November 4, 2023

Hello all,

Happy November all! This week was somewhat quiet until Cisco threw out a bunch of vulnerability updates. There are quite a few other significant and interesting items, so let’s get to them.

The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Atlassian has published warnings and updates for a critical Confluence Data Center and Server vulnerability.
  • Cisco unveiled 27 vulnerabilities in Adaptive Security Appliance (ASA), Firepower Management Center (FMC), and Firepower Threat Defense (FTD) products. Additionally, Cisco released updates for AnyConnect SSL/TLS VPN connections and urges updating asap.
  • Microsoft Windows 11 Pro turns on BitLocker drive encryption by default, a good thing. Unfortunately, Microsoft opted for software encryption instead of using hardware, so up to a 45% reduction in SSD performance may result. Windows 11 23H2 has now been unleased on the world. The ISO can be downloaded directly from Microsoft.
  • Siemens and Microsoft are collaborating on integrating Microsoft’s AI into Siemens’ robots, anticipating huge productivity gains as machine learning optimizes factory functions. Why do I have images of a T800 from the movie Terminator flashing in my mind?

In Ransomware, Malware, and Vulnerabilities News:

  • Email phishing attacks are up 1,265% since the introduction of ChatGPT. Wow!
  • Domains ending in .US are being used as URL shorteners for malicious purposes. I received one this week via SMS. Stay vigilant.
  • Apache ActiveMQ servers are being actively targeted by malactors. If you have this exposed to the internet, patch immediately!

In Other News Events of Note and Interest:

  • FTC has put out new requirements for non-bank entities that deal with finances. They impact a huge swath of companies. It is worth your time to evaluate whether your compliance is expected, and to take appropriate action.
  • Brave, the company behind the browser of the same name has given birth to a privacy focused AI named Leo. It is integrated into their browser.

In Cyber Insurance News:

  • Many SMEs have a gap in coverage. Check your policies to verify you understand what is and isn’t covered.

One item from this week’s news warrants a special callout. ServiceNow published information about how a misconfiguration could result in “unintended access” to data. Further, the configuration mentioned has existed since 2015. There have been numerous news reports of companies breached recently that resulted in connected companies suffering exfiltration or worse. All of us should be asking how many vendors do I integrate with that have access to my data or I have access to theirs? Is it secure? What are their security practices? What happens when one side is breached? Do I have a plan for that eventuality?

Unfortunately, cybersecurity is mountainous terrain, and it isn’t possible to fly under the radar. We must have adequate defenses to fly in our environment.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: