CISA Adds Four Known Exploited Vulnerabilities to Catalog

This article is contributed. See the original author and article here.

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise.

CVE ID Vulnerability Name Due Date
CVE-2022-24682 Zimbra Webmail Cross-Site Scripting Vulnerability 3/11/2022
CVE-2017-8570 Microsoft Office Remote Code Execution 8/25/2022
CVE-2017-0222 Microsoft Internet Explorer Remote Code Execution 8/25/2022
CVE-2014-6352 Microsoft Windows Code Injection Vulnerability 8/25/2022

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known CVEs that carry significant risk to the federal enterprise. BOD 22-01 requires FCEB agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.

Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the Catalog that meet the meet the specified criteria.

New Modern Work for Gov Series: Teams Real Talk

New Modern Work for Gov Series: Teams Real Talk

This article is contributed. See the original author and article here.

Untitled design (3).png


 


How does using Microsoft Teams everyday make you feel? Does it improve your work? Impede it? Whether you are using Teams simply for 1:1 chat or for all your various collaboration throughout the day, we want to hear from you, the good, bad, and ugly.

Join us for an open-ended one hour session, where Federal Customer Success Managers, Abby and Kyren, will create a space to gain a better understanding of where the pain points are in our technology, as well as uncover opportunities to connect Federal organizations to the right resources. There will be no recording. Consider this your first relationship management session for Teams! You can register at : aka.ms/ModernWork4Gov


 

Mozilla Releases Security Update for Mozilla VPN

Mozilla Releases Security Update for Mozilla VPN

This article is contributed. See the original author and article here.

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

SSL

Secure .gov websites use HTTPS

A lock (lock icon) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
From hiding your meeting video to Yammer community suggestions—here’s what’s new in Microsoft 365

From hiding your meeting video to Yammer community suggestions—here’s what’s new in Microsoft 365

This article is contributed. See the original author and article here.

This month, we’re bringing new capabilities to Microsoft Teams to help people focus on their presentation and stay on top of required trainings, provision Windows 365 Cloud PCs more easily, and more.

The post From hiding your meeting video to Yammer community suggestions—here’s what’s new in Microsoft 365 appeared first on Microsoft 365 Blog.

Brought to you by Dr. Ware, Microsoft Office 365 Silver Partner, Charleston SC.

SQL Server 2022: Introducing Buffer Pool Parallel Scan (Ep.5) | Data Exposed

This article is contributed. See the original author and article here.

In this episode of Data Exposed with David Pless and Anna Hoffman, we will discuss the new SQL Server 2022 Buffer Pool Parallel Scan improvement. Buffer Pool parallel scan improves the performance of scan operations on large-memory machines by utilizing multiple CPU cores. Customers running SQL Server on large-memory machines will witness faster executions scenarios which were historically slower due to the serialized buffer pool scan. The parallel scan feature also improves the buffer pool scan performance of small databases residing on large-memory machines. Additionally, this improvement adds buffer pool scan diagnostics and telemetry for supportability.


 


Watch on Data Exposed


 


Resources:



 


View/share our latest episodes on Microsoft Docs and YouTube!