VMware pushes admins to uninstall vulnerable, deprecated vSphere plugin (CVE-2024-22245, CVE-2024-22250)

VMware Enhanced Authentication Plug-in (EAP), a plugin for VMware vSphere, has two vulnerabilities (CVE-2024-22245, CVE-2024-22250) that could be exploited by attackers to mount authentication relay and session hijack attacks. The vulnerabilities haven… Continue reading VMware pushes admins to uninstall vulnerable, deprecated vSphere plugin (CVE-2024-22245, CVE-2024-22250)

First Ring Daily: Local AI, Cloud AI, and a Build of AI

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss how Microsoft’s Build 2024 conference will be all about AI and Copilots, and how AI technology could become the next big data harvesting tool. 

The post First Ring Daily: Local AI, Cloud AI, and a Build of AI appeared first on Petri IT Knowledgebase.

Continue reading First Ring Daily: Local AI, Cloud AI, and a Build of AI

On the Insecurity of Software Bloat

Good essay on software bloat and the insecurities it causes.

The world ships too much code, most of it by third parties, sometimes unintended, most of it uninspected. Because of this, there is a huge attack surface full of mediocre code. Efforts are ongoing to improve the quality of code itself, but many exploits are due to logic fails, and less progress has been made scanning for those. Meanwhile, great strides could be made by paring down just how much code we expose to the world. This will increase time to market for products, but legislation is around the corner that should force vendors to take security more seriously…

Continue reading On the Insecurity of Software Bloat

Microsoft Enters Talks with CISPE to Address Cloud Licensing Complaints

Microsoft has recently started talks with the Cloud Infrastructure Services Providers in Europe (CISPE) to address an ongoing antitrust case. These discussions aim to resolve concerns regarding the company’s anti-competitive licensing policies. The Cloud Infrastructure Service Providers in Europe (CISPE) association is an organization that represents cloud infrastructure providers based in Europe. It includes both…

The post Microsoft Enters Talks with CISPE to Address Cloud Licensing Complaints appeared first on Petri IT Knowledgebase.

Continue reading Microsoft Enters Talks with CISPE to Address Cloud Licensing Complaints

Embracing offensive cybersecurity tactics for defense against dynamic threats

In this Help Net Security, Alexander Hagenah, Head of Cyber Controls at SIX, discusses the critical steps in creating effective offensive security operations and their impact on organizational security strategies. What are the critical steps in creatin… Continue reading Embracing offensive cybersecurity tactics for defense against dynamic threats

How AWS Responded to the Generative AI Wave of 2023 (and What IT Pros Should Expect in 2024)

After a big year for AI in Australia and New Zealand in 2023, AWS’s Rada Stanic and Louise Stigwood reflect on innovations made to support generative AI and predict it will continue to be a focus into 2024. Continue reading How AWS Responded to the Generative AI Wave of 2023 (and What IT Pros Should Expect in 2024)

SrSecEng – how to optimize for future vision [closed]

I’d like to do Cloud, Security, and Programming, ideally in Python/Golang. To move from process automation towards asynchronous, distributed, autonomic systems. Security inspired by DevOps/SRE practices. That’s my ideal trajectory.
I’ve be… Continue reading SrSecEng – how to optimize for future vision [closed]