McAfee is replacing the monthly SNS Digest with the SNS Weekly Roundup. To update your subscription preferences head over to the SNS Subscription Center.
Random ramblings and findings whilst maintaining and supporting MS Active Directory and interfacing
Friday, 15 September 2017
McAfee monthly SNS Digest is being replaced
Thursday, 29 June 2017
AlienVault v5.4 Addresses 72 vulnerabilities
Several vulnerabilities were discovered in the underlying OS packages in AlienVault USM Appliance and OSSIM v5.3.7 and earlier. All of the vulnerabilities below have been confirmed and fixed in the AlienVault v5.4. AlienVault encourages customers to upgrade all AlienVault appliances to eliminate the vulnerabilities.
See the v5.4 release notice for details on the release.
See the v5.4 release notice for details on the release.
Microsoft announce another CVE - Win32k Information Disclosure Vulnerability
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
Microsoft has reserved CVE candidate CVE-2017-8554 ready for announcement, but an early indication for MSRC shows the following OS Versions affected:
Windows 10
Windows 8.1
Windows 7
Server 2016
Server 2012 R2
Server 2012
Server 2008 R2
Server 2008
This vulnerability has been rated CVSS 4.7 resulting in a Medium Risk
Microsoft has reserved CVE candidate CVE-2017-8554 ready for announcement, but an early indication for MSRC shows the following OS Versions affected:
Windows 10
Windows 8.1
Windows 7
Server 2016
Server 2012 R2
Server 2012
Server 2008 R2
Server 2008
This vulnerability has been rated CVSS 4.7 resulting in a Medium Risk
Location:
Brixham TQ5, UK
Thursday, 8 June 2017
InfoSecurity Professional Magazine - May June 2017 Issue
(ISC)² Digital Publication design for the professional development of its members have released the May/June 2017 issue.
This issue covers Choosing a Cloud Access Security Broker, the third in a series of InfoSecurity Professional insights to GDPR and the Hong Kong Chapters work at promoting Safe and Secure Online.
All members can earn 2 group A CPEs for reading list issue and completing the quiz. You can read this issue online here and take the quiz here.
This issue covers Choosing a Cloud Access Security Broker, the third in a series of InfoSecurity Professional insights to GDPR and the Hong Kong Chapters work at promoting Safe and Secure Online.
All members can earn 2 group A CPEs for reading list issue and completing the quiz. You can read this issue online here and take the quiz here.
Location:
Brixham, UK
Thursday, 16 February 2017
McAfee Labs Threat Advisory for W32/DistTrack
W32/DistTrack is detection for a worm malware that has extremely destructive behaviour. Machines infected by it are rendered useless because most of the files, the Master Boot Record (MBR), and the partition tables are overwritten with random data. The overwritten data is lost and is not recoverable. The system is rendered unbootable.
Labels:
Intel Security,
McAfee,
SNS Notice,
Threat Advisory
Location:
Brixham TQ5, UK
McAfee Labs Threat Advisory for Ransomware-SAMAS
Ransomware-SAMAS is a detection for a family of ransomware that on execution encrypts certain file types present in the user’s system. The compromised user has to pay the attacker with a ransom to get the files decrypted.
Ransomware-SAMAS has been known to be used in targeted ransomware attacks on Organisations.
Ransomware-SAMAS has been known to be used in targeted ransomware attacks on Organisations.
Labels:
Intel Security,
McAfee,
SNS Notice,
Threat Advisory
Location:
Brixham TQ5, UK
Friday, 10 February 2017
PowerCLI 6.5 reference poster
If, like me you are using PowerShell to build and automate everything, the millions of PowerShell commands swimming around in your head can make you go stir crazy.
While listening to the VMware vExpert Community Podcast from 8/2/2017 I heard Kyle Ruddy announce that the PowerCLI 6.5 R1 Poster had been released.
Head over to the PowerCLI blog to grab yourself a copy.
While listening to the VMware vExpert Community Podcast from 8/2/2017 I heard Kyle Ruddy announce that the PowerCLI 6.5 R1 Poster had been released.
Head over to the PowerCLI blog to grab yourself a copy.
Wednesday, 5 October 2016
LDAP Authentication issues in USM and OSSIM v5.3.2
If you are using LDAP authentication for your OSSIM or USM installation you may want to hold off the v5.3.2 upgrade.
In a recent message from AlienVault, an issue has been detected during the password reset process post upgrade. The Password reset process was initiated to improve the security of password storage within OSSIM and USM, however this process is not working correctly for LDAP authentication.
LDAP Authentication issues in USM and OSSIM v5.3.2
If you are using LDAP authentication for your OSSIM or USM installation you may want to hold off the v5.3.2 upgrade.
In a recent message from AlienVault, an issue has been detected during the password reset process post upgrade. The Password reset process was initiated to improve the security of password storage within OSSIM and USM, however this process is not working correctly for LDAP authentication.
Friday, 30 September 2016
Collecting McAfee ePO threat data using AlienVault OSSIM
If you are using AlienVault OSSIM you can collect ePO Threat Data and add it to your SIEM Security Events.
AlienVault have already development a database plugin to connect to the ePO Database, collect and parse the data into the OSSIM Database, but I have struggled to get this to work with our MS-SQL Database cluster, resulting in 'ParserDatabase [INFO]: Can't connect to MS-SQL database' errors.
The steps for enabling the plugin and collecting the data are:
AlienVault have already development a database plugin to connect to the ePO Database, collect and parse the data into the OSSIM Database, but I have struggled to get this to work with our MS-SQL Database cluster, resulting in 'ParserDatabase [INFO]: Can't connect to MS-SQL database' errors.
The steps for enabling the plugin and collecting the data are:
- Enabling the Plugin
- Creating a local configuration file
- Configuring the database connection
- Troubleshooting connection errors
Labels:
AlienVault,
ePO,
McAfee
Location:
St Neots, UK
Tuesday, 30 August 2016
VirusScan 8.8 P8 release - Windows 10 Anniversary Edition
After some issues with VSE 8.8 not being compatible with Windows 10 Anniversary edition, Intel Security have now release Patch 8 which adds compatibility for the current build of Windows 10.
Patch 8 (build 8.8.0.1588) has been released to the update site, and if you are running ePO 5.1.1 or later the Software Manager will be able to pull this update into your Master Repository.
Full details for this release can be found in the release notes PD26631 and the supported platforms, environments and operating systems can be found in KB51111
Patch 8 (build 8.8.0.1588) has been released to the update site, and if you are running ePO 5.1.1 or later the Software Manager will be able to pull this update into your Master Repository.
Full details for this release can be found in the release notes PD26631 and the supported platforms, environments and operating systems can be found in KB51111
Labels:
ePO,
Intel Security,
McAfee
Location:
St Neots, UK
Friday, 26 August 2016
ePolicy Orchestrator update fixes multiple Oracle Java vulnerabilities - July 2016
ePO is vulnerable to the following CVEs reported in Oracle's July 2016 Java SE update.
Collectively, these vulnerabilities affect integrity and availability of the server.
AFFECTED SOFTWARE
ePO 5.1.3 and earlier
ePO 5.3.2 and earlier
REMEDIATED/PATCHED VERSIONS
Oracle Java 7.0 officially reached End of Life (EOL) status in April of 2015. The Java version currently supported in ePO 5.1.x and 5.3.x has been upgraded to Java 8.0. This issue is remediated with ePO 5.x Hotfix 1151890. These fixes will be included in the next ePO patch when scheduled.
ePO 5.1.3 + Hotfix 1151890 (EPO5xHF1151890.zip)
ePO 5.3.1 + Hotfix 1151890 (EPO5xHF1151890.zip)
ePO 5.3.2 + Hotfix 1151890 (EPO5xHF1151890.zip)
McAfee recommends that all customers verify that they have applied the latest updates. Impacted users should install the relevant patches or hotfixes. For full instructions and information, see McAfee Knowledge Base article SB10166.
Collectively, these vulnerabilities affect integrity and availability of the server.
AFFECTED SOFTWARE
ePO 5.1.3 and earlier
ePO 5.3.2 and earlier
REMEDIATED/PATCHED VERSIONS
Oracle Java 7.0 officially reached End of Life (EOL) status in April of 2015. The Java version currently supported in ePO 5.1.x and 5.3.x has been upgraded to Java 8.0. This issue is remediated with ePO 5.x Hotfix 1151890. These fixes will be included in the next ePO patch when scheduled.
ePO 5.1.3 + Hotfix 1151890 (EPO5xHF1151890.zip)
ePO 5.3.1 + Hotfix 1151890 (EPO5xHF1151890.zip)
ePO 5.3.2 + Hotfix 1151890 (EPO5xHF1151890.zip)
McAfee recommends that all customers verify that they have applied the latest updates. Impacted users should install the relevant patches or hotfixes. For full instructions and information, see McAfee Knowledge Base article SB10166.
Labels:
Intel Security,
McAfee,
Security Bulletin
Location:
St Neots, Saint Neots PE19, UK
Thursday, 16 June 2016
ePolicy Orchestrator update fixes multiple Oracle Java vulnerabilities - May 2016
ePO is vulnerable to multiple CVEs reported in Oracle's April 2016 Java SE update. Collectively, these vulnerabilities affect confidentiality, integrity, and availability of the server.
Labels:
ePO,
Intel Security,
Security Bulletin
Location:
Saint Neots, Cambridgeshire, UK
Monday, 13 June 2016
(ISC)2 SecureLondon 2016
This conference explores the impact of the rise of the virtual organisation on security practice; the solutions that are emerging to tackle this environment; and the lessons being learned within professional practice. Acknowledging the need to step away from the technology–driven approach that often dominates traditional systems security management, delegates will explore the foundational concepts that drive security and still apply in a world that is designed to be much less defined than in the past.
(ISC)2Members - Free
(ISC)2 Chapter Members: 50% discount
ISF Members: 15%
ISSA/ISACA Members: 10% discount
Registration available here
Location:
Saint Neots, Cambridgeshire, UK
Friday, 10 June 2016
PSRemoting Domain Controllers - Least Privilege access
Remoting Domain Controllers can speed up SysAdmin operations and enable SysAdmins to schedule automation tasks, lets be honest thats why we like Powershell so much. Being able to remote a domain controller requires elevated permissions and based on the Principle of least privilege we don't want to configure scheduled tasks using Domain Admin credentials.
Labels:
active directory,
PowerShell
Location:
Saint Neots, Cambridgeshire UK
Thursday, 9 June 2016
Becoming an Associate of (ISC)2
With the shortfall in the cybersecurity workforce projected to be 1.5 million globally in five years*, businesses are pressed to find qualified candidates to protect their organisation against cyber threats. The need for candidates to prove their capability is more important than ever.
The Associate of (ISC)² allows those just starting out in the information security workforce to demonstrate their competence in the field. Associates have passed a rigorous (ISC)² certification exam, proving their cybersecurity knowledge, and maintaining their continuing professional education (CPE) requirements while working toward completing the experience requirements to become fully certified as a CISSP, SSCP, CCSP, HCISPP, CCFP, CAP or CSSLP.
*2015 Global Information Security Workforce Study
*2015 Global Information Security Workforce Study
Labels:
(ISC)2
Location:
Saint Neots, Cambridgeshire UK
Tuesday, 24 May 2016
Inside the Verizon Data Breach Investigations Reports Webcast
Verizon’s 2016 Data Breach Investigations Report (DBIR) provides a comprehensive analysis of data breach patterns seen in 2015. As a contributor, Intel Security provided anonymized breach data and co-authored a section focusing on post-breach fraud and what happens to data once it has been stolen from the breached entity.
Earn one CPE credit for attending the live webcast.
Wednesday, June 8, 2016 11:00AM PT | 1:00PM CT | 2:00PM ET
REGISTER: https://events.demand.intelsecurity.com/ISecWebcast-6-08-16?s=DFMSNS
Earn one CPE credit for attending the live webcast.
Wednesday, June 8, 2016 11:00AM PT | 1:00PM CT | 2:00PM ET
REGISTER: https://events.demand.intelsecurity.com/ISecWebcast-6-08-16?s=DFMSNS
Labels:
(ISC)2,
CPE,
DBIR,
Intel Security,
webcast
Location:
Saint Neots, Cambridgeshire PE19, UK
Thursday, 12 May 2016
McAfee to Intel Security Migration
On May 12, 2016, the SNS Internet domain migrated from snssecure.mcafee.com to sns.secure.intelsecurity.com.
Labels:
Intel Security,
McAfee,
SNS Notice
Location:
St Neots, UK
Thursday, 7 April 2016
Update Lync LineURI with Active Directory Phone Number
In this series of Blog posts I will explain how we can use the Lync Powershell Modules to help automate some Bulk Lync user tasks. While most of these task can be completed using PowerShell Remoting using the OCSPowershell provider endpoint provided by the Lync server, some of the error forwarding through the proxy doesn't work as expected. In this case we can utilise the Lync Management Shell locally on our administration console.
Mass enabling Enterprise wide options in Lync can be laborious using the Control Panel, bulk changes can be best achieved using the Lync Management Shell. The Management Shell is a PowerShell session with the Lync Modules Imported at Runtime.
This is the second post in this Series detailing some tooling to help bulk enable an organisations Lync Users.
Mass enabling Enterprise wide options in Lync can be laborious using the Control Panel, bulk changes can be best achieved using the Lync Management Shell. The Management Shell is a PowerShell session with the Lync Modules Imported at Runtime.
This is the second post in this Series detailing some tooling to help bulk enable an organisations Lync Users.
Labels:
Managing Lync,
PowerShell
Location:
St Neots, UK
Wednesday, 6 April 2016
Installing Lync Modules on Administrative Consoles
Labels:
Managing Lync,
PowerShell
Location:
St Neots, UK
Subscribe to:
Posts (Atom)















