Preparing for inclement weather

CTC NEWS
Due to the anticipated arrival of inclement weather from Hurricane Helene, the state of Georgia is under a State of Emergency. No closures or scheduling changes are planned at this time but we will be monitoring power, weather and road conditions as the storm moves through the area and updating plans as needed to ensure the health and safety of our team. If there are any schedule changes or closures, we will post updates to our website here and to our social media (Facebook and X).
Read More

September 2024 News and Updates

CTC NEWS, Industry News, Monthly Newsletters, Tech news
Apple / Mac Security Updates - In addition to the usual suspects, significant security updates have been released by Apple for multiple products including iOS / iPadOS 17.7, iOS / iPadOS 18, MacOS 13.7, 14.7 and 15, tvOS 18, watchOS 11, visionOS 2 and more. Additional info is available from CISA here. Basically, if you've got an Apple device, update it :) Microsoft Recall - The short version is that Microsoft Recall is apparently not as dead as we thought (hoped) that it was and I've not seen anyone state this better than Brian Krebs here. "...But last week, the software giant clarified that what it really meant was that the ability to disable Recall was a bug/feature in the preview version of Copilot+ that will not be available to…
Read More

Closed 2 September 2024 for Labor Day

CTC NEWS
We will be closed on Monday, 2 September 2024 to enjoy the Labor Day holiday with friends, family and loved ones and will reopen during normal business hours on Tuesday, 3 September 2024.  Emergency support will be available for our commercial and MyIT clients.  If you need emergency support on Monday, simply include the word 'emergency' in the subject of your email to help@ctc.co or by noting it in your voicemail at 770.386.8900.
Read More

August 2024 News and Updates

CTC NEWS, Industry News, Monthly Newsletters
Labor Day - Cyber Tech Cafe will be closed on Monday, 2 September 2024 in observance of Labor Day. CrowdStrike - I've had a lot of conversations with folks on this and believe that, in addition to the takeaways in the original post, there are three things that could have been done different. First, test the changes before you deploy it. In the case of the CrowdStrike incident, that likely would have saved the day. Second, fail gracefully. The bug caused an error at a very low level in Windows that prevented Windows from booting and required physical access to impacted systems to revive them. The fix was a very simple fix but it required physical access. Allowing the application to fail gracefully so that the systems was able to…
Read More

Announcement – Project Lazarus

CTC NEWS
I alluded to it in my After Action Report for the CrowdStrike incident but one of the takeaways was that the fix was a relatively simple one but many administrators and support personnel were left without the ability to connect to the impacted computers. As a small MSP, this resonated with our team since a large scale event requiring a manual fix, like the CrowdStrike failure, impacting multiple client sites at once would be difficult for us to address quickly. It's still very much in the early stages but I'm excited to announce what we're calling Project Lazarus. Project Lazarus is a bootable USB drive that, as long as the hardware is still functional, will allow customers to boot the machine, connect to to the Internet and get our team…
Read More
After Action Report – CrowdStrike

After Action Report – CrowdStrike

Industry News, Tech news
As many of you know, an issue with an update to CrowdStrike, a security platform installed on literally millions (if not billions) of computers worldwide, caused a global IT Outage on Friday and many organizations (and IT workers) are still feeling the sting of that outage today. The root issue appears to have been a bad configuration update from CrowdStrike that prevented affected systems from booting. We are thankful that none of our clients were directly impacted but the incident provides an excellent opportunity to "sharpen the saw" and update our internal processes. In this email, I'd like to quickly summarize what happened, some key things that we took away from the incident and some changes that we're making in as a result. What happened? CrowdStrike released a corrupt configuration…
Read More

July 2024 News and Updates

CTC NEWS, Industry News, Monthly Newsletters, Tech news
Client Forms - In an effort to make requesting support easier for common tasks (onboarding and offboarding users, for example), we are launching a number of forms that clients can use to request support. Links to the forms are located at the top of our website under Client Forms. Windows Recall - We received a surprising amount of feedback on the blurb about Windows Recall in last months newsletter and, not surprisingly, literally none of it was positive. The common thread in all of the feedback was basically what are the alternatives? We don't really have a plan, just yet, but we do have some ideas. Expect more on this next month and, if you're concerned about Windows Recall for whatever reason (privacy, regulatory compliance, etc.), keep an eye out…
Read More

Please update your FortiGate

Industry News, Tech news
What is this about? In February of this year, Fortinet disclosed multiple vulnerabilities in the FortiOS firmware, the operating system for their entire line of products. The vulnerability was highly publicized by Fortinet, The U.S. Cybersecurity and Infrastructure Security Agency (CISA), news outlets, message boards and on social media and we reached out directly to all of our MyIT Clients. The vulnerability is significant because it's position in a network, often running on the Internet facing firewall protecting that network from Internet borne threats, means it's exploitable from anywhere on the Internet and successful exploitation could give an attacker full access to a vulnerable device. It's also important to note that state sponsored threat actors are known to favor (and target) these types of vulnerabilities. What do I need to…
Read More

We will be closed July 4th

CTC NEWS
Cyber Tech Cafe will be closed on Thursday, 4 July 2024 in observance of Independence Day to enjoy time with family, friends and loved ones. We will reopen on Friday, 5 July 2024 at 9:00am ET. We will have on-call support available for commercial and MyIT clients via the emergency support option on the phone or by adding 'emergency' to the subject line of support email. From all of us at Cyber Tech Cafe, we wish you a happy Fourth of July and are eternally grateful to the men and women who have fought to win and preserve our freedom.
Read More

CDK Breach – Threat actors now contacting CDK customers directly.

CTC NEWS, Tech news
We are working with a number of clients who have been impacted by what is, I believe, now officially being referred to publicly by CDK as an attack and, specifically, multiple attacks. This latest development (the threat actors are reaching out to CDK Customers directly) confirms that there was data, at the very least customer lists and contact info, taken during the attack. Details are sketchy and there are a lot of moving parts behind the scenes so this post will be a) short, b) in no particular order and c) vague but there are a number of common questions / concerns / comments that we're getting that I'm hoping to address with this post. For those who don't know who CDK is or why this may be important, CDK…
Read More