We’re aware that there have been hoax bomb threats sent to multiple New Zealand schools. Schools that use N4L’s Email Protection service (provided by Proofpoint) may have had this email intercepted and quarantined, however email filtering happens in multiple ways....
Microsoft 365 service degradation
We’re aware of a global issue impacting multiple Microsoft 365 services, which may result in degraded functionality or an inability to access certain features for some schools. Microsoft has confirmed that recovery efforts are underway and they are currently refining...
Ruckus Cloudpath upgrade to version 6.0 R5
During the July school holidays we’re upgrading the Ruckus Cloudpath system to version 6.0 R5. This is a security upgrade to patch against known threats and there is no change for users. It will be carried out by N4L in tranches on 6, 7, 8 and 9 July (4pm to 11:30pm)...
Palo Alto GlobalProtect VPN vulnerability
We’re aware of a critical vulnerability in Palo Alto’s GlobalProtect VPN application used under our Remote Access solution. If exploited, a remote attacker could connect to school networks as a VPN user - you can find more information in Palo Alto’s advisory. It’s...
Advisory: PAN-OS vulnerability impacting Palo Alto User-ID Authentication Portal
We’re aware of a critical vulnerability (CVE-2026-0300) affecting the User-ID Authentication Portal (Captive Portal) in Palo Alto’s PAN-OS software, which is a web-based login page that enables user identification for unknown traffic on a network. The vulnerability...
IMPORTANT: Update to GlobalProtect setting
N4L has made a change to the GlobalProtect settings, which will affect users using the GlobalProtect VPN client to log in remotely. Previously, GlobalProtect was configured with an “always on” setting, which meant it automatically reconnected to the school firewall...
Advisory: Microsoft SharePoint vulnerability
We’re aware of a global issue affecting Microsoft SharePoint services, which could allow a remote unauthenticated attacker to access your server. Systems impacted: Microsoft SharePoint Enterprise Server 2016 - 16.0.0 to 16.0.5535.1001 Microsoft SharePoint Server 2019...
Advisory: AirSnitch wireless vulnerability impacting RUCKUS products
We’re aware of the AirSnitch vulnerabilities present in wireless networking equipment from multiple vendors, including RUCKUS. To exploit the vulnerability, an attacker needs a connection to the wireless network they’re targeting. This would require the attacker to be...
Advisory: Increased DoS and brute force activity
The National Cyber Security Centre (NCSC) is advising organisations to be increasingly vigilant, following an increase in denial of service (DoS) and brute forcing activities in relation to the situation in Iran. Denial of service is an attempt to make an online...
Advisory: Getting ready for the new year: Secure Access device enrolment tips
As we head into a new school year, we want to help you get your school’s unmanaged and personal devices ready for the N4L Secure Access network. Prerequisite: ensure a smooth transition, please note that school Google or Microsoft credentials are required for...