December 9, 2023


Hello all,

There are a few rather severe items to be aware of this week, called out below. And this coming Tuesday is Patch Tuesday for Microsoft and a number of other vendors. Traditionally, December’s release has held fewer updates than other months. Let’s hope the trend continues. And please computing world, no Log-for Shell scale surprises at the start of the Christmas holiday this year.

The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Atlassian has released updates for four of their products; three of the flaws could lead to Remote Code Execution, so patch quickly if you use this.
  • Bluetooth has a critical flaw dubbed BLUFFS that exists in pretty much every mobile implementation, Android, Apple, and Linux. If you have a vulnerable device, a threat actor within 33 feet (10 meters to the rest of the world) could conduct an RCE against the device. It will be up to the vendors to patch this flaw. If your device cannot get updates, you should consider turning Bluetooth off, or replacing your device. I have personally just replaced my device as a result of this new serious revelation.
  • Google Drive version 84 caused files to disappear for a subset of users (as reported last week). Google has now published guidance on retrieving the files.
  • UEFI LogoFAIL firmware attack. We’d reported on this item last week, but it bears repeating as the tech industry took active notice this week. Watch for updates from your device manufacturers and apply them quickly. It won’t be long until some dirtbag looking to spoil your day finds a way to chain a Privilege Escalation flaw and take advantage of LogoFAIL to install persistent and nearly undetectable malware and backdoors.
  • WordPress is in the news quite frequently. This week there are two headlining items. The first is that a very official looking and well-crafted fake advisory being spammed out is fooling admins into installing a backdoor into their sites. The second is an actual issue with WordPress itself that requires an immediate update or action to mitigate an RCE flaw.

In Ransomware, Malware, and Vulnerabilities News:

  • USPS – United States Postal Service scams are abounding this year via email and text message. While USPS will send you delivery notifications, if you’ve requested them, they will never send you a link in the message. Don’t fall for the click-bait.

In Other News Events of Note and Interest:

  • AI can recreate images from human brainwaves. That headline sounds like science fiction, but it is rapidly becoming reality. Researchers have been able to reproduce images with up to 75% accuracy from just brainwaves. It seems that it is only a matter of time when computers will actually be able to read your thoughts. We are living in strange and exciting times!

In Cyber Insurance News:

  • Cyber-Attacks are More Likely Than Fire or Theft, businesses are 67% more likely to experience a cyber incident than a physical theft and almost five times as likely to have an attack as a fire. Among SMB’s, only 17% have cyber coverage. Clearly SMB’s need to be better educated on the risks that face them.

Happy Hanukkah to our Jewish readers! And to all of our readers, may this Holiday Season bring you much light in this world filled with so much cyber darkness.

In closing, I present a video created by Network PeopleTwas The Week Before Christmas (Cyber Security Edition)”, narrated by Tampa Bay’s Al Reuchel. It bears an important and timely message for all to take to heart. And, as the video conclusion states, “Have a cyber-safe holiday”.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: