Broadcom Begins Auditing Organizations Using VMware!
Earlier this year, Broadcom began sending cease-and-desist letters to organizations using VMware products. These letters instructed recipients to stop using any VMware updates or enhancements, such as maintenance releases, minor and major upgrades, patches, bug fixes, or security updates, issued after their support contract expired. The only exception is critical zero-day security patches.
The letters also warned of potential audits, which now appear to be in progress. Below is an example of a letter sent to a customer in the Netherlands.
According to the letter, the audit will be conducted by Connor Consulting, a global firm headquartered in San Francisco. The review will assess the organization's VMware deployment and entitlements. It may involve on-site visits, remote testing, and meetings with staff from accounting, licensing, and IT departments. Recipients are expected to respond to Connor Consulting within three business days.
The letter is signed by Aiden Fitzgerald, Director of Global Sales Operations at Broadcom, who states the audit process will be handled "as efficiently and productively as possible to minimize disruption to your daily business operations."
If your organization uses VMware, ensure you're compliant with the licensing terms. Otherwise, you risk paying a hefty penalty!
#Broadcom #VMware #Audit #Compliance #SoftwareLicensing
Okay so this is HUGE - our amazing AI red team have open sourced their AI red team labs so you can set up your own training!
https://t.co/brvdq6roHp
@ram_ssk
Active Directory Hardening Series
Part 1 Disabling NTLMv1 https://t.co/9gla1vtQ18
Part 2 Removing SMBv1 https://t.co/KOqpamarcW
Part 3 Enforcing LDAP Signing https://t.co/oW2Ymvu1ZW
Part 4 Enforcing AES for Kerberos https://t.co/iENjEPBOFD
STOP users from joining computers to the domain!
By default, standard users can join a computer to the domain. Once they do that, they will automatically become the owner of the computer.
This gives them the ability to take control of the computer and make themselves a local administrator in just a few simple steps.
That's a security risk you don't want.
Also, many admins use their domain administrator account to join a computer to the domain. While this is the easiest to do because it has all the permissions, it's not advisable.
The recommendation is to create a new service account with limited permissions and use it to join a computer to a domain.
Learn more:
https://t.co/tb03NaSArq
#Microsoft #ActiveDirectory #Cybersecurity
[𝗧𝗼𝗼𝗹] 🛠️ - AD Miner
AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses.
Repo - 🔗 https://t.co/udIYgkgqU2
#CyberSecurity#ActiveDirectory
One of our very smart Active Directory experts has been putting together a series of blog posts about hardening AD. Already into its 7th installment, it covers SMB hardening, disabling NTLMv1, least privilege and more. Check the series out - https://t.co/KkKfarAX9a