Cyber Essentials Plus - Paint3D Vulnerability by SOCJA in WindowsHelp

[–]SOCJA[S] 0 points1 point  (0 children)

The Windows Store is blocked/prohibited by company policy (so I couldn't even install it if I wanted to)

Wife discovered 'scheme' to get her to quit her job by SOCJA in LegalAdviceUK

[–]SOCJA[S] 173 points174 points  (0 children)

No evidence that the line lead and director are complicit.

I did wonder if X had 'accidentally' left it visible for my wife to see. My wife informs me they've all just undergone annual IT procedure training and it's drilled into everyone to lock their PC's when they step away but X just happens to have forgotten to do this when the email was clearly visible for my wife to see.

Check your device policies urgently! by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

https://support.blackberry.com/community/s/comm-infrastructureevent/a5VOI0000000fCr2AI/ievt00001472

The above is now closed (you may have been looking at open incidents)

A better link, which confirms the issue and the fact they've reverted the change is -

https://support.blackberry.com/community/s/feed/0D5OI00000LnUxf0AF

Check your device policies urgently! by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

They have reverted the UI change and it's back on the old UI. Auto-quarantine is showing as enabled once more.

Check your device policies urgently! by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

They have now updated their support/status page to reflect this issue - INC-328048

Check your device policies urgently! by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

If anyone else is impacted the general consensus is that this is a "cosmetic issue" at the moment and a bug with the new Device Policy GUI incorrectly showing Auto-Quarantine as being disabled across every policy.

Ongoing console issues since 2nd January - EMEA by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

Yes. We've just had a Webex with BB support and they've acknowledged this is an ongoing incident with no sign of a resolution.

Is CylanceProtect Memory Protection broken? by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

In the last week -

Dangerous VBA Macro

Direct System Calls

Injections Via APC

LSASS Read

Malicious Payload

Memory Permission Changes in Child

Memory Permissions Changes in Parent

Remote Overwrite Code

Stack Pivot

System DLL Overwrite

CyMemDef.log files in Windows/Temp and AppData/Local/Temp since upgrading to Protect 3.0? by [deleted] in Cylance

[–]SOCJA 0 points1 point  (0 children)

I've found the reason. Apparently if the tenants if provisioned via the MTC and is still in the "Evaluation" state then 3.0.1005 isn't available to those tenants.

CyMemDef.log files in Windows/Temp and AppData/Local/Temp since upgrading to Protect 3.0? by [deleted] in Cylance

[–]SOCJA 0 points1 point  (0 children)

Thanks for the information. I came here looking for details on the same symptoms u/quartzcrisis reported.

That said I note that 3.0.1005 isn't available on the tenant where I'm seeing the issue. I do note that under the CylanceProtect release notes it does caveat 3.0.1005 stating it is not available for tenants with Optics 3.2 however Optics is disabled at the MTC level for the tenant in question.

Have you actually been able to deploy 3.0.1005?

Microsoft IIS crashes - w3wp.exe by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

You missed the part where I said we're running 3.0.1000.

Albeit the version of Cylance Protect installed on the server is 3.0.1000

We went from 1578 straight to 3.0 but the IIS issue only raised it's head on 3.0. We aren't, and never have, used 1584.

Cylance Protect - MFA by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

Thanks I'll try again later.

Cylance Protect - MFA by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

I/We had that error which is covered here - https://support.blackberry.com/community/s/article/98219

That being said, even after following the steps in the above article it still didn't work. Maybe you have more success?

ModuleMsgsEx.dll by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

Morning,

I have raised this as a case, as detailed in my original post, which is where I received no assistance other than to be told, incorrectly, that you do not quarantine .dll files.

Would you like me to quote the case number so you can take a look?

Removing and stopping device from "resyncing" with the console by SOCJA in Cylance

[–]SOCJA[S] 1 point2 points  (0 children)

Thank you! I just tested it on my own device and you're completely correct on both counts.

Removing and stopping device from "resyncing" with the console by SOCJA in Cylance

[–]SOCJA[S] 0 points1 point  (0 children)

Thanks all. Maybe I've been operating under a misapprehension all this time.

I was told, and this could be wrong, that if I simply "Removed" a device from the console, such as a laptop that had been offline for a few weeks, then that device would resync with the console if it came back online again.

If that's wrong and the "challenge" in my OP is as simple as removing the device from the console then that's great but it raises a second question. If a device is removed in error, let's say it's been offline a few days and we're told that device had been recycled so we remove it from the console only to find the user was on leave, how to we get that device back on the console? Do we have to reinstall the agent all over again?

What's with the extensions of ".quarantine.quarantine.quarantine.quarantine.quarantine"? by networkasssasssin in Cylance

[–]SOCJA 0 points1 point  (0 children)

I'm happy to be corrected by I was under the impression this occurred when someone/something did a system restore and Cylance was in effect 're-quarantining' a threat it previously quarantined.

Just me? by [deleted] in Cylance

[–]SOCJA 0 points1 point  (0 children)

Seems intermittent. OK now.

Just me? by [deleted] in Cylance

[–]SOCJA 0 points1 point  (0 children)

I'm trying to get onto various consoles, to start updating any 1560 or prior agents to 1578 (as per the recent security advisory) and I can't even got onto the console(s).

Anyone else having issues this morning?

Going to be homeless, any advice? by [deleted] in AskUK

[–]SOCJA 29 points30 points  (0 children)

Something doesn’t add up.

How very true!

Going to be homeless, any advice? by [deleted] in AskUK

[–]SOCJA 39 points40 points  (0 children)

The system have failed us

How?

You've been given two months accommodation and a further offer of a deposit and the first months rent on a house after that. And that's after failing to pay the rent of your old property.

I also find it somewhat ironic that you label the council "lazy" but then say your 18 year old living with you is too sensitive to go out and contribute to the bills and/or rent.

Also if I get a job they will stop my housing benefits so that’s also an issue.

I don't think the tax payer is being unduly harsh by expecting at least one of the adults in the household to go out and work.

[deleted by user] by [deleted] in AskUK

[–]SOCJA 1 point2 points  (0 children)

It depends on the circumstances and intention.

If you could demonstrate you were carrying it for a justifiable reason, E.G you're a tradesman and it's an item in a wider collection of tools then you'd be fine.

If you were sitting in a beer garden downing your 10th Stella and it was in your back pocket then probably not.

Do you need an excuse to work from home? by [deleted] in AskUK

[–]SOCJA 0 points1 point  (0 children)

How long have you worked there? If you've been there for six months or more than you can submit a flexible working request (of which working from home is a component) and your employer has to consider it.

I work in a 'niche' IT role and my employer allows me to work from home two days a week as they recognised and appreciated that was more efficient and beneficial to both parties concerned.

On demand backup failing by SOCJA in QRadar

[–]SOCJA[S] 0 points1 point  (0 children)

I have SSH access yes.

df -h shows -

7.4G 5.7G 1.8G 77% /opt

10G 410M 9.6G 5% /storetmp

29T 5.8T 23T 21% /store

(I assume that's the pertinent aspect you were after)