From CVS to Chevron, FDA decision triggers vaccine mandates

PAUL WISEMAN and JOSEPH PISANI
Tue, August 24, 2021, 1:10 PM

From Walt Disney World and Chevron to CVS and a Michigan university, a flurry of private and public employers are requiring workers to get vaccinated against COVID-19 after the federal government gave full approval to the Pfizer shot. And the number is certain to grow much higher

Food for thought/opinion if all firms require employees be vaccinated or find a new job..then have your employer re-write there contract with you if you get sick..they pay for all medical expenses with no out of pocket expenses and they continue to pay you your full salary

Associated Press writers Carla K. Johnson, Anne D’Innocenzio, Tom Krisher and Ricardo Alonso-Zaldivar contributed to this story.

Opinion

Bitdefender Requirement Important

Please read your Security Alerts:

Deployments have reached Customer’s maximum license limit:

Notification Details:

The Customer company XYZ FD has reached the maximum number of endpoints protected by the license key (Company Key).
To protect more endpoints for this company, you should extend its service subscription or add more licenses.
Otherwise your endpoints will not be protected and are subject to malware

Windows Privilege Escalation Vuln Puts Admin Passwords At Risk

July 21 2021

Microsoft has issued a temporary workaround for systems vulnerable to CVE-2021-36934, also known as “HiveNightmare” and “SeriousSAM.”

Microsoft has issued a temporary workaround for a privilege escalation vulnerability that could expose administrator passwords to non-admin users.

CVE-2021-36934, also called “HiveNightmare” and “SeriousSAM,” appears to have been first detected by security researcher Jonas Lykkegaard, Forbes reports. Lykkegaard noticed the Security Account Manager (SAM) file had become read-enabled for all users, meaning an attacker with non-admin privileges could access hashed passwords and elevate privileges.

Lykkegaard and other security researchers found the issue affected the Windows 11 preview as well as Windows 10. Microsoft has confirmed the problem affects Windows 10 version 1809 and newer operating systems and has provided workarounds for systems affected by the flaw.

“An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database,” the company wrote in its CVE.

An attacker who successfully exploited the flaw could run arbitrary code with system privileges and then install programs; view, change, or delete data; or create new accounts with full user rights. They also have the ability to execute code on a target system to exploit the bug. So far Microsoft has not detected exploits in the wild, though it notes exploitation is “more likely.”

Microsoft has stated it will update the CVE as its investigation continues.
Article: Dark Reading

Windows Print Spooler Remote Code Execution Vulnerability

MspPortal Reported the issue on 7-7-2021

For PrintNightmare we currently have the following detections live:
Exploit.RPRN.CVE-2021-1675.PrintNightmare — from our NAD module (I know the CVE in the name differs, but it still detects the attack)
Alert.RPRN.AddPrinterDriver — from our EDR module
We are also working on detection from our behavioral engine. However, that will take a bit more time as it requires extensive testing but will be available soon.

 

Solution 7-12 Bitdefender Solved the issue

Bitdefender technologies will now protect against this vulnerability. 

Little about MspPortal Partners and Bitdefender relationship

1) We do 1,2,3 line tech support for Bitdefender Gravity Zone we average 60 tech cases a week just on 1 and 2nd level support we typically solve our case load within 15-30 minutes
2) We do the hands on Training (1 hour) no power point live. When we are done you can start selling that day. We write a default policy that will keep you out of trouble and avoid Crypto. We also do a lot of Bitdefender’s beta work. Helps us to be better service to you
3) We do the licenses (reality we just keep your bucket full so it’s nothing more than adding more licenses when needed (just send an email to us) You only pay for what you use/install
4) Last we do the invoicing 2nd of the month we make sure you receive a report of the breakdown for your billing on the first. for the prior month (arrears)
5) The reality is even though we are a distributor we are really a VAD value add we work for a living 😉
6) Techs since 1994 when Roy Miehe started this firm

We will be glad to answer any questions you may have and also share some best practices with you.

Bitdefender has a great program with solutions specifically tailored for MSPs..

Bitdefender Email Alerts on Gravity Zone Important

Folks if you are not receiving Bitdefender Alerts

Please send an email to goldsupport@bitdefender.com

Subject Line: Not receiving Bitdefender Mail Alerts Important You should receive a response with a case number

** Importance to this is alerting you folks as to Incidents occurring in Gravity Zone -> whatever you have chosen to receive alerts on**

I have already made Development aware of this issue

Rackspace Email Changes Important

On June 8th Rackspace Email will start making changes to the retention rules for the spam and trash folders. The maximum data retention limits of the spam and trash folders will change to 14 and 30 days respectively. This means that any mail data in these folders older than the retention limits will be removed and unrecoverable. Since an unlimited number of messages can now be stored in either of the spam or trash folders, the option to “Delete After ‘x’ Total Email” will be removed.

Prior to June 8th, you should review your spam and trash folder cleanup settings. If they are higher than the new limits (spam: 14 days, trash: 30 days) then the mailbox owner will need to review the mail in those folders and move anything worth keeping into another folder. You can view the spam and trash limits for each mailbox by logging into https://cp.rackspace.com and navigating to mailboxes > manage > settings.

Please inform your customers of these upcoming mail retention changes by May 4th. We look forward to the benefits these changes will bring to both the Rackspace Email platform and your organization’s mailboxes.

Sincerely,

The Rackspace Email Team

Barracuda RMM 12 SP3 HF1 and Barracuda RMM ServiceNow Service Desk

Dear MspPortal Partners,

Barracuda RMM 12 SP3 HF1 and the Barracuda RMM ServiceNow Service Desk is now available. The Barracuda RMM 12 SP3 HF1 release includes performance enhancements for alert handling, the file size for automation scripts and packages has been increased to 25 MB, and the OSX Site Prep Utility now supports macOS versions Catalina and Big Sur. For more information, please read the release notes:

The Barracuda RMM ServiceNow Service Desk offers robust bi-directional integration with ServiceNow, enabling MSPs who use the ServiceNow event management system to use Barracuda RMM with no adjustments to accommodate. For more information, please read the release notes.

If you have any questions, please do not hesitate to contact tech@mspportal.net.

Regards,

The Barracuda MSP team