Security best practices for Windows Server Update Services (WSUS)

Security best practices for Windows Server Update Services (WSUS)To help provide additional protection from potential malware attacks, Microsoft recommends using HTTPS with Windows Server Update Services (WSUS). In this post, we will walk you through the steps required to configure each of your WSUS servers to use HTTPS. We will then share details on how to obtai…TECHCOMMUNITY.MICROSOFT.COM [https://techcommunity.microsoft.com/t5/windows-it-pro-blog/security-best-practices-for-windows-server-upd…

Read More

Human-operated ransomware attacks: A preventable disaster

Human-operated ransomware attacks: A preventable disaster - Microsoft SecurityIn human-operated ransomware attacks, adversaries exhibit extensive knowledge of systems administration and common network security misconfigurations, perform thorough reconnaissance, and adapt to what they discover in a compromised network.Microsoft SecurityMicrosoft Threat Protection Intelligence Team [https://www.microsoft.com/security/blog/2020/03/05/human-operated-ransomware-attacks-a-preventable-disaster/]…

Read More

@SwiftOnSecurity: Due to the very low perf cost of Defender antivirus update checks, I’m experimenting with launching an update request to their cloud 90 seconds after every login and workstation unlock.

> Due to the very low perf cost of Defender antivirus update checks, I’m experimenting with launching an update request to their cloud 90 seconds after every login and workstation unlock. By that time user has stable network connection. Defender’s “update on startup” is unreliable. — SwiftOnSecurity (@SwiftOnSecurity) July 25, 2020 [https://twitter.com/SwiftOnSecurity/status/1286887124411846661?ref_src=twsrc%5Etfw]…

Read More

CIAOPS: The insecurity of shared mailboxes

https://blog.ciaops.com/2019/04/27/the-insecurity-of-shared-mailboxes/ Shared mailboxes are a really handy component of Microsoft 365 in that they allow multiple users to access a single mailbox. This works really well for generic accounts like info@, accounts@, etc. However, there are some security issues with these that I don’t think many people are aware of. The first point to note is that shared mailboxes in Microsoft 365 actually have a login and password. Thus, they can be accessed direc…

Read More