Daily Bulletin

Business Mentor

.

March Patch Tuesday Commentary

  • Written by Chris Goettl, Senior Director of Product Management, Security at Ivanti


There was an interesting start to March, with four Exchange Server exploits and an out of band update.      There is an additional Zero Day vulnerability being exploited in Internet Explorer and three publicly disclosed vulnerabilities to discuss this month. A total of 83 unique CVEs (Common Vulnerabilities and Exposures) have been resolved in Microsoft’s March Patch Tuesday update. Microsoft products affected this month include Windows OS, Office, Internet Explorer, Edge, Exchange Server, and Sharepoint, as well as many development tools and updates for Azure, Azure DevOps, and Azure Sphere

 

Exchange Zero Day Update:

Microsoft has provided a set of links to many relevant articles on the Exchange vulnerabilities, steps to identify if your environment has been compromised, mitigation options meant to protect environments short-term at the sacrifice of some functionality, and steps to take if you believe you have found indications of compromise. They also expanded the release with additional version\CU coverage.     

It is rare for Microsoft to update out of support versions of a product. This is an indication of the severity and reach of the attacks targeting the Exchange Server on-prem products. Revision note:

Reason for Revision: Microsoft is releasing security updates for CVE-2021-27065, CVE-2021-26855, CVE-2021-26857, and CVE-2021-26858 for several Cumulative Updates that are out of support, including Exchange Server 2019 CU 6, CU 5, and CU 4 and Exchange Server 2016 CU 16, CU 15, and CU14.

Please see the following for more information on the Microsoft Exchange Server Vulnerabilities:

Exploited and Publicly Disclosed Vulnerabilities:

Internet Explorer and Edge (HTML-based) browsers are being targeted by attacks in the wild. This vulnerability has also been publicly disclosed, which would allow other threats. CVE-2021-26411 is a memory corruption vulnerability that could allow an attacker to target users with specially crafted content. An attacker could utilise specially crafted websites or websites that accept user-provided content or advertisements to host content designed to exploit this vulnerability.

 

A publicly disclosed vulnerability (CVE-2021-27077) exists in Windows Win32k that could allow an attacker to elevate privileges on the affected system. The vulnerability is rated as Important and carries a base score of 7.8, but the exposure of being publicly disclosed raises the potential risk.

 

A .Net Core update from February has been re-released to provide links to release notes. The vulnerability from February had been publicly disclosed and, if exploited, could allow Remote Code Execution (CVE-2021-26701). The vulnerability has been rated as Critical and affects Microsoft .Net 5.0, .Net Core 3.1 and 2.1 as well as Visual Studio 2019 and 2017 versions.

 

March Update Priorities:

  • Exchange Server on-prem is the top priority
  • Windows OS, Internet Explorer, Edge: The browser Zero Day and other critical and publicly disclosed vulnerabilities require priority attention.
  • SharePoint Server: While not disclosed or exploited, CVE-2021-27076 is a Critical CVE and Microsoft has flagged it as Exploitation More Likely on their Exploitability Assessment.   

 

Bad Habits Today, Huge Losses Tomorrow

  • Written by News Co

Running a business is not an easy task, so if you have one under your name, Congratulations! But if you are taking proper care of your company premises, it might cause an issue. One such issue is the presence of bugs at your place.

Well! If you own a company in Sydney, you are well aware of the seriousness of this condition. But somehow, everyone thinks that it's only the cool temperatures that attract bugs to inhabit an office place. Well! To burst the bubble, let's be frank here. It's your everyday actions that might be inviting the pests to your office space.

But how can you amend the issues if you have no idea what we are talking about? Well! Scroll down, and you'll find out.


Habits That Might be Inviting Unwanted Guests (Pests) to Your Business Location

Did you know closed spaces can be an ideal place for pests to hide? For instance, if your enterprise contains caulk cracks or crevices around baseboards or cabinets, it might become a passage of pests entry to your place.

This isn't it!

If you have recycling bins near your office or placed in an attached garage, the remnants of the food or soda might appeal to the ants to your place. Further, if piles of paper, fabric, or other clutter are lying around, it might attract rodents or other bugs. Now that you know about what might be causing the pest infestation, the next step is to do the right thing.

How to Stop Bugs Inhabiting Your Business Location?

Well, the first thing you should do is get professional guidance. For instance, if your company was closed due to the pandemic, you must call a Commercial Pest Control Sydney and screen your place for all the possible bugs or rodents before starting it again.

Other than that, you must seal all the gaps or doors. And weatherproof all the windows. Keep a check on leaks in different areas of the workplace. Also, if you provide your employees with the facility of food within the premises, make sure to use sealed containers or other measures to avoid it attracting your place.

But that's not it!

Usually, cleanliness is the primary cause of pest issues. If you are keeping your worksite untidy or not well maintained, you will likely reencounter pest issues. So, you need to screen the breeding and nesting areas, remove them and make sure that you don't make the mistakes again.

Wrapping up- Break The Habits That Attract Pests

Remember, if your space gets infested by bugs or rodents, there might be a point where you will have to shut down. And the cost of shut down might be catastrophic to your future goals. And it won't end here. You'll have to face legal implications that will further damage the reputation of your business.

So, you must consult the experts and take care of all the measures to keep your business in the "running mode" always. Does it sound like a better idea? If yes, share your thoughts.

How to Get the Best Value When Buying Cardboard Boxes

Cardboard boxes have become an indispensable part of daily life, whether for moving houses, shipping products or simply for storage purposes. The key to making the most out of these versatile contai...

Daily Bulletin - avatar Daily Bulletin

BYD Expands in Australia: Introducing Chinese Dealerships and Pioneering Innovative Operations

Recently, BYD has been generating significant buzz with the launch of its two new stores in Melbourne and Sydney, revealing some exciting developments. Notably, BYD’s Chairman, Wang Chuanfu, graced ...

Daily Bulletin - avatar Daily Bulletin

Deciphering the Intricacies of Scrap Copper Prices in Melbourne: A Comprehensive Analysis

Introduction In the bustling metropolis of Melbourne, where innovation meets industry, the scrap copper market forms an integral part of the city's economic landscape. From the scrapyards scattered...

Daily Bulletin - avatar Daily Bulletin

Empowering Your Brand: The Integral Role of User-Generated Content in Social Media Marketing

In the ever-evolving landscape of digital marketing, brands constantly seek innovative strategies to connect authentically with their audience. Among these strategies, User-Generated Content (UGC) h...

Daily Bulletin - avatar Daily Bulletin

DIY Panel Beating Tips for Car Enthusiasts: A Beginner’s Guide

Welcome to the world of car maintenance and repair, where enthusiasts and DIYers converge to breathe new life into their beloved vehicles. Today, we’re diving into an essential skill for anyone look...

Daily Bulletin - avatar Daily Bulletin

The Perfect Extension: A 7 Point Checklist for Your Domain Name

The perfect domain name is imperative to your online success. It may not seem like much, but your extension is the first impression customers experience when they come across your brand. And in th...

Daily Bulletin - avatar Daily Bulletin

Tomorrow Business Growth