Weekly Cyber Security
News Events &Information
From sources found online in the past seven days
Hello all,
This past week most of the world took notice of Andres Freund, a mild-manner programmer who single-handedly saved the internet. No joke. He found a supply-chain attack that was in process of being stealthily slipped into millions of computers worldwide. Due to his efforts, this particular attack was thwarted. Well done sir! Upcoming this week is Patch Tuesday, I predict it will be larger than last month with at least two new zero-days from Microsoft, we’ll see how good my prognosticating skills are soon. Regarding Microsoft, the US government’s Cyber Safety Review Board (CSRB) pulled no punches this week in saying that Microsoft’s security culture is “inadequate”. There’s lots more, so let’s get to it.
The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.
Notable Callouts:
- Apache has released patches for two flaws in the HTTP server that can allow for malicious header injection and launch HTTP/2 DDoS attacks. Patch quickly.
- Google Chrome has received another zero-day update this week, following up on their update last week. Check your browser for updates. Since this now has a patch, the details of how this can be exploited will be public soon.
- Ivanti can’t catch a break. They just released updates to patch four vulnerabilities in their Connect Secure and Policy Secure Gateways. In a related note, their CEO sent an open letter to the world committing to a secure-by-design overhaul. It will be a major undertaking as some researchers have shown that the base code is rife with vulnerable code/packages. In a related note, CISA has revealed that over 100,000 organizations may have had data exposed by their own Ivanti breach.
- Microsoft, as mentioned earlier, was the subject of the Cyber Safety Review Board (CSRB) review of the Exchange hack from 2023. In the Executive Summary section it states, “The Board finds that this intrusion was preventable and should never have occurred. The Board also concludes that Microsoft’s security culture was inadequate and requires an overhaul…” and this only references the known summer 2023 hack, not the new reveal from January 2024. As a result of these numerous public failings, many organizations are now considering if they have too many eggs in one cyber-basket.
- OWASP, the Open Worldwide Application Security Project, in a wry humorous note, suffered its own security incident recently. They’d left exposed a wiki server that contained resumes for members who had joined the organization between 2006 and 2014. The server has since been secured and any exposed, cached data removed.
- T-1000 infant created by the Chinese University of Hong Kong. Seriously, they made a shape-shifting robot that can liquify and return to the original form. Have these people never watched a Terminator movie?
In Ransomware, Malware, and Vulnerabilities News:
- Panera Bread experienced a ransomware attack and has recovered after a week of downtime and complaints from customers about not getting their “unlimited sips” and earning or redeeming points. They are still in the process of restoration, but it appears that they are now able to take more than just cash payments.
- Jackson County Missouri revealed that the ransomware attack that crippled a good portion of their services was the result of a phishing email. User education is vital. Technology can only stop so much. Cyber security is everyone’s responsibility.
In Other News Events of Note and Interest:
- Broadcom’s executives say that VMware price increase complaints are “unwarranted”, that customers with two or more products now get more and now they have support. I don’t think the customers with one product appreciate that remark at all. Nor does the education sector, which is facing huge increases due to Broadcom’s elimination of non-profit discounts. Many are reporting 200% or more in increases. Not cool Broadcom. But it is a major opportunity for other virtualization vendors, if they’re able to jump on it quickly enough.
In Cyber Insurance News:
- Cyber Insurance Reduces Risk is a good article that showcases some of what are now considered standards in the security industry.
People are the problem. There are evil people intent on doing you, your systems, and/or your country harm. There are the clueless who click on everything that lights up electrons on their screen. And unfortunately, these actors in the digital cyber-drama that our world is enmeshed in affect the vast majority of innocent bystanders who had nothing to do with the attack or the enabling of the boom. However, people are also the solution. Thankfully, there are good people everywhere doing all that they can to keep the malevolent scum and their weapons of destruction out, and are doing all they can to protect and ensure that our digital world is secure, stemming back the darkness every day.
Keep the shields up. They really are out to get you.
Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News
Headline NEWS
- Apache HTTP Server Flaw Let Attackers Inject Malicious Headers
- Google fixes one more Chrome zero-day exploited at Pwn2Own
- Ivanti fixes VPN gateway vulnerability allowing RCE, DoS attacks
- Microsoft’s Shoddy Security Exposed US Official Emails in Chinese Hack
- Microsoft’s Security Chickens Have Come Home to Roost
- OWASP discloses data breach caused by wiki misconfiguration
- Scientists develop a shape-shifting robot that can liquefy
Ransomware, Malware, and Vulnerabilities News
- Microsoft employee accidentally saves global Linux meltdown from CVE-2024-3094 XZ backdoor
- Thwarted supply-chain hack sets off alarm bells across DC
- New XZ backdoor scanner detects implant in any Linux binary
- Software supply chain attack impacts repo of large Discord bot community
- Over 100K possibly impacted by Ivanti-related CISA compromise
- Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security Flaws
- US federal employee data leaked, claimed by hacker trio
- Federal government affected by Russian breach of Microsoft
- Microsoft fixes five security vulnerabilities in Edge 123
- Google fixes two Pixel zero-day flaws exploited by forensics firms
- Org Server & XWayland Hit By Four More Security Issues
- Hoya’s optics, second largest in the world, suffers debilitating cyberattack
- New HTTP/2 DoS Attack Potentially More Severe Than Record-Breaking Rapid Reset
- Attackers Abuse Google Ad Feature to Target Slack, Notion Users
- Bing ad posing as NordVPN aims to spread SecTopRAT malware
- Microsoft OneNote Files to Orchestrate Cyber Attacks
- Cyberattacks Wreaking Physical Disruption on the Rise
- UK Police launch inquiry after MPs targeted in apparent ‘spear-phishing’ attack
- Escalating malware tactics drive global cybercrime epidemic
- Mispadu Trojan Targets Europe, Thousands of Credentials Compromised
- From PDFs to Payload: Bogus Adobe Acrobat Reader Installers Distribute Byakugan Malware
- Over 92,000 exposed D-Link NAS devices have a backdoor account
- Linux Kernel Flaw-Attackers Gain Full Root Access: PoC Published
- Latrodectus Malware: This Spider Bytes Like Ice
- Hotel Self Check-In Kiosks Exposed Room Access Codes
- China-linked Hackers Deploy New ‘UNAPIMON’ Malware for Stealthy Operations
- Chinese Hackers Hijack Swedish Routers to Launch Cyber Attacks
- UnitedHealth Hack Leaks 6 TB of User Data
- SurveyLama data breach exposes info of 4.4 million users
- Cyberattack hits Omni Hotels systems, taking out bookings, payments, door locks
- Remote desktop protocol attacks are becoming a huge threat to businesses everywhere
- Panera Bread week-long IT outage caused by ransomware attack
- Birmingham, AL computer outage continues, city using paper time sheets
- Hernando County, FL falls victim to hacking attack, some services offline
- Jackson County, MO says ransomware attack took down tax, license systems
- Official says phishing email led to ransomware attack in Jackson County
- Sprawling Sellafield Nuclear Waste Site Prosecuted for Cybersecurity Failings
- Shopping platform PandaBuy data leak impacts 1.3 million users
- Cambodia: Hundreds of Indians rescued from cyber-scam factories
- Yacht retailer MarineMax discloses data breach after cyberattack
- Oil & Gas Sector Falls for Fake Car Accident Phishing Emails
- Fake AI law firms are sending fake DMCA threats to generate fake SEO gains
- Open-source voice cloning model “Voice Craft” steamrolls over OpenAI’s ethical concerns
- Urgent Security Alert! Hackers Hijacked Notepad++ Plugin
- Data Confirms A Surge In WordPress Vulnerabilities
- Ukrainian cybersecurity official reveals structure of Russian hacker groups
- XSS Vulnerability Affects Beaver Builder WordPress Page Builder
- XSS flaw in WordPress WP-Members Plugin can lead to script injection
- Critical Security Flaw Found in Popular LayerSlider WordPress Plugin
- Visa warns of new JSOutProx malware variant targeting financial orgs
- Malicious Visual Studio Code Extensions Stealing Users’ Sensitive Data
- Security Advisory YSA-2024-01 – Yubico, update your YubiKey Manager GUI
- WiFi WPS vulnerability: disable it, or else
Other News Events of Note and Interest
- Cool Tool: PowerToys 0.80 is out with Desired State Configuration support and new Peek features
- Cool Tool: WinToHDD 6.5
- Cyber Volunteer Resource Center
- US gov’t commits $3.6M to address cybersecurity skill shortage
- CISA Unveils Critical Infrastructure Reporting Rule
- Considerations for Operational Technology Cybersecurity
- Broadcom execs say VMware price, subscription complaints are unwarranted
- Education sector facing huge VMware cost increases after Broadcom ends discounts
- Ivanti commits to secure-by-design overhaul after vulnerability nightmare
- Our Commitment to Security: An Open Letter from Ivanti CEO Jeff Abbott
- Cisco completes Splunk acquisition
- NIST Wants Help Digging Out of Its NVD Backlog
- CISA faces resource challenge in implementing cyber reporting rules
- Google Domains controls are moving over to Squarespace now
- Number of Chinese Devices in US Networks Growing Despite Bans
- 76% of consumers don’t see themselves as cybercrime targets
- FFmpeg 7.0 “Dijkstra” Released with Important AArch64 Optimizations for HEVC
- German state, Schleswig-Holstein, ditches Windows, Microsoft Office for Linux and LibreOffice
- Google now blocks spoofed emails for better phishing protection
- Google says it will destroy browsing data collected from Chrome’s Incognito mode
- New Chrome feature aims to stop hackers from using stolen cookies
- New York City payroll website has been down for a week, following phishing attack
- Linux Kernel 6.7 Reaches End of Life, Users Urged to Upgrade to Linux Kernel 6.8
- US wields the banhammer against sanctions-compliant Nvidia RTX 4090D ‘Dragon’
- Malaysia emerges as a hotspot for chip firms amid U.S.-China tech war
- China aims to break chokehold of US chipmaking sanctions
- The US wants ASML to stop servicing its advanced chipmaking tools in China
- Chinese chipmaker gains traction replacing American processors – Longsoon ships 10,000 chips into schools
- You can now hop on ChatGPT without needing an account
- Ubuntu 24.04 Beta Delayed Due to Security Issue
- MSI admits faulty heatsink design for cracked Z790 chipsets, begins replacing faulty units
- Recent Windows updates break Microsoft Connected Cache delivery
- Microsoft fixes Windows Sysprep issue behind 0x80073cf2 errors
- Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack
- Microsoft warns Gmail blocks some Outlook email as spam, shares fix
- Microsoft splits up the Teams and Office apps worldwide, following EU split
- Microsoft fixes Outlook security alerts bug caused by December updates
- Microsoft announces prices for Windows 10 Extended Security Updates
- Microsoft 365 launches High Volume Email in public preview with no per-minute message limits
- Windows 11 Moment 5 (KB5035942) causing install issues, BSOD, black desktop screen
- Windows 11 24H2 LTSC images leak ahead of official announcement
- What’s New in WordPress 6.5 (Features and Screenshots)