ZeroTrustBlog-July2024) or visit the trial page [here](aka.ms/EntraSuiteTrial).
Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #AAD #Identity techcommunity.microsoft.com/t5

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-06-28

Congratulations to our Principal Consultant who achieved their Cyber Advisor (Cyber Essentials) certification this week!

registry.blockmarktech.com/cer

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-06-05

This is one for your cyber security briefings to your staff:

cloud.google.com/blog/topics/t

You and your company may not be involved in the Olympics but the bad guys will still use it as a lure to trick you into clicking on that email..

h/t @screaminggoat

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-05-17

If you are one of those people that keeps their browser open all week without restarting it you may be missing out on important security updates.

The Chrome browser has had THREE updates this week alone...

Get in the habit of restarting your browser everyday...

You will be able to restore your tabs via the keyboard shortcut of CTRL + ALT + T for both Chrome & Edge, when the browser restarts.

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-05-14

This morning is @Apple's usual patch release day, and **everything** needs updating

Details here -> buff.ly/2Jy40mT

Midfoils Tech :donor:midfoilstech@infosec.exchange
2024-05-13

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst