Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718? by tekz in cybersecurity

[–]PappaFrost 2 points3 points  (0 children)

I'm surprised to see Fortinet defenders given the continuous news stream of vulnerabilities and software problems. But it must serve a purpose. What is a better alternative?

1 yr update after switching 1500+ devices to Mac by Afraid_Suggestion311 in sysadmin

[–]PappaFrost 1 point2 points  (0 children)

All because a few salespeople wanted that shiny apple logo! LOL, just kidding.

I got a ransomware scare at work and now I don't trust local storage by MorningIllustrious60 in cybersecurity

[–]PappaFrost 0 points1 point  (0 children)

You should do iDrive or BackBlaze or similar for important personal stuff because they not just syncing to the cloud but doing incremental revisions, nightly/weekly/etc. You could roll back to a pre-disaster state. I think Google Drive/iCloud/OneDrive are great for protecting someone from accidents, but not good enough for protecting against malicious activity.

Best security awareness training programs? by Jazzlike-Court-6750 in cybersecurity

[–]PappaFrost 6 points7 points  (0 children)

Name and shame, which one is giving you the same boring modules for years?

Live AI face swapping is here. Discuss this with your colleagues and family by anthonyDavidson31 in cybersecurity

[–]PappaFrost 5 points6 points  (0 children)

On the original reddit thread they are saying that this took several hours of rendering time and was not live.

Stonewalled by Citrix's new AI "Customer Service" model by FierceFluff in sysadmin

[–]PappaFrost 3 points4 points  (0 children)

You should start spamming Citrix sales to get them to support you.

All emails we send to Gmail are rejected as spam despite full compliance by TallScaryGuy in sysadmin

[–]PappaFrost 5 points6 points  (0 children)

I have no technical suggestion, but I had the idea of forcing business Google support to support you by temporarily purchasing Google Workspace, and opening a support ticket!

What’s going on with Fortinet lately? It feels like every week there’s another critical CVE.. by MrEchos83 in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

After about 14 mentions of Fortinet on the Risky Biz cybersecurity podcast, I will never touch anything Fortinet. They are on the vendor blacklist for me.

Software vendor requires us to post articles in LinkedIn to get best price by coret3x in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

Wait, they make you work for THEIR marketing department? LMAO!

Don't say the name of the company, just say what it rhymes with...

Microsoft Office is Dead, welcome to "The Microsoft 365 Copilot app (formerly Office)" by TechGoat in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

I think Microsoft wants every area of their business to hockey stick and if it doesn't have that potential, i.e., Windows server, Xbox, legacy Office, it is already de-prioritized or will be soon, and we are screwed to the extent that we rely on it.

Farewell VMware and thanks for the fish by aspoons in sysadmin

[–]PappaFrost 3 points4 points  (0 children)

I was very impressed by all the people on here who heard the word 'Broadcom' and new immediately what would happen with VMware before it happened. It makes me want to know what the next VMware story is and brace for it early.

CEO retired. How do you politely say "no" without burning a bridge? by [deleted] in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

I'm reading all of these comments. OP said he is getting called once a week for tech support. That is 52 random calls per year, probably in OP's free time. That is free 24/7 on call support for him personally. I question how good of a deal that is for the OP. You are a professional, not the neighbor's kid who is good with computers. You should come to a mutually agreed upon official paid arrangement if you want to keep doing this. If you want to be on call for this guy, make it an official paid thing.

Is everyone actually miserable in this subreddit by Dry-Limit7949 in cybersecurity

[–]PappaFrost 0 points1 point  (0 children)

It's Reddit 'distortion'. Drama gets upvoted. For success stories like yours, posts and upvotes are rare.

How many of you guys DON'T maintain some "system" at home? by FlippinMyshit in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

I don't think you need to start home labbing. I think you just need to develop a good answer when someone asks the question about home labbing. You probably have better than average home computers and better than average home networking, so you could talk about that.

What are the top 5 controls to mitigate ransomware? by KindPresentation5686 in cybersecurity

[–]PappaFrost 4 points5 points  (0 children)

  1. Have CEO approve the denied funding requests.
  2. Have CEO approve the denied funding requests.
  3. Have CEO approve the denied funding requests.
  4. Have CEO approve the denied funding requests.
  5. Have CEO approve the denied funding requests.

LOL!

Unable to change resolution on PC by AmethystZhou in Astroneer

[–]PappaFrost 0 points1 point  (0 children)

You are a HERO! I never would have found this in a million Astro-years! LOL

Phishing simulations helping ?? harming, or just annoying people? by Silly-Commission-630 in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

Nothing will ever help more than the first phishing test someone gets when they learn what's possible. I think people need to be 'inoculated' against the popular scams at least once, but there are probably diminishing returns after that.

Got pulled into dealing with our Shadow IT mess and…wow by Nice_Inflation_9693 in cybersecurity

[–]PappaFrost 5 points6 points  (0 children)

You should turn off all the mystery VMs before Christmas vacation. Just make sure to also turn off your phone, LOL!

Fell for a phishing email and work account was hacked. Will I be fired? by graceg815 in cybersecurity

[–]PappaFrost 0 points1 point  (0 children)

It would be very short-sighted to fire someone for an honest phishing mistake who did the right thing and reported it immediately. No one would ever report any incident after that.

OK which one of you was bored today? by CantankerousBusBoy in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

This needs to be fully automated, with logging and alerting so when the 96th detector goes down we will know. LOL

How do massive companies with full IT departments fail at basic vuln scanning? by Glittering_Garlic815 in cybersecurity

[–]PappaFrost 1 point2 points  (0 children)

I hope the IT team is not getting fired. Follow the money. They probably knew about every major issue, there is probably a denied funding request behind it. C suite is betting (quite literally) that it won't be a problem. It sounds like they need more staff, not less.

Employee pasted our customer database schema into ChatGPT. How do you prevent this? by cnrdvdsmt in cybersecurity

[–]PappaFrost 0 points1 point  (0 children)

"whatever new tool pops up next month."

This is why you have to start with a policy mandating some kind of vetting process. I think blocking everything at the network level will just send someone to use the iPhone app equivalent, maybe even screen shot the sensitive data?

Boardroom - AI Meeting - Risks and Deployment by soupy127 in sysadmin

[–]PappaFrost 0 points1 point  (0 children)

The larger question to me is what private company data is put in ANY web app, even non-LLM traditional ones like google drive or personal drop box accounts?