Uncategorized

Log4Shell – Log4J CVE-2021-44228 Vulnerability

NB: Updated constantly Here is a summary of what Microsoft had of information https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/ * Over a period of the last 4 months, the library has been downloaded 28.6 million. * Ingenuity, the Mars 2020 Helicopter mission, is powered by it. * On Friday alone there were about 840,000 endpoints that were running a vulnerable instance based

Log4Shell – Log4J CVE-2021-44228 Vulnerability Read More »

Vulnerability CVE-2021-42306 CredManifest in Azure Automation and how to fix it

For customers that are using Azure Automation in many cases have been using it to build runbooks to automate against Azure environments (using a built-in AzureRunAsAccount) which is automatically created using the Azure Portal wizard. This creates a service principal in Azure Active Directory and gets by default contributor access to the environment. This configuration,

Vulnerability CVE-2021-42306 CredManifest in Azure Automation and how to fix it Read More »

Azure VM Guest Agent

Many might remember the day that Windows Servers stood still in Microsoft Azure because Microsoft made a change to the backend artifact repository for the Microsoft Azure agent. Now many are not that familiar with what that agent does and how it integrates into the Azure Fabric Controller, so I decided to do a little

Azure VM Guest Agent Read More »

Scroll to Top