November 11, 2023

Hello all,

Today is Veteran’s Day in the United States, and Armistice Day in much of the world, marking the end of World War Two, on the eleventh hour, of the eleventh day, of the eleventh month. Hostilities officially ceased and the guns went silent. It would be nice to have a digital armistice day, but alas, that is not on the horizon. What is rapidly coming into view is Patch Tuesday this week, so be prepared for an incoming barrage. Meanwhile, there’s plenty of news from this past week, so let’s get to it.

The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Article 45 is ticked away inside of eIDAS 2.0, Europe’s newly proposed regulations for digital security of its citizens. However, Article 45 is severely flawed and will result in worse security and privacy if enacted. Hundreds of scientists and researchers from 39 countries have written eIDAS an open letter of opposition to this article.
  • Microsoft unleased Windows 1.0 on the world 40 years ago today. And we’ve never been the same since. That’s a bit of a stretch. It caused little more than a yawn until Windows 3.0 and Windows 3.1 were released, and then everything changed.
  • Okta had a breach recently that gave them quite a bruising in the press and financially. The reason for the breach that affected 134 organizations has been traced to an employee accessing personal items on his work computer. Let that sink in for a moment. Keep your work and personal computing separate, please.
  • QNAP is warning of critical command injection flaws. Patches have been released. So, update quickly, or take mitigating actions if you can’t update now.
  • Veeam has warned of critical bugs in Veeam One. If you are using this update now or risk compromise.

In Ransomware, Malware, and Vulnerabilities News:

  • MGM and Caesars attacks are stark examples of how social engineering is being used to defeat security. Move to FIDO2 compliant security as quickly as you’re able to help fight social engineering attacks.
  • Open AI was down or extremely slow this week due to massive DDoS attacks against them. Likewise, Cloudflare experienced its own share of DDoS this week.
  • SysAid is being actively attacked via a critical vulnerability. Patch now.

In Other News Events of Note and Interest:

  • Google Chrome has a nifty new feature. If you hover over a tab it shows you how much memory that tab is using.
  • ChatGPT received major updates this week. If you can get past the DDoS, it has some nifty new features worth checking out.

In Cyber Insurance News:

  • Business Owners lack cyber insurance knowledge. A full 20% do need guidance and education about the purpose and need of this coverage.

May your electrons all cooperate. And hopefully you can enjoy a period of calm before the storm this Tuesday when Microsoft and other organizations unleash a new slew of patches and unveil fresh vulnerabilities for bad-guys to attack.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: