December 23, 2023


Hello all,

Welcome to the penultimate edition of the Red-N Weekly Cyber Security News for 2023. While not an extreme week, there have been a few large newsworthy items along with the usual morass of evil people doing nefarious things.

The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Apple leads the news with security updates for most of their products. A large number of items were addressed, so check and update your iFruit if you have it.
    Apple Watch sales were stopped in the US due to them losing a patent infringement suit. It couldn’t have come at a worse time as it will cost Apple an estimated $300-$400 million in holiday sales.
  • ALPHV aka Blackcat ransomware group had large chunks of their infrastructure infiltrated and subsequently seized by the FBI. One immediate positive result was that at least 300 decryptors were made available by authorities to victims of the dirtbag alpha-cats. Undaunted, the malevolent, evil, subhuman, criminals reappeared on the dark web within a few days and upped the ante by declaring that they would now attack critical infrastructure, including “nuclear reactors”. I’m not sure if the scum realize that they just publicly declared that they are terrorists. And as such they’ve painted a much larger target on themselves.
  • Google patched the 8th critical vulnerability for 2023 in Google Chrome. This one is in the WebRTC framework which is used by many other browsers, prompting them to update this past week as well. Check for updates in your browsers to patch this buffer overflow issue.
  • First American Financial one of the nation’s largest title insurance and settlement services for real estate companies and mortgage providers has shut down nearly all internet facing connections due to a “cybersecurity incident”. If you were expecting to close on real estate this holiday season, you may experience delays due to increased activity at other firms needing to handle the offload from First American.
  • SEC the Securities and Exchange Commission’s new reporting rules for Cyber Events are now in effect. Publicly traded companies must report cybersecurity incidents to the SEC on a Form 8-K within four business days.
  • QNAP announced on Dec 7 that the VioStor NVR (Network Video Recorder), which has flaws currently being exploited, was patched in version 5.x of QNAP’s software, which has been our for nearly a decade. Patch your stuff people!

In Ransomware, Malware, and Vulnerabilities News:

  • 10 Essential Insights from the Microsoft Digital Defense Report makes for excellent reading. The number one finding is that 99% of attacks are preventable with basic security hygiene such as MFA, and timely updates to software and firmware.
  • Xfinity had a data breach that affected 36 million people. That’s more than the population of a good number of US states – Wow!

In Other News Events of Note and Interest:

  • Microsoft is now hosting Oracle in Azure. The sheer volume of datacenter capacity being engineered for this effort has made Microsoft Oracle’s largest customer. I think hades just got a lot chillier.

In Cyber Insurance News:

  • NordVPN now offers cyber insurance. Yep, the VPN service is bundling insurance with their proxy services. It seems to be a good deal from what I have been able to deduce.

Robert Cioffi, co-founder and CTO of Progressive Computing in New York was a victim of the Kaseya VSA REvil attack on July 2, 2021 that encrypted hundreds, if not thousands, of service providers and their clients’ devices. He is a great communicator and the story is well worth reading. However, I bring him up for a different reason. He has gifted us with a cyber take on a holiday classic. Here is a link to his, “It was the week before Christmas”. Enjoy!

May your tech toys all work, and come with batteries included. Merry Christmas to you and yours if you celebrate this blessed holiday. To the rest, may this be a calm week for you.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: