The ITAM Roundup: 6/9/24

roundup Jun 9, 2024
📰
News

Microsoft makes Windows Recall opt-in, secures data with Windows Hello

Microsoft updates Recall for Copilot+ PCs to be more secure by making it opt-in and requiring users to prove their presence via Windows Hello before enabling and accessing Recall. Additionally, Recall's search index database receives enhanced decryption protection through Windows Hello Enhanced Sign-in Security (ESS), ensuring data remains encrypted until authenticated. These privacy and security updates will be implemented when Recall (preview) ships on June 18, aligning with Microsoft's recent commitment to prioritize security.

Microsoft makes Windows Recall opt-in, secures data with Windows Hello
Following massive customer pushback after it announced the new AI-powered Recall for Copilot+ PCs last month, Microsoft says it will update the feature to be more secure and require customers to opt in to enable it.

Announcing FOCUS support for OCI cost reports to make multicloud FinOps easier

Oracle Cloud Infrastructure (OCI) announces support for the FinOps Open Cost and Usage Specification (FOCUS), aiming to standardize cost reports across cloud providers and facilitate multicloud FinOps practices. FOCUS provides a common format for cost and usage datasets, enabling efficient allocation, analysis, and optimization of cost data across different cloud providers. OCI offers supplemental cost reports in the FOCUS schema, making it easier for users to understand and manage their cloud costs programmatically or through the console.

Announcing FOCUS Support for OCI Cost Reports
FinOps Open Cost and Usage Specification (FOCUS) is an open-source specification aimed at bringing consistency across the cost and usage datasets produced by cloud providers. OCI is one of the contributors to the FOCUS 1.0 specification. OCI is firm in its support for the FOCUS effort and is now generating supplemental cost reports in the FOCUS schema.

VMware Tools End of Life

VMware Tools version 10.3.x is reaching its end of life on June 30, 2024, necessitating an upgrade to ensure continued support and access to security patches. VMware Tools is essential for managing virtual environments, providing functionalities such as message exchange, OS customization, and time synchronization between host and guest machines. Following VMware's Enterprise Infrastructure Policy, versions receive 5 years of general support followed by 2 years of technical guidance, during which only low-severity issues are addressed, emphasizing the importance of staying updated to maintain security and functionality.

VMware Tools End of Life - Lansweeper
VMware Tools version 10.3.x is going end of life on June 30th, 2024. Manage your VMware Tools Installations with the included audit to remain supported.

Microsoft Makes $3.2B AI Bet on Swedish Data Centers

Microsoft is investing $3.2 billion in AI and cloud facilities in Sweden, marking its largest infrastructure investment in the Nordic country, with plans to add 20,000 GPUs across three data centers. The move aims to leverage Sweden's green energy resources and cements Microsoft's presence in the nation while committing to training 250,000 individuals in essential AI skills. The investment reflects Microsoft's belief in Sweden's potential for AI innovation, with the Nordic region attracting big energy users like Meta Platforms and Alphabet due to its abundance of clean energy.

Microsoft Makes $3.2 Billion AI Bet on Swedish Data Centers
The move cements the tech-giant’s footprint in the nation by adding 20,000 GPUs at its three data centers.

SAP to acquire digital adoption platform WalkMe for $1.5B

WalkMe, founded in Israel in 2011 and now based in San Francisco, initially focused on simplifying website navigation but evolved to offer both consumer and enterprise solutions, including in-app guidance and user behavior insights. As part of its enterprise push, WalkMe automates contextual support within applications, a feature SAP views as valuable for its own enterprise customers. Despite fluctuations in valuation post-IPO, WalkMe's recent strong earnings and the introduction of WalkMeX, an AI-powered copilot, have contributed to its shares rising by 25% in two weeks, prompting SAP's acquisition interest, aligning with its focus on supporting end users in software transformations.

SAP to acquire digital adoption platform WalkMe for $1.5B | TechCrunch
SAP sees WalkMe’s focus on automating contextual, in-app support as bringing value to its own enterprise customers.
📖
Tips

Refactoring your IT sourcing strategy for digital success

Perkins emphasizes the strategic importance of transitioning digital operations in-house, despite potential increases in labor costs, as outsourced solutions may not adequately protect or transform the organization. Bringing peers along in the workforce transformation journey requires delivering messages in business terms, highlighting benefits like cost advantages and improved decision-making, while involving IT staff in setting future roadmaps to manage evolving technology effectively.

Refactoring your IT sourcing strategy for digital success
Zurich North America COO Barry Perkins shares how tech chiefs can repatriate skills and hone digital prowess by rethinking the onshore, nearshore, and offshore composition of their global workforce.

Latest Microsoft Licensing Updates June 2024

The latest Microsoft licensing updates for June 2024 are relatively limited, with emphasis on clarifications and additions to various product terms, including updates to Universal Licensing Terms and Privacy & Security Terms. Highlights include clarifications on the use of Microsoft Gen AI services, updates to Azure Maps restrictions, and the addition of clauses for Defender for Identity and Defender for Endpoint. Additionally, a new comparison table has been released, providing the most recent comparison data amidst anticipation for potential future updates such as M365 suites.

Microsoft Licensing Update June 2024 | Azure, M365, AI services and more - LicenseQ
This month’s latest Microsoft licensing updates, with changes to Azure, AI Services, Defender for Endpoint and more

RISE with SAP: Tips to streamline SAP Cloud licensing

SAP's cloud-first approach, highlighted by RISE with SAP and SAP S/4HANA Cloud, introduces significant changes for ECC customers, including the cessation of ECC maintenance, halted innovations, and annual maintenance fee increases. RISE with SAP aims to simplify cloud migration and support digital transformation by bundling solutions and services into a single subscription package, offering potential cost savings compared to on-premises implementation. The introduction of the Full Use Equivalent (FUE) model under RISE with SAP brings flexibility to user licensing, but careful analysis and optimization are necessary to avoid unnecessary costs and ensure alignment with actual system usage.

RISE with SAP: Tips to streamline SAP Cloud licensing
The article describes what RISE with SAP is all about, its impact on licensing and audits, and what optimization options customers should consider now.
🐛
Bugs & Exploits

Oracle WebLogic Server OS Command Injection Flaw Under Active Attack

The U.S. CISA added an actively exploited security flaw, CVE-2017-3506, affecting Oracle WebLogic Server to its Known Exploited Vulnerabilities catalog, allowing unauthorized access and complete control of vulnerable servers via OS command injection. While the specific nature of attacks wasn't disclosed, the China-based 8220 Gang has historically leveraged this vulnerability to deploy crypto-mining botnets, utilizing obfuscation techniques for stealthy payload delivery. Federal agencies are advised to apply the latest fixes by June 24, 2024, to mitigate potential threats.

Oracle WebLogic Server OS Command Injection Flaw Under Active Attack
The U.S. cybersecurity agency has added Oracle WebLogic Server Vulnerability CVE-2017-3506 to its Known Exploited Vulnerabilities catalog.

Ticketmaster hacked in what’s believed to be a spree hitting Snowflake customers

Multiple Snowflake customers, including Ticketmaster, have been hacked, with threat actors obtaining credentials through malware or purchasing them on online forums. Snowflake acknowledged the breaches and urged customers to ensure multifactor authentication is enabled on all accounts. Despite investigations by security firms Mandiant and Crowdstrike, no evidence suggests the breaches stemmed from vulnerabilities in Snowflake's platform, but concerns persist about the cumbersome nature of enabling multifactor authentication.

Ticketmaster hacked in what’s believed to be a spree hitting Snowflake customers
Researcher says Snowflake customers hit by mass scraping ... “but nobody noticed.”

Tags