This is yet another example of the cybercriminal bad guys taking advantage of a crisis situation and attempting to catch us with our collective guards down. I know many in the business world are now nearly completely reliant upon Skype, Teams, WebEx, and Zoom to function on a daily basis, but that need to stay connected cannot supersede the sound security practices that protect data and keep us safe.
Remember this simple truth – if you get an email message regarding an issue with an online service or tool, stop and don’t click any email links. Go directly to the website you know and trust from a browser. Any messages or alerts sent via email will be there on the website waiting for you. President Reagan’s montra is applicable and not cliché, Trust but verify.
This situation is a great example of the importance of patch and firmware management. Just because a system is hosted in the cloud, it does not mean that you are not responsible for parts if not all of the patch and firmware oversight. Pay close attention to your service level agreements and other cloud services documentation.
If you are using these particular Azure services from Microsoft, please review this content and patch accordingly.
It’s that time again when we all get to evaluate our PC and server environments and kick off our monthly patching processes. Please take a look at the changes this month and patch accordingly. And please don’t forget your at-home devices. Patching is not just a business process. All computers and workstations and laptops need to be patched and updated on a regular basis.
Our ability to securely move beyond passwords as the singular trusted authentication mechanism has been here for some time, but concept and related technology has lacked traction. I am excited to see Microsoft continue to endorse and partner with the FIDO Alliance to bring forward secure, alternative authentication options to the masses.
Please remember that even the best Microsoft Hello option is still often a single authentication factor. For sensitive system access, multi-factor authentication is still the safest, most effective approach to authentication.
The Patch Tuesday cycle has begun once again and the team at Fortinet has announced some of the conditions surrounding several of the Windows and Office related patches that have been released by Microsoft. Please review your environments and patch your systems accordingly.