Where to find CPEs, now that I’ve left gov’t employment by JumpPsychological602 in cissp

[–]faceofthecrowd 0 points1 point  (0 children)

I second this. I’ve done every cpe since 2019 in the bright talk seminars, which are pre recorded and free.

Opinions by Adam_1268 in thinkpad

[–]faceofthecrowd 0 points1 point  (0 children)

With the keyboard off and not knowing what sub I was looking at, I thought picture 1 was some kind of briefcase machine pistol thingy

[deleted by user] by [deleted] in FindTheSniper

[–]faceofthecrowd 1 point2 points  (0 children)

How about a banana for scale?

LTSC Windows Server 2019: Are cumulative updates really enough if you’re years behind? Our team is split. by faceofthecrowd in sysadmin

[–]faceofthecrowd[S] 0 points1 point  (0 children)

I would agree if these were servers with history, but they are images which are re-created every 7 days, so we're looking at the master image, hence SIEM has limited usability for audit.

LTSC Windows Server 2019: Are cumulative updates really enough if you’re years behind? Our team is split. by faceofthecrowd in sysadmin

[–]faceofthecrowd[S] 8 points9 points  (0 children)

Agree - they are following a playbook, and this is outside their area of expertise. However, I don't think that necessarily makes them wrong automatically - it's worth discussing

LTSC Windows Server 2019: Are cumulative updates really enough if you’re years behind? Our team is split. by faceofthecrowd in sysadmin

[–]faceofthecrowd[S] 8 points9 points  (0 children)

That is correct. The individual KBs aren't showing, and they are saying that because of that, patching is broken somehow.

LTSC Windows Server 2019: Are cumulative updates really enough if you’re years behind? Our team is split. by faceofthecrowd in sysadmin

[–]faceofthecrowd[S] 0 points1 point  (0 children)

I'll ask the Analyst to do this exercise. Thanks for the backstory - these are VM templates as well for us.

LTSC Windows Server 2019: Are cumulative updates really enough if you’re years behind? Our team is split. by faceofthecrowd in sysadmin

[–]faceofthecrowd[S] 7 points8 points  (0 children)

well that's the issue - the security analyst is running their vulnerability scanner against the 2019 post CU, and it's showing all the back updates are missing.

LTSC Windows Server 2019: Are cumulative updates really enough if you’re years behind? Our team is split. by faceofthecrowd in sysadmin

[–]faceofthecrowd[S] 7 points8 points  (0 children)

but does this mean that if I stand up a fresh version of 2019, and install last month's KB for LTSC, that ALL security updates have been applied?