November 25, 2023


Hello all,

While the flurry of notices from Patch Tuesday are now behind us, vulnerabilities, patches, exploits, and other tech excitement continues. OpenAI made headlines for themselves and Microsoft for much of the week with Sam Altman news. The dust appears to have settled now with Mr. Altman back in charge and Microsoft in a more secure position in regard to their endeavors with AI.

After the Black Friday shopping frenzy of this past week Cyber Monday is upon us. Awesome tech deals are to be found, but be very wary of scammers, spoofers, phishers, and malvertizers. They will be out in force to try to con their share of the holiday booty. Now, on to the news of the week.

The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Crypto Mining Rig found under floor of courthouse. You can’t make this stuff up. This is actually the second time I’ve seen a headline like this. Long Island, NY, had a similar problem that may have contributed to a ransomware event that Suffolk County is still attempting to recover from over 2 years later.
  • Black Friday – phishing emails were up 237% from just prior. Clearly the bad guys want to reap their share of the shopping frenzy too. Stay vigilant.
  • Broadcom has finally gotten approval from the last holdout – China – for their takeover of VMware. Now, comes the reorganizing. We’ll have to wait to see what emerges as a result.
  • Fidelity National Financial a Fortune 500 company based out of Jacksonville, FL suffered a cyber-event that forced them to shut down much of their IT Systems. The result has been that real estate closings using their services have had to be postponed or rescheduled with other companies.
  • Lenovo recalled USB-C power banks due to risk of fire. If you have one, check if it is on the recall list and if so, immediately discontinue using it. Contact Lenovo and they will ship you a free replacement.
  • Microsoft / Open AI / Sam Altman were in the news quite a bit this past week. First Sam Altman was fired by the Open AI board, then Microsoft hired him, and finally he’s back in charge at OpenAI and Microsoft now is much more entrenched in the running of Open AI.
  • Microsoft Defender bounty program. If you can find problems, you can earn up to $20k in reward from the Redmond giant.

In Ransomware, Malware, and Vulnerabilities News:

  • Huntress published a Small Medium Business (SMB) Threat Report that is excellent reading.
  • Toronto Public Library suffered a ransomware attack a month ago. They expect to begin restoring service in January.

In Other News Events of Note and Interest:

  • CISA is offering to be an MSSP to critical infrastructure organizations. Hmm…
  • NIS2 is a Network and Information Systems Directive due to come into effect in October 2024, seeks to improve cyber resilience in the European Union. In Article 21 it essentially makes any non-EU based supplier to an EU country subject to NIS2’s reporting requirements.

In Cyber Insurance News:

  • CISA has relaunched a working group on Cyber Insurance – Cybersecurity Insurance and Data Analysis Working Group (CIDAWG). The stated goal of the resurrected group is “aid in determining the most effective security tools to defend against increasingly sophisticated attacks and help improve enterprises’ security postures.”

I asked my AI overlord to help me with a holiday shopping themed poem. Here it is:

Here’s a rhyme for you, I hope it’s fun,
About holiday cybercrime, and how to shun.
Fake websites with irresistible deals,
Are often used to scam and steal.
Web-based malware, phony ads,
Free or discounted products, all bad.
Social media scams, counterfeit items galore,
Gift vouchers, cards, and free products, all with a malicious core.
To protect yourself, patch and update,
Pay attention to errors, don’t take the bait.
Use a credit card, not a debit one,
For online purchases, so you’re not undone.
If something seems too good to be true,
Be like the jolly old saint, and check twice, it’s the right thing to do.

May your shopping be safe and provide you with awesome deals galore!

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: