The ITAM Roundup: 6/9/24
Microsoft makes Windows Recall opt-in, secures data with Windows Hello
Microsoft updates Recall for Copilot+ PCs to be more secure by making it opt-in and requiring users to prove their presence via Windows Hello before enabling and accessing Recall. Additionally, Recall's search index database receives enhanced decryption protection through Windows Hello Enhanced Sign-in Security (ESS), ensuring data remains encrypted until authenticated. These privacy and security updates will be implemented when Recall (preview) ships on June 18, aligning with Microsoft's recent commitment to prioritize security.
Announcing FOCUS support for OCI cost reports to make multicloud FinOps easier
Oracle Cloud Infrastructure (OCI) announces support for the FinOps Open Cost and Usage Specification (FOCUS), aiming to standardize cost reports across cloud providers and facilitate multicloud FinOps practices. FOCUS provides a common format for cost and usage datasets, enabling efficient allocation, analysis, and optimization of cost data across different cloud providers. OCI offers supplemental cost reports in the FOCUS schema, making it easier for users to understand and manage their cloud costs programmatically or through the console.
VMware Tools End of Life
VMware Tools version 10.3.x is reaching its end of life on June 30, 2024, necessitating an upgrade to ensure continued support and access to security patches. VMware Tools is essential for managing virtual environments, providing functionalities such as message exchange, OS customization, and time synchronization between host and guest machines. Following VMware's Enterprise Infrastructure Policy, versions receive 5 years of general support followed by 2 years of technical guidance, during which only low-severity issues are addressed, emphasizing the importance of staying updated to maintain security and functionality.
Microsoft Makes $3.2B AI Bet on Swedish Data Centers
Microsoft is investing $3.2 billion in AI and cloud facilities in Sweden, marking its largest infrastructure investment in the Nordic country, with plans to add 20,000 GPUs across three data centers. The move aims to leverage Sweden's green energy resources and cements Microsoft's presence in the nation while committing to training 250,000 individuals in essential AI skills. The investment reflects Microsoft's belief in Sweden's potential for AI innovation, with the Nordic region attracting big energy users like Meta Platforms and Alphabet due to its abundance of clean energy.
SAP to acquire digital adoption platform WalkMe for $1.5B
WalkMe, founded in Israel in 2011 and now based in San Francisco, initially focused on simplifying website navigation but evolved to offer both consumer and enterprise solutions, including in-app guidance and user behavior insights. As part of its enterprise push, WalkMe automates contextual support within applications, a feature SAP views as valuable for its own enterprise customers. Despite fluctuations in valuation post-IPO, WalkMe's recent strong earnings and the introduction of WalkMeX, an AI-powered copilot, have contributed to its shares rising by 25% in two weeks, prompting SAP's acquisition interest, aligning with its focus on supporting end users in software transformations.
Refactoring your IT sourcing strategy for digital success
Perkins emphasizes the strategic importance of transitioning digital operations in-house, despite potential increases in labor costs, as outsourced solutions may not adequately protect or transform the organization. Bringing peers along in the workforce transformation journey requires delivering messages in business terms, highlighting benefits like cost advantages and improved decision-making, while involving IT staff in setting future roadmaps to manage evolving technology effectively.
Latest Microsoft Licensing Updates June 2024
The latest Microsoft licensing updates for June 2024 are relatively limited, with emphasis on clarifications and additions to various product terms, including updates to Universal Licensing Terms and Privacy & Security Terms. Highlights include clarifications on the use of Microsoft Gen AI services, updates to Azure Maps restrictions, and the addition of clauses for Defender for Identity and Defender for Endpoint. Additionally, a new comparison table has been released, providing the most recent comparison data amidst anticipation for potential future updates such as M365 suites.
RISE with SAP: Tips to streamline SAP Cloud licensing
SAP's cloud-first approach, highlighted by RISE with SAP and SAP S/4HANA Cloud, introduces significant changes for ECC customers, including the cessation of ECC maintenance, halted innovations, and annual maintenance fee increases. RISE with SAP aims to simplify cloud migration and support digital transformation by bundling solutions and services into a single subscription package, offering potential cost savings compared to on-premises implementation. The introduction of the Full Use Equivalent (FUE) model under RISE with SAP brings flexibility to user licensing, but careful analysis and optimization are necessary to avoid unnecessary costs and ensure alignment with actual system usage.
Oracle WebLogic Server OS Command Injection Flaw Under Active Attack
The U.S. CISA added an actively exploited security flaw, CVE-2017-3506, affecting Oracle WebLogic Server to its Known Exploited Vulnerabilities catalog, allowing unauthorized access and complete control of vulnerable servers via OS command injection. While the specific nature of attacks wasn't disclosed, the China-based 8220 Gang has historically leveraged this vulnerability to deploy crypto-mining botnets, utilizing obfuscation techniques for stealthy payload delivery. Federal agencies are advised to apply the latest fixes by June 24, 2024, to mitigate potential threats.
Ticketmaster hacked in whatâs believed to be a spree hitting Snowflake customers
Multiple Snowflake customers, including Ticketmaster, have been hacked, with threat actors obtaining credentials through malware or purchasing them on online forums. Snowflake acknowledged the breaches and urged customers to ensure multifactor authentication is enabled on all accounts. Despite investigations by security firms Mandiant and Crowdstrike, no evidence suggests the breaches stemmed from vulnerabilities in Snowflake's platform, but concerns persist about the cumbersome nature of enabling multifactor authentication.