Fake O365 message Important Upgrade Is Required – Phishing

We see lots of phishing attempts for email credentials. This one is a typical one. It pretends to be a message from Microsoft Office365 saying your mailbox is full. It is so obvious from the style of the email that these are not written by a native English speaker. I Continue reading → Continue reading Fake O365 message Important Upgrade Is Required – Phishing

Microsoft updates the Office 365 Enterprise K1 plan to add services for frontline employees

Microsoft has just unveiled new additions to the current Office 365 Enterprise K1 subscription plan that puts valuable tools in the hands of your employees that can help them be more productive.

read more Continue reading Microsoft updates the Office 365 Enterprise K1 plan to add services for frontline employees

Cyber Security Roundup for March 2017

Security researchers found there were able to find numerous sensitive documents by searching Microsoft’s Office 365 documents made publically accessible through the Docs.com website. Documents found included business confidential information, passwords and personal data. The issue was not caused by any security vulnerability in O365, but by its users misconfiguring or not understand the access permissions on their Microsoft O365 file storage, inadvertently permitting public access to their confidential data.  Businesses and users need to meet cloud services halfway when it comes to security, that starts obtaining a clear understanding of what security the cloud service does and does not do, so ensure your security homework is done before adopting the cloud.

A patch for a critical vulnerability in Apache (Server) Struts was released this month, the vulnerability, which is being actively exploited by cyber criminals in ransomware attacks, allows the remote execution of commands on the server. Non-Microsoft patches are more likely to be missed, given the patch process of Apache servers is often a manual one. It is essential to check any Apache server software facing the internet is constantly kept up to date, in this case, make sure the Struts framework element as used with Java EE web apps, is running a non-vulnerable version, either Struts 2.3.32 or Struts 2.5.10.1

It is the official ‘goodbye Vista’ next month as of 11 April 2017, Microsoft will no longer support Windows Vista, which means no further security updates to fix new vulnerabilities, either free or via paid assisted support options. So if you have Windows Vista, either upgrade or apply additional security measures such as application whitelisting to be safe. It is less overhead and cheaper long-term to upgrade to a supported Operating System in my view.

Finally, the UK Government Digital and Culture Minister, Matt Hanock, is pushing for further adoption of the Cyber Essentials scheme, insisting all governance contractors hold a Cyber Essentials certificate. A number of businesses have also agreed to require their suppliers to achieve Cyber Essentials, including Barclays, BT, Vodafone, Astra Zeneca, Airbus Defence & Space and Intel Security.  Hancock said   “We know the scale of the threat is significant: one in three small firms and 65% of large businesses are known to have experienced a cyber-breach or attack in the past year. Of those large firms breached, a quarter was known to have been attacked at least once per month.” Cyber-security is one of the seven pillars of the government’s digital strategy, he said. “It’s absolutely crucial UK industry is protected against this threat – because our economy is a digital economy.” 

News

Awareness, Education and Threat Intelligence

Continue reading Cyber Security Roundup for March 2017

SharePoint Podcast #330 — Number 4 Will Shock You

Shane Young and Todd Klindt discuss the most popular version of SharePoint, the release of the new SharePoint Online management cmdlets, Azure AD Connect, the SharePoint Framework roadmap, a little Hotmail hacking, their love of BGInfo, and Google Docs.

The post SharePoint Podcast #330 — Number 4 Will Shock You appeared first on Petri.

Continue reading SharePoint Podcast #330 — Number 4 Will Shock You

SharePoint Podcast Episode #329 — Well-Known and Irritating to One and All

Todd Klindt and Shane Young talk about two-factor authentication hitting home in the last week and we remind you all to go turn it on yourself. Then discuss a new PowerShell Video Shane made that shows you how to copy, move, and delete SharePoint Online files using PowerShell and we hit on new features for OneDrive for Business and AD Group management for Office 365.

The post SharePoint Podcast Episode #329 — Well-Known and Irritating to One and All appeared first on Petri.

Continue reading SharePoint Podcast Episode #329 — Well-Known and Irritating to One and All

Getting Started with PowerShell for SharePoint Online and Office 365

snag-0009

Shane Young dives into the different PowerShell for SharePoint Online and Office 365 cmdlets available, how to get them installed, and then the tricky part of connecting.

The post Getting Started with PowerShell for SharePoint Online and Office 365 appeared first on Petri.

Continue reading Getting Started with PowerShell for SharePoint Online and Office 365