October 28, 2023

Hello all,

This cyber week has been a somewhat normal one with the usual warnings, updates, and reports of activity by horrible people that deserve a toasty spot in hell. There are some neat new things as well, so let’s get to the report.

The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Apple has released updates for a large number of their products, not just the latest in their series. If you have iFruit, check for updates.
  • Cisco is still finding new things related to their massive hole. Apparently they’ve discovered a new zero-day that was being exploited. The number of infected devices seen on the internet has dropped, either due to them being cleaned, or the threat actors hiding themselves well. I guess we’ll see what time reveals on this. I’m sure there is more to come.
  • F5 has a vulnerability that allows remote code execution their Big-IP devices. If you have any, patch quickly.
  • Pwn2Own has just concluded in Canada with hackers exploiting 58 new zero-days. Manufacturers will be given up to 120 days to fix the flaws before they are published. Companies such as Xiaomi, Western Digital, Synology, Canon, Lexmark, Sonos, TP-Link, QNAP, Wyze, Lexmark, and HP were among the ones successfully hacked.
  • Mozilla released updates for several products, if you use anything from them, Firefox, Thunderbird, etc. check for updates.
  • VMware has released updates for vCenter for a large swath of their versions and will be back-porting to older unsupported versions. That should hint at the criticality of this issue. Check for updates for your version if you use this and apply as soon as possible.

In Ransomware, Malware, and Vulnerabilities News:

  • Google cannot catch a break. They are a big target. Fake Chrome updates are huge now, and Punycode is being used to make them look legitimate.
  • Nigerian Police – What, they have police?! Who knew? Read on. Nigerian Police have dismantled a major cybercrime ring and they are still pursuing additional lowlife scum. Yay good guys!
  • Ragnar Locker Ransomware boss was arrested in Paris, score another one for the good guys!

In Other News Events of Note and Interest:

  • Microsoft Word turned 40! Happy Birthday to the world’s most popular word processor.
  • Windows 11 Moment 4 features are now publicly available in the latest non-security update. Next month’s Patch Tuesday should push them out to the masses.

In Cyber Insurance News:

  • Self-Attestation is coming under increasing scrutiny. Companies are either falsifying insurance forms, or not keeping information timely, and it costs them dearly when a claim is made. The industry is looking to close the gap via more automated reporting.

I generally write this report while sitting out on my screen-enclosed patio, listening to the gurgling sounds of water in the pool and soft music from my entertainment system. It is an idyllic environment. Unfortunately, I do not live out in the middle of nowhere, I live in the city, so occasionally loud cars go by, a neighbor decides to mow his lawn, etc. Yet, those are expected or anticipated interruptions. I can live with those; in my mind they are planned for, and I have a newsletter continuity plan. Then there’s my neighbor, let’s call him Ryan (because that is his name). He seems to delight in things that are loud, the louder the better. One moment there is tranquil quiet peace, the next an hour or more of a minibike with no muffler running at top speed behind my house for several hours, back and forth, back and forth… Even inside the house I can hear it. Much like a DDoS-attack, it comes out of nowhere and disrupts your life. Mitigations exist, but short of moving to a new location, you have to ride it out until the attack stops. Make plans now for the inevitable unexpected interruptions. There are plenty of “Ryans” out there just waiting to spoil your day.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: