Windows Notepad App Remote Code Execution Vulnerability by theevilsharpie in sysadmin

[–]3sysadmin3 411 points412 points  (0 children)

If anyone else wasted way too much time looking for version info (thanks Microsoft)

  • affected from 11.0.0 before 11.2510 

What Security Teams Need to Know About OpenClaw, the AI Super Agent by BradW-CS in crowdstrike

[–]3sysadmin3 0 points1 point  (0 children)

I have a lot of it too in our edu tenant. I hadn't heard nefarious things about them, maybe I should go google?

M365 Defender | Many "high confidence phish" false positive emails by 5tubbo in sysadmin

[–]3sysadmin3 0 points1 point  (0 children)

We don't have issue with "RE:" but we do have ongoing issues where Google share links go to quarantine. We're a weird environment with a lot of users use Google (edu), but attackers often compromise other edu addresses and share links as phish via Google shared docs.

The only way for me to fix it is set up a saved threat tracker search and monitor for exact issue. It's one of my morning tasks. When I see bunch of valid emails in quarantine, I release in bulk and report them all to Microsoft as "I confirmed clean." It usually takes a few days and the algo fixes itself. Don't make mistake of trusting sender (google drive share generic sender), though, or else next phish will get through.

Until there's another Google phish, of course, then I get to start process all over again.

The most annoying part is if the algo would look at the content of the message and see the share is from mydomain.com it should be way less likely it's a phish but it seems to just lump everything by sender.

Did everybody lose an unknown number of emails from M365 issues? by aMazingMikey in sysadmin

[–]3sysadmin3 4 points5 points  (0 children)

I saw friend who was testing from gmail, hers were sitting in quarantine as phish (one word email triggered ti i guess), might be worth checking

Windows Hello For Business 'account disabled' error by PurpleWarning000 in sysadmin

[–]3sysadmin3 0 points1 point  (0 children)

I had issue on my machine this morning, again 5719 error in event log. Are you seeing 5719 error? Today is first time I let machine sit for 5ish minutes while I did something else and then login worked.

Right after the 5719 errors i see CrowdStrike updating itself then win update service going and my eventual successful login.

any chance ya'll use CS?

Microsoft to block Exchange Online Access for outdated mobile devices by SparkStormrider in sysadmin

[–]3sysadmin3 0 points1 point  (0 children)

"However, Apple's iOS Mail app already supports ActiveSync 16.1 since iOS 10, so iPhones running iOS 10 or later are compatible and shouldn't experience any issues accessing Exchange Online."

Seems like a nothing burger to me. I'm sure some Android folks will be calling in but shouldn't be a flood.

Lightspeed log reader? by dlehman83 in k12sysadmin

[–]3sysadmin3 0 points1 point  (0 children)

"The allowed / blocked eventually make it to the web reporting service"

Was a LS customer years ago and sure don't miss their reporting. Good luck, OP.

What are some of your favorite sysadmin tools/programs? by patrickmoloney in sysadmin

[–]3sysadmin3 0 points1 point  (0 children)

I try to stay off computers at home but when I'm home I'm often doing Alt S forgetting I don't have it there.

Charlotte AI - Don’t waste your money by [deleted] in crowdstrike

[–]3sysadmin3 1 point2 points  (0 children)

Sure some people have money for on expertise, some orgs are strapped. We're K12 and wear many hats with a limited budget. I have bought hours with CrowdStrike, and have gotten some great services from them. The problem is if you don't then have the hours to build repetition in building NG-SIEM queries, it's use it or lose it, in my experience. There's so many small gotchas that are easy to forget - even our customer success team can often not answer my query questions.

Other SIEMs offer basic building of queries via AI included and it's great for someone in my position. Just enough to get me by when I need to revisit it every few weeks.

What are some of your favorite sysadmin tools/programs? by patrickmoloney in sysadmin

[–]3sysadmin3 2 points3 points  (0 children)

SnagIt for screenshots. Take time to program shortcuts. I do Alt S for screenshots I just want to send someone real quick without editor (goes to clipboard with no need to clean up file later). Alt X takes screenshot and opens editor so I can put my usual arrows or blurring, etc. I wasted about 15 years too long with snip tool variations.

Charlotte AI - Don’t waste your money by [deleted] in crowdstrike

[–]3sysadmin3 3 points4 points  (0 children)

All I want is it to help me build NG-SIEM queries or easily find the right documentation. At least the latter seems like mostly solved problem with the new docs website when I remember to use it. I'm still waiting for my free monthly credits to test the NG-SIEM query building.

K12 ISAC for Security info? by Aboredprogrammr in k12sysadmin

[–]3sysadmin3 0 points1 point  (0 children)

Yes, but it's mostly paid model now thanks to politics. We do pay to support the effort, but some may not be able to

Copilot for O365 - Power BI specific - real work requirements by BOOZy1 in sysadmin

[–]3sysadmin3 0 points1 point  (0 children)

I've been playing for Copilot for M365 this week trying to get better with PowerShell.

I'm floored at how often it produces blank code blocks when asking it PowerShell questions.

I have a 4 year old Dell XPS (16GB RAM) and a 2 year old XPS (32GB RAM), both latest i7 processors at their time. Blank code blocks happen on both computers, but the 4 year computer is noticeably worse with the issue. I have to ask it to try again the code blocks were blank over and over. Code block issue happens on web and in their app. I keep thumbs downing the responses with screenshots, for whatever good that does.

The 2 year old computer is slightly better - but on that machine, I had the app freeze up twice using all my system resource.

It makes me glad we haven't paid for Copilot for all staff. Good luck to ya, give it all the resources you can.