IT SPARC Cast

IT SPARC Cast is a digest of the Enterprise IT news over the last week, with insights, opinions, and a little sarcasm from 2 experts each with over 20 years of experience working in IT or for IT vendors.<br /><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>

Phobos Ransomware Arrest, Windows 365 Link Nerd Fight, and a Palo Alto CVE Warning

In Episode 14 of IT SPARC Cast, John and Lou delve into the latest enterprise IT news. Topics include the extradition of a ransomware mastermind, a heated debate over Microsoft’s new Windows 365 Link device, and an urgent security warning for Palo Alto firewalls. Tune in for insights, analysis, and a touch of humor from IT industry veterans.Show Notes:News Bytes:Phobos Ransomware Leader Extradited•Russian national Evgenii Ptitsyn extradited to the U.S. for leading a global ransomware operation using Phobos. Alleged to have extorted over $16 million, Ptitsyn faces multiple charges and potential decades in prison.•Discussion on ransomware’s impact on businesses and the importance of cybersecurity insurance and enforcement.•https://www.darkreading.com/cyberattacks-data-breaches/phobos-ransomware-cybercriminal-extradited-south-korea AI Deepfake Scandal Shuts Down Pennsylvania School•A student-created deepfake scandal at a private school in Pennsylvania sparks legal and parental outrage. Lou and John discuss the importance of clear policies to handle AI misuse in both schools and corporate settings.•https://news.slashdot.org/story/24/11/18/2122251/explicit-deepfake-scandal-shuts-down-pennsylvania-schoolNerd Fight:Microsoft Windows 365 Link Device – Innovation or Nostalgia?•John and Lou debate the value of Microsoft’s new $349 Windows 365 Link device. John argues it’s a game-changer for secure remote work, while Lou critiques it as a glorified “dumb terminal.”•They discuss its potential use cases in IT-controlled environments, from call centers to flexible remote work setups.•https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-link—the-first-cloud-pc-device-for-windows-365/4302687CVE of the Week:Palo Alto Zero-Day Exploits (CVE-2024-00012)•Critical vulnerabilities in Palo Alto firewalls allow attackers to bypass authentication and escalate privileges to root access. Lou provides practical tips for mitigating risks, including internal whitelisting and VPN use.•John highlights the need for zero-trust architecture to combat modern multi-vector attacks.•https://www.securityweek.com/palo-alto-patches-firewall-zero-day-exploited-in-operation-lunar-peek/Wrap Up:•John and Lou invite listeners to share opinions on the Windows 365 Link device and other topics via feedback@itsparccast.com or @ITSPARCCast on X.•Programming note: IT SPARC Cast will return on December 4th with a deep dive on IT support for remote work and more enterprise IT news on December 6th. Hosted on Acast. See acast.com/privacy for more information.

11-22
29:32

IT’s Role in Supporting Remote Workers: Communication, Tools, and Culture

In Episode 2 of this multi-part series, John and Lou dive deeper into IT’s role in supporting remote work. They discuss the critical elements of successful remote work environments, including clear communication infrastructure, robust digital tools, structured policies, and trust-based management. Explore how IT leaders can create a remote work culture that fosters productivity, collaboration, and employee satisfaction.Show Notes:Episode 1 Recap:•A quick review of Episode 1, focusing on why IT leaders must care about remote work and how enabling it supports talent acquisition, resilience, cost savings, and employee satisfaction.•Youtube - https://youtu.be/H02u0BASJsE•Podcast - https://shows.acast.com/it-sparc-cast/episodes/its-essential-role-in-enabling-remote-work-productivity-flexClear Communication Infrastructure:•Importance of synchronous and asynchronous communication tools (e.g., Zoom, Teams).•Encouraging video-on for meetings while respecting personal boundaries.•Regular team check-ins and 1:1s to mitigate disconnection and improve engagement.•AI tools for automated note-taking and action item tracking during meetings.Strong Digital Tools & Systems:•Evaluating project management platforms (e.g., Monday, Trello) for collaboration.•Addressing secure file sharing and time zone management challenges.•Innovations in video conferencing and telepresence setups for better engagement.Structured Remote Work Policies:•Setting clear expectations for availability, dress code, and meeting attendance.•Offering flexibility in status reporting formats (e.g., text, audio, or video).•Providing the right equipment and training while ensuring proper asset tracking.Cultural Elements:•Encouraging work-life balance and trust-based management styles.•Creating intentional social connection opportunities (e.g., virtual break rooms, watch parties).•Inclusive practices to prevent remote worker isolation and build stronger teams.Management Practices:•Emphasizing outcomes over hours worked.•Structured performance reviews and effective goal-setting.•Using written communication to document priorities and expectations.Wrap Up:•John and Lou invite feedback on tools, policies, and practices for supporting remote workers.•Connect via feedback@itsparccast.com or on X @ITSPARCCast.•Programming Note: New episodes will resume after Thanksgiving on December 4th and December 6th. Hosted on Acast. See acast.com/privacy for more information.

11-20
40:02

OpenAI Agents, Salesforce’s AI Expansion, and Android’s Critical Security Flaws

In this episode of IT SPARC Cast, John and Lou cover the latest in AI and cybersecurity. OpenAI prepares to launch locally-hosted AI agents, Salesforce ramps up its AI-powered products with new hires, and 19 critical vulnerabilities in Android demand immediate attention. Tune in for insights on how these developments impact enterprise IT and security.Show Notes:News Bytes:OpenAI to Launch Local AI Agents•OpenAI’s “Operator” project will bring AI agents to local devices, enabling automation of tasks across platforms. This advancement could revolutionize daily workflows by integrating data from multiple enterprise systems into a unified report.•Discussion on potential enterprise applications, from log analysis to anomaly detection, all within secure local environments.•https://www.theverge.com/2024/11/13/24295879/openai-agent-operator-autonomous-ai Salesforce’s AI Expansion with AgentForce•Salesforce announces plans to hire 1,000 people to support its new AI product, AgentForce, a platform for building intelligent agents for customer service and internal use.•This move reflects the growing demand for no-code AI tools and signals Salesforce’s commitment to AI-driven business solutions.•https://slashdot.org/story/24/11/10/1819213/salesforce-to-hire-1000-people-for-big-ai-product-sales-push •https://finance.yahoo.com/news/salesforce-hire-1-000-people-194931457.htmlMeet Wi-Fi 8: Reliability Over Speed•Early details about Wi-Fi 8 show a focus on stability rather than speed, addressing connection drops common in current high-speed protocols.•Discussion on the benefits for IoT devices and the challenges of implementing new standards across existing infrastructure.•https://www.pcworld.com/article/2518469/meet-wi-fi-8-which-will-trade-speed-for-a-more-reliable-experience.html CVE of the Week:19 Critical Android Vulnerabilities•Google’s latest Android update addresses 19 high-severity security holes, with two already actively exploited (CVE-2024-43047 and CVE-2024-43093).•These vulnerabilities affect a wide range of devices and could compromise Android’s sandbox environment. John and Lou emphasize the importance of prompt patching and secure device management for enterprises.•https://source.android.com/docs/security/bulletin/2024-11-01 Wrap Up:•John and Lou invite feedback on potential topics, especially regarding vendor earnings and their implications for the IT sector. Reach out at feedback@itsparccast.com or on X @ITSPARCCast.•Don’t forget to like, subscribe, and share to keep up with the latest in IT news. Hosted on Acast. See acast.com/privacy for more information.

11-15
30:50

IT’s Essential Role in Enabling Remote Work: Productivity, Flexibility, and the RTO Debate

In this first episode of a new series, John and Lou explore IT’s critical role in supporting remote work. They discuss why remote work matters, the benefits it brings to employees and businesses, and why a mandated return to the office (RTO) may not be the best path forward. Get insights into how IT can help sustain productivity and enhance job satisfaction in a remote environment.Show Notes:Intro:•John and Lou introduce the multi-part series on remote work, exploring how IT can optimize remote setups for productivity and flexibility.Why Should We Care About Remote Work?•The benefits of remote work include productivity boosts, better work-life balance, and access to a broader talent pool.•Cost savings for both employees (commute, meals) and companies (office space).•Increased flexibility improves employee satisfaction and retention, a critical metric in today’s competitive job market.Why Are We So Adamant About Promoting Remote Work?•Both John and Lou have extensive experience managing remote teams and have seen the benefits firsthand.•Remote work offers flexibility for life’s demands (e.g., elder care) and can significantly improve mental and physical health.•They argue that modern tools and technology make remote work not only feasible but often preferable.State of the RTO (Return to Office) Effort:•Large companies, like Amazon, are mandating RTO, often citing productivity concerns. John and Lou view this as a micromanagement issue.•Examples from companies like Pinterest show that flexible work policies can boost innovation and reduce real estate costs.•https://www.fastcompany.com/91225476/pinterest-exec-companies-that-force-workers-back-to-the-office-are-missing-the-big-picture•Insight into how cultural shifts and management adjustments can sustain remote productivity without requiring full-time office presence.Wrap Up:John and Lou invite feedback on the pros and cons of remote work, asking listeners to share their experiences and opinions.Stay tuned for future episodes diving into IT strategies, tools, and setups that enhance remote work efficiency.Connect via feedback@itsparccast.com or on X @ITSPARCCast. Hosted on Acast. See acast.com/privacy for more information.

11-13
30:32

TP-Link Zombies are coming, GitHub’s AI Spark Tool, and a Critical SharePoint Vulnerability

In this Episode of IT SPARC Cast, John and Lou dive into the latest in IT security and automation. They cover TP-Link devices forming a massive botnet, GitHub’s AI-powered Spark for micro app creation, and a critical SharePoint vulnerability (CVE-2024-38094) that’s being actively exploited. Tune in for insights, proactive solutions, and the importance of robust patching policies.Show Notes:News Bytes:TP-Link Botnet Threats:•Hackers using over 8,000 compromised TP-Link routers in password-spray attacks targeting Microsoft Azure accounts. The botnet, known as “Botnet 7777,” operates stealthily across 16,000 devices, largely evading detection.•Discussion on how home and small business devices, like TP-Link, may pose hidden risks in networks due to infrequent patching.•https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botnet-used-in-password-spraying-attacks/#gsc.tab=0 GitHub’s Spark for AI Micro Apps:•GitHub introduces Spark, a tool allowing users to create micro applications using natural language commands. This AI-powered system promises efficiency for non-coders and customizable app creation for IT departments.•John and Lou discuss the potential of Spark in enterprise environments and the future of no-code tools for network and software automation.•https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.htmlGoogle’s Big Sleep Project Discovers Real-World Exploits:•Google’s Big Sleep project, an AI-assisted vulnerability research tool, recently identified an exploitable stack buffer overflow in SQLite before its public release.•Highlighting how AI is becoming a critical resource for vulnerability detection, with this discovery marking a significant step in proactive security.•https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.htmlCVE of the Week:SharePoint Vulnerability - CVE-2024-38094:•A recently patched vulnerability in SharePoint has seen exploitation in the wild. Rated 7.2 in severity, this issue allows attackers to run unauthorized code on vulnerable SharePoint servers.•John and Lou stress the need for timely patching and suggest tools for network administrators to keep an eye on such vulnerabilities in on-prem environments.•https://www.csoonline.com/article/3598616/a-new-sharepoint-vulnerability-is-already-being-exploited.html Wrap Up:John and Lou invite listeners to share thoughts on SharePoint’s role in the enterprise and suggest any topics for future episodes. Connect with feedback@itsparccast.com or follow @ITSPARCCast on X.Don’t miss next week’s deep dive on supporting remote work in enterprise IT. Hosted on Acast. See acast.com/privacy for more information.

11-08
23:40

AI in K-12 Education Part 3: Policies, Challenges, and the Path Forward

In the final episode of this three-part series, John and Lou discuss the future of AI in K-12 education. They cover how IT leaders stay informed on AI developments, the role of AI in classrooms, and best practices for collaboration among school districts. Discover insights on building policies that balance innovation with responsibility and explore the partnerships shaping AI’s role in education.Show Notes:Intro:•John and Lou welcome listeners to the last part of the K-12 AI series, covering AI policy development and district collaboration for the future of AI in schools.Recap:•Summary of Episodes 1 and 2: The current state of AI in schools, human impacts, and AI’s effect on students, teachers, IT staff, and parents.•Youtube Episode - Part 1 - https://youtu.be/CU1CryyZkIE•Youtube Episode - Part 2 - https://youtu.be/wLR6g81yLpc  Question 7: Staying Informed on AI Developments•District 1 utilizes conferences like Maine Educational Technology Association (META) and an AI sandbox project with the University of Maine to stay up-to-date.•District 2 stays informed through online forums and “thinking like a student,” searching topics students might explore about AI.Question 8: AI’s Role in the Future of Education•District 1 emphasizes balancing AI benefits with responsible use, focusing on policy to deter misuse (e.g., cheating).•District 2 views AI as an integral tool in high school education, focusing on guidance for ethical usage as AI adoption grows.Question 9: Collaboration with Other Districts and Organizations•District 1 collaborates with Maine Educational Technology Association (META) and the University of Maine, while District 2 shares resources through the New Hampshire CTO group.•Both districts highlight the importance of real-time communication among teachers, IT staff, and administrators to adapt AI policies.Wrap Up:John and Lou conclude the series, inviting feedback from educators, IT directors, and parents. Join the conversation at feedback@itsparccast.com or on X @ITSPARCCast.Stay tuned for next week’s series on remote work and enterprise IT. Hosted on Acast. See acast.com/privacy for more information.

11-06
17:45

AT&T vs. Broadcom, Delta’s Legal Battle with CrowdStrike, and Super Micro’s Audit Issues

In Episode 11 of IT SPARC Cast, John and Lou unpack high-stakes lawsuits and investigations shaking the IT industry. They cover AT&T’s clash with Broadcom over VMWare support costs, Delta’s lawsuit against CrowdStrike after a massive flight disruption, and Ernst & Young’s exit as Super Micro’s auditor. Join us for insights on how these cases impact IT decision-makers, plus our CVE of the Week and security tips for handling layoffs.Show Notes:News Bytes:Return to Office Programs Losing Steam:•New data shows that 80% of companies have return-to-office policies, but only 17% enforce them. Lou and John discuss how “quiet covering” by managers is keeping remote work alive and the risks of enforcing in-office requirements.•https://www.yahoo.com/news/back-office-orders-become-common-100031656.html AT&T Sues Broadcom Over VMWare Support Costs:•AT&T claims Broadcom violated a VMWare support agreement, raising fees by 1,000% after switching to a subscription model. The New York Supreme Court issued a temporary restraining order to maintain AT&T’s support during negotiations.•https://www.theregister.com/2024/10/16/att_broadcom_vmware_settlement_possible/ •https://www.techtarget.com/searchVMware/news/366614302/Court-asks-ATT-Broadcom-to-resolve-VMware-dispute •https://arstechnica.com/information-technology/2024/10/a-year-after-broadcoms-vmware-buy-customers-eye-exit-strategies/ Delta Airlines vs. CrowdStrike:•Delta is suing CrowdStrike over a botched update that caused a $500 million impact on operations, affecting 1.3 million passengers. Lou breaks down how the lawsuit may shape the future of endpoint security.•https://www.reuters.com/legal/delta-sues-crowdstrike-over-software-update-that-prompted-mass-flight-2024-10-25/ Super Micro Under Federal Investigation:•Ernst & Young resigned as Super Micro’s auditor, citing internal control issues. Super Micro’s shares plummeted 33%, leading IT leaders to consider alternative hardware providers or renegotiate for better pricing.•https://www.cnbc.com/2024/10/30/super-micro-auditor-resigns-after-raising-concerns-months-earlier.htmlCVE of the Week:Reflecting on CVE’s 25 Years of Service:•Instead of a specific CVE, John and Lou honor the CVE system’s contribution to cybersecurity. They discuss its origins with MITRE and its essential role in keeping systems secure.Insider Threat Spotlight: •Lou shares a story about a former Disney employee who hacked internal systems to disrupt menu displays, demonstrating the need for stricter access management during terminations.•https://www.theregister.com/2024/10/30/fired_disney_employee_hacks_menu/  Hosted on Acast. See acast.com/privacy for more information.

11-01
32:20

AI in K-12 Education Part 2: Tackling Cheating, Privacy, and Policy

In this episode of IT SPARC Cast Deep Dive, John and Lou continue with the second of three parts of the discussion on AI in K-12 and primary education. They dive into how schools address AI-assisted cheating, privacy challenges, and the role of IT departments in crafting responsible AI policies. Learn about real-life strategies from school IT leaders and the importance of collaboration in using AI effectively in education.Show Notes:Intro:John and Lou kick off by recapping the first episode, where they compared two school districts’ approaches to AI in education.Deep Dive:AI and Cheating Detection•Concerns around plagiarism: Districts are exploring AI detection tools but worry about false positives.•Some schools now require all assignments to be written in Google Docs to track typing patterns and prevent AI-assisted submissions.•Discussion on the evolving tactics students might use to bypass these measures.Collaborative Policy Development•Districts are conducting “AI tours” and working with digital learning specialists to educate teachers on safe AI tools and data privacy.•Schools emphasize collaboration between IT, teachers, and administrators to ensure that AI policies align with classroom needs.Managing Student Devices•IT departments are limiting AI tools on student Chromebooks, while allowing teachers access to approved educational AI applications.•Google’s admin console gives schools control over Chromebooks, enabling restrictions that align with educational goals and privacy requirements.Experimenting with Prompt “Poisoning” to Detect AI Usage•John and Lou test a strategy where obscure references are added to prompts to detect AI-generated work, revealing mixed results in effectiveness.•They discuss the importance of educating teachers to recognize AI-generated assignments and use critical questioning to assess student knowledge.Wrap Up:John and Lou encourage feedback from educators and IT professionals on AI’s role in schools, inviting emails at feedback@itsparccast.com and comments on X @ITSPARCCast.Listeners are urged to subscribe, share, and stay tuned for next week’s episode on AI’s future in education. Hosted on Acast. See acast.com/privacy for more information.

10-30
25:52

IT SPARC Cast - October 25th 2024

In this episode of IT SPARC Cast, John and Lou tackle VMware’s shifting strategy under Broadcom, discussing whether the virtualization giant is losing ground. They also dig into the resurgence of the Spectre vulnerability and what it means for IT security in 2024. Plus, with recent fines over the 2020 SolarWinds hack, CISOs are facing more pressure to cover their bases. Tune in for expert opinions and insights from the world of Enterprise IT.Show Notes:News Bytes:VMWare’s Future Under Broadcom:•With Broadcom’s acquisition of VMWare, companies are jumping ship due to rising costs. •John and Lou discuss potential alternatives •https://www.linkedin.com/posts/prgmd_has-broadcom-killed-vmware-many-businesses-activity-7253122328279076866-FfjD?utm_source=share&utm_medium=member_iosAI Agents: Anthropic’s and Microsoft’s Automation Tools•Anthropic’s AI Agents:•New AI models automate tasks like keystrokes and mouse clicks, aimed at software developers.•https://www.reuters.com/technology/artificial-intelligence/anthropic-releases-ai-automate-mouse-clicks-coders-2024-10-22/?_bhlid=11acf92736eb5937f843fe68c430b79a27b05f8f•Microsoft’s AI Agents:•No-code AI tools for automating daily tasks, releasing in November.•Easy access to AI-powered automation without programming skills.•https://www.reuters.com/technology/artificial-intelligence/microsoft-allow-autonomous-ai-agent-development-starting-next-month-2024-10-21/ AGI Prompt Attacks: Deceptive Delight•Researchers found a method to trick AGI models into revealing restricted info with cleverly crafted prompts.•AI systems can be manipulated to reveal hidden data, posing risks for sensitive information handling.•https://thehackernews.com/2024/10/researchers-reveal-deceptive-delight.htmlhttps://thehackernews.com/2024/10/researchers-reveal-deceptive-delight.html CISO Accountability in the SolarWinds Fallout:•CISOs are becoming the new shields for corporations and what this means for corporate liability in data breaches.•https://www.csoonline.com/article/3578782/four-firms-charged-fined-over-handling-of-solarwinds-hack-disclosures.htmlCVE of the Week:Spectre Bug Resurfaces:•Despite widespread patches since 2017, Spectre is back in the spotlight. •This time, researchers found a way to bypass hardware mitigations and access root passwords, leaving companies exposed. •https://www.phoronix.com/news/Torvalds-Frustrated-Buggy-HW Hosted on Acast. See acast.com/privacy for more information.

10-25
40:30

AI in K-12 Education Part 1: Revolutionizing Education or Raising Concerns?

In this inaugural episode of IT SPARC Cast Deep Dive, John and Lou explore the impact of AI on K-12 education. They discuss how different school districts are handling the integration of AI tools, including the use of tools like ChatGPT and Google Gemini. Are schools ready for this shift, or are they playing catch-up? Join the conversation as they examine the challenges, policies, and future of AI in the classroom.Show Notes:AI in the Classroom: A Case Study:John spoke with two IT directors from different school districts—one in a rural, lower-income area (School A) and another in a more affluent, suburban district (School B). They compare how these districts are tackling the challenges of AI in education.•School A has implemented an acceptable use policy focused on preventing plagiarism with AI tools like ChatGPT.•School B has adopted School AI, a specialized tool that monitors student AI use and helps keep them on task.ChromeBooks and Google Gemini:The rise of AI-integrated hardware in education is becoming a growing concern, with Google Gemini’s introduction to new ChromeBook models. Will schools be able to control these tools effectively, or will they be forced to adopt AI faster than they are prepared for?Student Learning and AI:Both districts are at different stages of AI adoption, but both recognize the importance of educating teachers on responsible AI use before fully integrating it into the classroom. AI tools like Canva and School AI have been introduced to help students, but privacy and ethical concerns loom large.Wrap Up:John and Lou discuss their takeaways: Schools are at the beginning stages of AI adoption, but they are aware of the challenges ahead. They encourage listeners to share their experiences and insights regarding AI in education.Feedback and topic suggestions: feedback@ITSPARCCast.com or @ITSPARCCast on X.Like, subscribe, and turn on notifications for more IT deep dives and expert opinions. Hosted on Acast. See acast.com/privacy for more information.

10-23
18:07

IT SPARC Cast - October 18th 2024

In this episode of IT SPARC Cast, John and Lou dive into the complexities of open source funding, the future of data centers powered by small modular nuclear reactors, and critical security vulnerabilities you need to know about. With a CVE hitting your firewall hard and the increasing fragility of AI systems, we cover what you need to secure your enterprise IT systems. Tune in for insights from seasoned pros in the IT space.Show Notes:News Bytes:• Open Source in Crisis: How enterprises rely on open source software and the importance of funding it.• Python and Linux are at the core of infrastructure, but without proper support, businesses are at risk.• Example: The left-pad NPM issue that caused widespread disruptions.• How can businesses support open-source projects?• Corporate sponsorships, direct monetization, and intermediary companies like Red Hat and Canonical are crucial solutions.• A spotlight on Germany’s Sovereign Tech Fund, leading the way in public aid for open source.• https://www.infoworld.com/article/3557846/how-do-we-fund-open-source.html• AI’s Growing Energy Demands• Amazon and the U.S. Department of Energy are collaborating on small modular nuclear reactors (SMRs) to power data centers.• Microsoft, Amazon, and others are exploring nuclear power to handle the future energy demands of AI.• Lou explains the cutting-edge advancements in liquid fluorine salt reactors and their potential future applications.• https://www.geekwire.com/2024/doe-announces-900m-for-next-gen-reactors-as-amazon-launches-nuclear-power-pursuit/• The Changing Landscape of IT Jobs• Despite big layoffs from tech giants, smaller companies are filling the gap.• AI and its role in reshaping the IT job market, including a shift toward roles in tech support, help desk, and AI development.• https://www.computerworld.com/article/3554907/big-shift-in-it-employment-shows-new-skills-are-needed.htmlCVE of the Week:• Firewall Meltdown: Fortinet, Palo Alto, and Check Point firewalls are facing severe vulnerabilities with CVEs like 2024-23113.• Fortinet’s OS vulnerabilities could allow attackers to execute arbitrary commands.• Palo Alto’s CVEs include operating system-level command injection vulnerabilities with a severity rating of 9.9 out of 10.• What should you do? Embrace defense-in-depth strategies and stay in touch with your firewall vendors for immediate updates.• https://nvd.nist.gov/vuln/detail/CVE-2024-23113 • https://thehackernews.com/2024/10/cisa-warns-of-critical-fortinet-flaw-as.html Wrap Up:•Call for feedback: Send your topic ideas or feedback to feedback@itsparccast.com or connect with us on X (@itsparccast).•Be sure to like, subscribe, and turn on notifications so you don’t miss next week’s insights into enterprise IT. Hosted on Acast. See acast.com/privacy for more information.

10-18
28:53

IT SPARC Cast - October 11th 2024

In this episode of IT SPARC Cast, John and Lou tackle the latest tech news, including a troubling Microsoft vulnerability affecting Mac apps, a phishing scam using physical mail, and malware targeting air-gapped networks. They also preview an upcoming book critiquing tech management practices and delve into Gartner’s 2024 tech trends. Tune in for insights, opinions, and practical advice for staying ahead in the IT world.Show Notes:News Bytes: • Microsoft’s Mac App Vulnerability: The hosts dive into a security issue affecting Microsoft’s Mac apps, where an entitlement disables MacOS’s hardened runtime, potentially allowing malicious DLL execution. Microsoft has partially addressed the issue but left some apps vulnerable. https://www.macworld.com/article/2432176/microsoft-apps-on-the-mac-have-a-security-hole-that-wont-get-fixed-soon.html • Air-Gapped Network Threats: Lou shares news about sophisticated malware targeting air-gapped networks, discovered by ESET. The malware employs USB drives for infiltration and advanced techniques for data exfiltration. The discussion touches on the human factor in security and the evolving threat landscape.https://arstechnica.com/security/2024/10/two-never-before-seen-tools-from-same-group-infect-air-gapped-devices/   • Old-School Phishing Goes Physical: Phishing has gone back to basics, with scam letters arriving in physical mailboxes in Germany, mimicking legitimate bank correspondence. John shares a personal phishing experience, emphasizing the need for skepticism, even with familiar-looking messages.https://www.pcworld.com/article/2419859/police-warn-of-deceptively-genuine-phishing-by-post-how-the-scam-works.html • Book Preview – “Fatal Abstraction”: Lou introduces an upcoming book arguing that managerial practices are to blame for many tech problems, touching on over-reliance on software and management misunderstandings. The hosts discuss management issues and software’s limitations in solving business challenges.https://www.theverge.com/2024/10/8/24265264/what-if-techs-problem-is-management  • Gartner’s 2024 Technology Trends: The episode touches briefly on Gartner’s top tech trends for the upcoming year, including AI trust and security, continuous threat exposure management, and industry cloud platforms. https://www.gartner.com/en/articles/gartner-top-10-strategic-technology-trends-for-2024CVE of the Week: • “PerfCTL” Linux Malware: This week’s CVE is a stealthy malware called “PerfCTL,” which exploits servers for cryptocurrency mining or malicious network activity. The hosts recommend packet-based analytics tools to detect unusual network behavior and discuss how to protect against such threats.https://www.wired.com/story/perfctl-stealthy-malware-infected-linux-systems Hosted on Acast. See acast.com/privacy for more information.

10-11
29:59

IT SPARC Cast - October 4th 2024

In this episode of IT SPARC Cast, John and Lou dive into Dell’s controversial return to office mandate, the future of Intel’s chip strategy, and the latest on Linux vulnerabilities. They discuss disaster recovery strategies, cybersecurity awareness, and how being prepared beats being lucky when disasters strike. Tune in for Lou’s Hot Take on crisis management and how IT pros can navigate unexpected events with smart planning. As always, we cover the latest IT news, CVEs, and much more!Show Notes:News Bytes• Dell’s In-Office Policy: How Dell’s move to require five days in the office is sparking employee discontent, and why remote work might still be the future.• https://content.techgig.com/technology/wfh-ends-at-dell-sparks-outrage-among-employees/articleshow/113772027.cms• Intel’s Gamble: Intel’s big bet on the 18A process and how Clearwater Forest Xeon chips could make or break the company’s dominance in data centers.• https://www.tomshardware.com/pc-components/cpus/intels-turnaround-plan-revolves-around-this-one-chip-family-clearwater-forest-pictured-intels-first-18a-chip-slated-for-high-volume-manufacturingCVE of the Week• CUPS Vulnerability: A new Linux CUPS vulnerability has been exposed, affecting printing services across systems. It’s a serious root-level exploit, and we break down the steps to mitigate it. Plus, a special shoutout to @EvilSocket on X for reporting the issue.• Check it out: exploit sandbox here: https://x.com/ippsec/status/1841463975734657440Lou’s Hot Take• Prepared vs. Lucky: In light of recent natural disasters, Lou emphasizes the importance of being prepared. He shares how IT teams can ensure continuous service during crises and highlights the increasing role of satellite communication (e.g., Starlink) for backup.Have thoughts or feedback? Email us at feedback@itsparccast.com or find us on X @itsparccast.Be sure to like, subscribe, and turn on notifications to stay updated on future episodes! Hosted on Acast. See acast.com/privacy for more information.

10-04
31:07

IT SPARC Cast - September 27 2024

IT SPARC Cast - September 27 2024: Old-School Linux, AI Monetization, and Unpatched Linux ExploitsBrief Description:In this week’s episode, John and Lou dive into the latest IT news with a nostalgic look at Linux running on a 1971 Intel processor, Cloudflare’s new AI bot marketplace, and an alarming unpatched vulnerability in the Linux kernel. They explore the implications of these stories for the enterprise, including hybrid work concerns, the evolving landscape of enterprise security, and key strategies for navigating IT challenges. Lou delivers a hot take on the future of remote work, and John addresses how enterprise IT can better adapt to changing workplace dynamics.Episode Sections:News Bytes•Linux on Intel 4004 Processor: A tech enthusiast boots Linux on a vintage Intel 4004.•Necro Trojan on Google Play: The Necro Trojan malware has infected millions of devices via the Google Play Store, posing a threat to enterprise networks through sideloading apps.•Cloudflare’s AI Marketplace: Cloudflare introduces a marketplace allowing websites to charge AI bots for scraping data. This could open revenue streams for content-heavy enterprises.•Smartsheet Goes Private: Smartsheet is set to go private in an $8.4 billion deal, reflecting a strategic pivot aimed at long-term growth.CVE of the Week•Unpatched Linux Exploit: A severe vulnerability (severity score of 9.9) affecting all modern Linux systems has been discovered, allowing full unauthenticated remote access. With no fix yet available, this exploit could have major implications for IoT devices and enterprise infrastructure.Lou’s Hot Take•Remote Work Backlash: Lou takes on the growing trend of companies, including Amazon, forcing employees back into the office. He explores the potential long-term consequences for retention, productivity, and employee satisfaction.Wrap Up•Format Feedback: John and Lou ask listeners for feedback on possibly breaking the show into shorter, more focused segments. They discuss upcoming tweaks to the show format based on listener suggestions.Links:•Linux Intel 4004 boot kit - https://www.tomshardware.com/pc-components/cpus/linux-takes-476-days-to-boot-on-an-ancient-intel-4004-cpu-cpu-precedes-the-os-by-20-years •Necro Trojan - https://www.securityweek.com/necro-trojan-infects-google-play-apps-with-millions-of-downloads/ •Cloudflare’s AI marketplace - https://techcrunch.com/2024/09/23/cloudflares-new-marketplace-will-let-websites-charge-ai-bots-for-scraping/•Smartsheet’s $8.4 billion acquisition - https://www.geekwire.com/2024/smartsheet-acquisition-competing-bids-unlikely-8-4b-deal-could-fuel-other-private-equity-buyouts/•Computer World article on Amazon’s return to office policy - https://www.computerworld.com/article/3532158/amazons-rto-mandate-likely-to-boomerang-other-companies-should-not-follow-suit.html Hosted on Acast. See acast.com/privacy for more information.

09-27
41:16

IT SPARC Cast - September 20 2024

In this episode of IT SPARC Cast, hosts John Barger and Lou Schmidt dive into the latest developments in the IT industry. They discuss the potential security risks associated with Microsoft’s Copilot, Intuit’s new enterprise suite, and the significant layoffs at Cisco and IBM. In the CVE of the Week, they explore an advanced phishing attack exploiting HTTP refresh in email. John’s Hot Take addresses Amazon CEO Andy Jassy’s push for a full return to the office and the implications for remote work. They wrap up with listener feedback on alternative data center power solutions.Show Notes:News Bytes • Will Potential Security Gaps Derail Microsoft’s Copilot?• Discussion on the security implications of Microsoft’s Copilot and data access concerns.• Comparison with Apple’s approach to AI and data privacy.• Questions about audit tools and how administrators can manage these new technologies.• https://www.computerworld.com/article/3511345/will-potential-security-gaps-derail-microsofts-copilot.html • Intuit Introduces Enterprise Suite• Overview of Intuit’s new robust financial management system.• Potential benefits for HR and finance operations.• Concerns about the sustainability of customer success teams and long-term support.• https://quickbooks.intuit.com/r/enterprise/what-is-intuit-enterprise-suite/ • Layoffs at Cisco and IBM• Cisco executes significant layoffs, hitting DevNet hard.• Rumors about Cisco passing off AnyConnect VPN service to Microsoft.• IBM’s stealth layoffs affecting thousands of employees.• Importance of contacting account teams to understand the impact on services and support.• https://www.theregister.com/2023/05/02/ibm_ai_back_office_jobs/CVE of the Week • Advanced Phishing Attack Exploiting HTTP Headers• Discussion on a sophisticated phishing attack that uses HTTP header manipulation for credential theft.• How the attack bypasses traditional email filters and user vigilance.• Call for community input on mitigation strategies.• https://unit42.paloaltonetworks.com/rare-phishing-page-delivery-header-refresh/• https://www.linkedin.com/posts/unit42_phishing-timelythreatintel-unit42threatintel-activity-7218635942796926978-ztlB/• Unit 42 Timely Threat Github - https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2024-07-15-IOCs-from-recent-phishing-campaign.txtJohn’s Hot Take • Amazon’s Return-to-Office Mandate• John critiques Amazon CEO Andy Jassy’s decision to require employees to return to the office full-time.• Analysis of the potential negative impacts on employee satisfaction and productivity.• Discussion on the benefits of remote work and how it can be a win-win for employers and employees.• https://www.wsj.com/business/amazons-return-to-office-plans-spark-concern-and-debate-among-employees-6273f615?mod=lead_feature_below_a_pos1Wrap Up • Listener feedback from Krangor on alternative power solutions for data centers, including geothermal energy and 360 Mining. • Invitation for listeners to provide feedback and engage with the show.Contact InformationEmail: feedback@itsparccast.comX (Twitter): @itsparccast Hosted on Acast. See acast.com/privacy for more information.

09-20
37:08

IT SPARC Cast - September 13 2024

In this episode of IT SPARC Cast, John Barger and Lou Schmidt delve into the latest IT news, including a novel attack vector that uses radio signals from RAM to break into air-gapped networks, Oracle’s ambitious plans to power data centers with nuclear reactors, and the phasing out of ActiveX by Microsoft. Lou also introduces the power of eBPF (Extended Berkeley Packet Filter) technology in his Hot Take, discussing its role in high-performance monitoring without compromising kernel security. As always, there’s plenty of insights, banter, and a touch of nostalgia.Show Notes:Intro• Episode Overview: RAMBO attacks on air-gapped networks, Oracle’s nuclear data center vision, and the unexpected longevity of ActiveX. [INSERT LINK HERE for further reading]News Bytes• RAMBO Air-Gap Attack: A groundbreaking attack vector discovered by Dr. Guri from Israel, where radio signals from RAM is used to exfiltrate data from air-gapped networks using radio signals. https://thehackernews.com/2024/09/new-rambo-attack-uses-ram-radio-signals.html• Microsoft Phases Out ActiveX: A nostalgic look back at ActiveX and its impending deprecation in Office 2024, part of Microsoft’s broader security enhancements. https://www.computerworld.com/article/3510909/activex-to-be-disabled-in-office-2024.html • Oracle’s Nuclear Data Centers: Larry Ellison’s bold plans for next-gen data centers powered by small modular nuclear reactors, addressing energy needs and vulnerabilities. https://www.cnbc.com/2024/09/10/oracle-is-designing-a-data-center-that-would-be-powered-by-three-small-nuclear-reactors.html CVE of the Week• CVE-2024-43491: A critical vulnerability in Windows 10 version 1507, which allows attackers to roll back patches and exploit system flaws. Exploits are already in the wild, with a severity score of 9.8 out of 10. Microsoft advises immediate action to mitigate this threat. https://www.securityweek.com/microsoft-says-windows-update-zero-day-being-exploited-to-undo-security-fixes/Lou’s Hot Take• Introduction to eBPF (Extended Berkeley Packet Filter): Lou breaks down the advantages of eBPF in high-performance monitoring, especially in cloud and container environments. He explores its potential in replacing kernel-level monitoring, offering better security without sacrificing performance. https://falco.org/ Falco is a cloud-native security tool designed for Linux systems.https://coroot.com/ is monitoring systems in containerized deploymentshttps://deepflow.io/ is doing full service mapping in containerized full stack deploymentshttps://cilium.io/ One of the core toolkits maintained by the team building eBPF. • CrowdStrike Incident Recap: Reflecting on the March kernel panic caused by an update, Lou discusses how eBPF could mitigate such risks in the future.Wrap Up• Feedback Request: John and Lou invite listeners to share thoughts on eBPF, how they’re handling Windows 10 updates, and any other topics they’d like covered in future episodes. Reach out at feedback@itsparccast.com or @ITSPARCCast on X.  Hosted on Acast. See acast.com/privacy for more information.

09-13
32:08

IT SPARC Cast - September 6 2024

In this episode of IT SPARC Cast, John Barger and Lou Schmidt discuss Intel’s exciting new Lunar Lake CPUs and their potential impact on mobile IT. The duo dives into crypto jacking attacks targeting Atlassian Confluence servers and the critical vulnerabilities that could leave your systems at risk. The discussion continues with how IT can better support the remote workforce, from technical tools to managing human connections. Tune in for insights, tech updates, and practical management tips from experienced IT professionals.Show Notes:Intro:•Episode introduction and overview of topics: Intel’s Lunar Lake CPUs, Atlassian Confluence crypto jacking, and supporting remote work.News Bytes:•Intel’s Lunar Lake CPUs•Atlassian Confluence Crypto Jacking. https://www.darkreading.com/threat-intelligence/attackers-exploit-critical-atlassian-confluence-flaw-for-cryptojacking •GDPR & Uber’s Fine https://www.forbes.com/sites/siladityaray/2024/08/26/uber-fined-record-324-million-in-netherlands-for-transferring-sensitive-eu-driver-data-to-us/•GITEX Global Preview https://www.gitex.com CVE of the Week:•D-LINK DIR-846W Vulnerability: Discussion of unpatched vulnerabilities in end-of-life D-LINK routers, rated 8+ on the severity scale. Emphasizing the risks of running legacy gear in your network. Main Stories - Supporting mixed remote and on-site IT Teams•Regular Virtual Meetings with a Purpose•Tailored Engagement•Asynchronous Communication Tools•Team Building Activities•Udemy - https://www.udemy.com•LinkedIn Learning - https://www.linkedin.com/learning/•Challenges App for iOS - https://apps.apple.com/us/app/challenges-compete-get-fit/id1051342211•Challenges App for Android - https://play.google.com/store/search?q=challenges+compete+get+fit&c=apps•The Conqueror Challenges for iOS - https://apps.apple.com/us/app/the-conqueror-challenges/id1539543704•The Conqueror Challenges for Android - https://play.google.com/store/search?q=the+conqueror+challenges&c=apps•Recognizing ContributionsListener Feedback:• Response to feedback from Krangor, recommending Miro and Obsidian for collaboration and project management.•https://miro.com•https://obsidian.mdListeners can send their feedback or topic suggestions to feedback@itsparccast.com or connect on X @itsparccast. Watch on YouTube or subscribe via your favorite podcast platform. Hosted on Acast. See acast.com/privacy for more information.

09-06
40:16

IT SPARC Cast - August 30 2024

Show Notes:Intro:•Episode introduction and overview of topics to be discussed.•Key Headlines: Polaris Dawn Mission and its implications for Starlink, Cisco’s latest round of layoffs, and Microsoft’s TCP/IP stack vulnerability.News Bytes:•Starlink & Polaris Dawn: Discussion on the Polaris Dawn mission and how its new Starlink capabilities could impact high-performance networks and real-time trading.•X (formerly Twitter) & Video Conferencing: Analysis of X’s (formerly Twitter) entry into the video conferencing market and its potential competition with Zoom, Teams, and others.•Cisco Layoffs: Examination of Cisco’s latest layoff strategy, the potential impact on its workforce, and the implications for customers relying on Cisco’s network solutions.CVE of the Week:•CVE-2024-38063: Deep dive into a high-severity vulnerability in the Windows TCP/IP stack affecting systems using IPv6. Discussion on the potential risks, the simplicity of the exploit, and the urgency of applying the available patch.Main Stories:•Supporting Remote Work: Exploration of the ongoing challenges in supporting remote workers in the IT industry. John and Lou discuss the lack of adequate tools and support for remote workers, the need for better collaboration ecosystems, and the potential for companies to reinvest cost savings into enhancing remote work infrastructure.•Future Collaboration Tools: Discussion on the current state of collaboration tools and the need for better-integrated solutions that support various platforms and work styles.Wrap Up:•Listener feedback segment featuring a question from Robert about Broadcom’s acquisition strategy, particularly the VMware acquisition. John and Lou share their thoughts on the implications for the virtualization market and broader IT industry.•Closing remarks and call to action for listeners to submit their questions and topic suggestions for future episodes. Hosted on Acast. See acast.com/privacy for more information.

08-30
33:10

IT SPARC Cast - August 8 2024

In the inaugural episode of IT SPARC Cast, John Barger and Lou Schmidt dive into the latest happenings in the IT world with a mix of insights and a touch of humor.NEWS BYTES:•Extreme Networks Teams Up with Intel: A new alliance aims to supercharge AI capabilities within Extreme’s platform.•Messy Data Hinders AI Adoption: Learn why disorganized data is holding enterprises back from leveraging AI effectively.•Former Pivotal CEO’s New Venture: Rob Mee launches Mechanical Orchard, tackling the digital transformation of legacy systems.MAIN STORIES:•Training the AI-Enabled Workforce: As AI adoption skyrockets, how do companies prepare their teams for this new landscape?•HPE’s Acquisition of Juniper Networks: Regulatory hurdles are being cleared—what does this mean for the future of networking?CVE OF THE WEEK:•VMware’s ESXi Vulnerability: A critical exploit tied to Active Directory could wreak havoc—learn why patching isn’t always enough.Tune in for expert takes, some speculation on the future, and critical info every IT professional should know!Send us feedback! feedback@ITSPARCCast.com or @ITSPACCast on X Hosted on Acast. See acast.com/privacy for more information.

08-28
31:33

Recommend Channels