Joint CISA FBI MS-ISAC Guide on Responding to DDoS Attacks and DDoS Guidance for Federal Agencies

This article is contributed. See the original author and article here.

CISA, the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have released Understanding and Responding to Distributed Denial-of-Service Attacks to provide organizations proactive steps to reduce the likelihood and impact of distributed denial-of-service (DDoS) attacks. The guidance is for both network defenders and leaders to help them understand and respond to DDoS attacks, which can cost an organization time, money, and reputational damage.

Concurrently, CISA has released Capacity Enhancement Guide (CEG): Additional DDoS Guidance for Federal Agencies, which provides federal civilian executive branch (FCEB) agencies additional DDoS guidance, including recommended FCEB contract vehicles and services that provide DDoS protection and mitigations. 

CISA encourages all network defenders and leaders to review:

VMware Releases Security Updates

This article is contributed. See the original author and article here.

VMware has released security updates to address multiple vulnerabilities in VMware Cloud Foundation. A remote attacker could exploit one of these vulnerabilities to take control of an affected system.

CISA encourages users and administrators to review VMware Security Advisory VMSA-2022-002 and apply the necessary updates and workarounds.

Bring agility, connectivity, and sustainability to the forefront—at Supply Chain Reimagined

Bring agility, connectivity, and sustainability to the forefront—at Supply Chain Reimagined

This article is contributed. See the original author and article here.

Today, many companies face global supply chain challenges. From unexpected demand to ever-increasing fulfillment expectations, the stakes have never been higher. In response, some are looking for new strategies and solutions to help them quickly predict and overcome disruptionsto keep goods moving and their businesses profitable.

Create resilient supply chains with innovative new offerings

Join Chris Capossela and Panos Panay, Chief Marketing Officer and Chief Product Officer at Microsoft, for the Supply Chain Reimagined digital event on November 16, 2022, to explore how to bring visibility, agility, connectivity, and sustainability to your supply chain.

You’ll learn about product innovations, essential insights, and the latest trends shaping supply chains, today and tomorrow. We’ll also take on topics like end-to-end visibility and data connectivity. You’ll leave with a better understanding of how technology is being used to improve both the customer experience and the bottom line. 

And you’ll discover real-world best practices for supply chain resilience from thought leaders, industry experts, and Microsoft customers and partners. Plus, you’ll get valuable lessons learned from Microsoft supply chain leaders across our Xbox, devices, and global Azure datacenter teams as they share the inside story of our own supply chain transformation.

Don’t miss this opportunity to engage in energizing conversations with leading experts about how to overcome today’s supply chain challenges.

Register for the Supply Chain Reimagined digital event today.

Learn how to create a connected, agile supply chain from your existing systems

Many of today’s leading supply chain systems are siloed solutions that don’t talk to each other. Because of that, some can’t handle the complexity of supply chain ecosystems that span providers, manufacturers, distributors, third-party and fourth-party logistics, delivery carriers, and consumerswhich leads to inefficient, reactive supply chain operations.

This digital event is a great opportunity for you to explore an effective solution to traditional supply chain issues. You’ll learn about a composable approach to supply chain transformation, which brings together various best-of-breed solutions on a common platform. You’ll see how to use this modular approach to enhance your existing systemsto deliver faster solutions to urgent problems and help your business become more resilient.

At Microsoft, we believe that a modular approach is key to supply chain resilience. That’s why we’re committed to providing solutions that work with your existing application landscapeto add extensible, scalable, and intelligent technologies that immediately improve supply chain practices, workflow, and value. This boosts agility by giving your teams the ability to quickly rearrange and reorient as needed depending on internal or external factors, like a sudden change in materials or a shift in customer priorities.

Moving from a siloed data infrastructure to a unified data platform is another key to supply chain resilience that highlights the benefits of an open, composable solution. Data is at the heart of supply chain operations and having a system that connects data across disparate systems is a critical advantage. You’ll gain end-to-end visibility across inventory systems, supplier schedules, and inbound and outbound orders, and you’ll empower your workforce to move from reactive to proactive, data-driven decision making throughout all areas of your supply chain.

Getting these essential insights is the first step toward building a connected, agile supply chain for your business. And it’s just one aspect of this information-packed digital event. We hope you’ll join us.

Bring sustainability into focus for your organization

Sustainability is a growing imperative for business as customers, regulators, investors, and employees are all asking organizations to do more to reduce their environmental impact. The pressure for measurable change is on supply chain leaders, as their systems often have the largest environmental impacts due to emissions or resource consumption.

At this digital event, you’ll find out how to build sustainable value chains on a secure, connected platform. You’ll learn from leaders in supply chain transformation how to reframe your strategy around sustainability and gain insights into practices that will empower you to deliver sustainability by design.

You’ll also gain insight into how Microsoft leaders have prioritized sustainability in our own supply chain practices, including building circularity into our design and striving to improve the impact across environmental, social, and governance factors.

Strengthen business resiliencenow and in the future

Finally, at the Supply Chain Reimagined digital event on November 16, 2022, you’ll also get an exclusive look at the future of supply chain transformation and the new solutions that can take you there. In addition to learning how to create an agile, connected, and sustainable supply chain, you’ll:  

  • Get key insights you can act on from thought leaders on topics like customer satisfaction, business agility, and operational efficiency.
  • See what’s shaping supply chain innovation today and tomorrow with real-world best practices and lessons learned from Microsoft and industry leaders.
  • Learn how our customers, including Mitch Arends from the Kraft Heinz Company, are partnering with Microsoft to improve supply chain resilience. 
  • Hear exciting announcements and be among the first to see new product innovations unveiledall designed to help protect your business from supply chain challenges.
  • Ask Microsoft supply chain experts all your most pressing questions in a live Q&A chat.  

Join us on Wednesday, November 16, 2022, from 9:00 AM to 10:15 AM Pacific Time (UTC-8).

Colorful shipping containers outside.

Supply Chain Reimagined

Start reimagining your supply chain for a more agile, resilient future.

The post Bring agility, connectivity, and sustainability to the forefront—at Supply Chain Reimagined appeared first on Microsoft Dynamics 365 Blog.

Brought to you by Dr. Ware, Microsoft Office 365 Silver Partner, Charleston SC.

CISA Releases Four Industrial Control Systems Advisories

This article is contributed. See the original author and article here.

CISA has released four (4) Industrial Control Systems (ICS) advisories on October 27, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.

CISA encourages users and administrators to review the newly released ICS advisory for technical details and mitigations:

•    ICSA-22-300-01 Rockwell Automation FactoryTalk Alarm and Events Server
•    ICSA-22-300-02 SAUTER Controls moduWeb
•    ICSA-22-300-03 Rockwell Automation Stratix Devices Containing Cisco IOS
•    ICSA-22-300-04 Trihedral VTScada

Crayon: Strengthening a global company during the pandemic with a shared culture of learning

Crayon: Strengthening a global company during the pandemic with a shared culture of learning

This article is contributed. See the original author and article here.

Key takeaways:



  • As some companies pulled back in the early days of the COVID-19 pandemic, Crayon doubled down broadly on training—including resources from Microsoft Learn—and is now in position to better serve its IT customers as organizations resume business at higher levels.

  • Access to Microsoft Learn resources and the expectation of earning certifications help the company maintain minimal employee turnover.

  • Crayon management says access to training and certification helps fulfill its commitment to addressing social concerns, including gender, culture, neurodiversity, equity, and inclusion.


 


Norway’s Crayon confronted the challenge of the COVID-19 era by doubling down on training and certification for its employees. Like many organizations, the global IT consultancy had to find ways for its teams to be productive while working remotely. Unlike others, though, Crayon saw distributed working as an opportunity to position the company for a return to normalcy. The company’s leadership projected that its corporate IT customers would have greater needs as the transition to the cloud accelerated. Crayon anticipated those needs by preparing employees with the Microsoft training and certifications required to support their customers’ ambitions.


 


Bente Liberg Quote Card.PNG


 


 


Microsoft Learn resources naturally aligned with Crayon’s commitment to training, which is broad and long-standing. “We started out with having focus on certification and training from day one,” recalls Crayon Chief Operating Officer (COO) Bente Liberg, who joined the 3,300-person company 20 years ago as its sixth employee. She cites the strategic importance of training—internally and externally. “Our strategy has always been to help customers implement. We train them so that they can use the things they buy from us, and our commitment to training starts with how we educate our own people.”


 


Because Crayon both provides services and creates solutions that it sells to customers, the company has a need for its employees to step out of the revenue stream and invest in learning. Bente notes, “It starts with our GMs—actually, all of our country managers have a development KPI for the company. And for them to be able to deliver on that KPI, they need to develop skill sets in the company.”


 


This is true at the line level, too, and for recruitment. “That was actually something positive for hiring and also for retention,” Bente continues. “We heard from candidates: ‘Oh, can I [do] training?’ Yes, not only you can do training, you have to do training. ‘Can I take [a] certification?’ Yes. You have to take certifications.”


 


Crayon Chief Executive Officer (CEO) Melissa Mulholland made training and Microsoft Certification available broadly across the company—and not just for consultants. In the company’s India team, for example, “We actually had everybody, including finance—everybody—go and pass [Exam] AZ-900, the [Azure] fundamentals exam, because if they have a better understanding, that will make them better at their job.” Beyond fundamentals, more than one-third of the company’s 8,000 certifications cover in-depth topics, she reports.


 


Allen Deniega Quote Card .PNG


 


 


From the perspective of a potential recruit or a new employee, this focus on training and certification is a professional opportunity. Senior Power BI Developer Allen Deniega recalls what drew him to the company earlier this year, noting that he has already completed two certifications since he joined Crayon. “The whole culture of helping others and promoting professional development—those two really made me come to Crayon,” he recalls. He started investigating training opportunities on his second day and made particular use of the Microsoft Official Practice Tests, often taking the same one multiple times. “Apart from giving you an idea of the structure and the format of the exam and the actual feel of the exam, it allows you to identify your gaps every time.”


 


Melissa believes that the learning culture not only makes Crayon more competitive and better able to differentiate its depth of knowledge to customers, but it also helps reduce turnover as employees see their career paths clearly. “It directly corresponds with talent retention, and we have very high retention in our organization. Globally speaking, from an annual standpoint, [turnover is] less than 10 percent, and I really believe that’s driven by this culture of learning and development.”


 


Melissa Mulholland Quote Card.PNG


 


 


She also believes that training and certification are key to helping the company fulfill its social commitments. In 2021, Crayon created its first environmental, social, and governance (ESG) report.[1] For Crayon, Melissa explains, “Certifications [are] an excellent way to bring in more diverse skill sets and, for example, giving women who want to be in technical roles the ability to.” She says certifications provide a pathway for individuals who may not have had access to professional opportunities because of gender, culture, color, or neurodiversity. Through the training program, in partnership with Microsoft, she says, “If you have the passion and will, and you have the demonstrated certifications behind that, I’m willing to give people chances to prove themselves in roles, and I think that’s an important mindset that we have in the company that very much aligns to our ESG focus.”


 


Microsoft and Microsoft Learn have been steady partners for Crayon in these achievements, Melissa points out. “I am so grateful for Microsoft, I think really having our back, at being able to guide us,” she says. “You experience growth when you push yourself to learn and adapt, and it’ll open up not only career opportunities, but it’ll also give you more information to be able to do your job better. Never get in the ‘comfort zone.’”


 


[1] An ESG report focuses on an organization’s environmental, social, and governance impacts and priorities. The United Nations has published a comprehensive set of these sorts of priorities, called Sustainable Development Goals (SDGs), which many organizations use to guide their own ESG goals and reporting.

New sales sequences experience improves seller productivity

New sales sequences experience improves seller productivity

This article is contributed. See the original author and article here.

The Microsoft Dynamics 365 sales accelerator helps sellers sell smartly by building a strong and prioritized pipeline, offering context, and suggesting next actions through sales sequences that expedite the sales process. We’ve made three improvements to sales accelerator that can help sellers be even more productive:

  • Sellers can now build their own sales sequences
  • We’ve made the sequence designer even easier to use
  • Sellers can add the Up next widget to any form

Let’s examine each of these improvements in more detail.

Empowering sellers to build their own sales sequences

Before now, sales managers enforced best practices by defining a set of consecutive activities for their sellers to follow throughout their workday. Managers could connect these sequences to leads and opportunities that appeared in the sellers’ work queue. Sales sequences helped sellers prioritize their activities and focus on selling to be more productive and to better align to business processes.

Now, we’re empowering sellers to build their own sequences. Often sellers are in a better position to decide the best engagement strategy to follow with a prospect. Now they can create sequences for themselves and connect them to records. They can also personalize a sequence with their own language and steps.

The following screenshot shows the new functionality in the Personal settings > Sequences page in the Sales Hub app:

graphical user interface, text, application, email

Use security roles to manage permissions to create, connect, and share sales sequences.

Improved design experience for sales sequences

As we give sellers the power to create sales sequences, we need to make sure it’s easy to do. That’s why we created a new sequence designer with a modern UX and an enhanced editing experience. Sellers will realize several immediate benefits:

  • Consistency between the marketing journey and sales sequences means sellers don’t have to learn two different systems.
  • A side panel makes editing easier and scalable with more space.
  • Changes are automatically preserved in the browser and can be saved with a single click.
  • The updated top command bar shows relevant options, leaving more space for editing.
  • An exit icon effortlessly identifies the end of any sequence branch.
  • Enhanced error handling enables easy identification and resolution of any errors.

graphical user interface, application

Add the Up next widget to any form

Sales organizations may have hundreds or even thousands of records their sales teams are working on. As they start using sales sequences, they typically create a few to try out and use them to determine the best way to grow and scale based on business needs. The trouble with that is that then the organizations have a few records that are connected to sequences and a multitude of records that aren’t. For sellers, this means that only the few connected records appear in the Up next widget in their worklist, because the Up next widget is fed by sequences. They have to juggle the worklist and their leads, opportunities, and other entities tables, where their non-sequenced records live.

To solve this challenge, we now allow sellers to add the Up next widget to any form. Previously, the Up next widget and sales sequences were available only in the sales accelerator workspace.

To help new users easily discover the benefits of the sales accelerator, we’ve started adding the Up next widget to the default lead, opportunity, contact, and account forms. Sellers can easily start using the sales accelerator to create sequences, streamline customer interactions, and win more deals.

graphical user interface, application

Learn more

New to Dynamics 365 sales accelerator? Watch the overview video and read the documentation: Configure the sales accelerator | Microsoft Learn

Read how to add the Up next widget to any form: Add the Up next widget to a custom form | Microsoft Learn

Read how to allow any security role to create or connect sequences: Sequences in sales accelerator | Microsoft Learn 

Read the seller guide to creating sequences: Create and connect sequences for yourself | Microsoft Learn 

The post New sales sequences experience improves seller productivity appeared first on Microsoft Dynamics 365 Blog.

Brought to you by Dr. Ware, Microsoft Office 365 Silver Partner, Charleston SC.

Azure CNI Powered by Cilium for Azure Kubernetes Engine (AKS)

Azure CNI Powered by Cilium for Azure Kubernetes Engine (AKS)

This article is contributed. See the original author and article here.

Production deployments of Kubernetes continue to soar as customers increasingly containerize their applications. With the growth in application modernization customers are looking to rapidly scale their Kubernetes deployments by building very large clusters or adopting a multi-cluster strategy. They expect instantaneous connectivity when spinning up and scaling out application instances. Specialized applications, such as gaming apps, expect superior data path throughput for rich application experience. The increased east-west traffic flows necessitate fine-grained monitoring and tracing for troubleshooting. Network Security is another important aspect as customers wish to implement common L4 and L7 security controls for their cloud-native applications and need solutions that are more tailored for Kubernetes and containers.    


 


These requirements call for a robust platform that scales seamlessly to provide networking for millions of containers, a rich set of security controls and hooks into rich traffic metrics and logs for network visibility, without compromising on the performance.  


 


Azure Container Network Interface (CNI) Powered by Cilium is the next-generation networking platform that meets all these requirements by combining two powerful technologies, viz. Azure CNI that provides a scalable and flexible Pod networking control plane integrated with the Azure Virtual Network stack and Cilium open-source project, a pioneer in providing eBPF-powered data plane for networking, security, and observability in Kubernetes.  


 


We are proud to announce the availability of Azure CNI Powered by Cilium natively in Azure Kubernetes Service to provide scalable and high-performance Pod networking and Kubernetes Network Policies. 


 


About Cilium eBPF 


eBPF is a revolutionary technology that allows the insertion of sandboxed programs into the Linux kernel to greatly enhance the traffic processing capabilities in the operating system runtime. eBPF programs today enable a rich set of networking, security, observability, and application tracing use cases at very high performance. 


 


Cilium offers the next generation dataplane for Kubernetes that builds on top of eBPF technology to address these use cases for cloud native workloads. Cilium provides rich functionalities such as high-performance data path for Kubernetes services, efficient load-balancing, extensive network security features and rich monitoring. Besides the traditional Kubernetes network-level security Cilium also enables security based on application protocol context, DNS FQDNs, and service identity.


 


About Azure CNI 


Azure CNI provides network provisioning for Kubernetes Pods in AKS. It functions in one of the following two modes which is configured at the time of AKS cluster creation. 


 


VNET Mode: In VNET mode Azure CNI assigns IPs to Pods from a Vnet subnet making Pods first-class citizens in a Vnet. Pods have direct connectivity to each other and to other resources in the VNET and on-premises. You can choose to dynamically assign IP addresses to Pods from a separate Pod subnet that is different from the cluster subnet. This provides better utilization of VNET IP space, and the ability to configure separate Vnet policies for Pods  


 


Overlay Mode: In Overlay mode only the cluster nodes are deployed into a VNET whereas Pods are assigned IP addresses from a private address space that is logically different from the VNET hosting the nodes. This mode significantly reduces the amount of Vnet IP addresses consumed by AKS clusters allowing limitless cluster scale. The Pod address space can be re-used on multiple clusters in the same VNET, greatly simplifying IP address planning. Overlay addressing does not require provisioning of custom routes or usage of encapsulation for Pod-Pod connectivity offering data path performance at par with connectivity between VMs in a VNET.


 


What does Azure CNI Powered by Cilium provide?


Azure CNI powered by Cilium integrates the scalable and flexible Azure IPAM control plane with the robust dataplane offered by Cilium OSS to create a modern container networking stack that meets the demands of cloud native workloads. 


 


Azure CNI Powered by CiliumAzure CNI Powered by Cilium


 


Azure CNI Powered by Cilium offers the following benefits today and provides the ideal platform for future innovations. 


 


Scalable and performant Networking 


The Cilium powered CNI supports both Vnet and Overlay modes. The socket-based load-balancing for Kubernetes services in Cilium replaces the inefficient load-balancing based on IPTable rules in KubeProxy to provide superior data path performance at par with direct connectivity to service backend Pod. The performance is deterministic irrespective of the number of services deployed in the cluster. 


 


Kubernetes Network


The Cilium powered CNI comes with built-in support for the basic Kubernetes Network Policies. There is no need to install a separate solution on top. The solution offers significant improvement in scale and performance by eliminating usage of IPTables for network filtering.


 


Using Azure CNI powered by Cilium


Azure CNI powered by Cilium is currently in preview in AKS. For detailed usage instructions refer to – https://aka.ms/aks/cillium-dataplane.


 

Apple Releases Security Updates for Multiple Products 

Apple Releases Security Updates for Multiple Products 

This article is contributed. See the original author and article here.

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

SSL

Secure .gov websites use HTTPS

A lock (lock icon) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Samba Releases Security Updates 

This article is contributed. See the original author and article here.

The Samba Team has released security updates to address vulnerabilities in multiple versions of Samba. A remote attacker could exploit one of these vulnerabilities to take control of an affected system. 

CISA encourages users and administrators to review the following Samba Security Announcements and apply the necessary updates and workarounds. 

•    CVE-2022-3437  
•    CVE-2022-3592