Weekly Cyber Security
News Events &Information
From sources found online in the past seven days
Hello all,
After the rather grueling CrowdStrike incident that started a week ago on Friday for many in the IT industry, I’m sure that they were happy to see that the latter half of this past week was somewhat calm. That’s not to say that nothing happened, just nothing that show-stopping dramatic. There was still a lot to know and to notice. So, onward.
The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.
Notable Callouts:
- Acronis, has warned about a critical vulnerability that allows for remote code execution (RCE) in Acronis Cyber Protect (ACI) “a unified multi-tenant platform that combines remote endpoint management, backup, and virtualization capabilities and helps run disaster recovery workloads and store enterprise backup data securely.” If you use this, patch now as it is under active exploitation.
- Docker has updated to patch a critical vulnerability in their authorization plugin (AuthZ) system that allows for RCE. This flaw was originally patched in January 2019. Unfortunately, the fix didn’t make it into subsequent versions. Yep, for 5 years this was open to exploitation. If you use Docker, check now for updates!
- Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers have been found to allow RCE. There is no fix as these routers are End-of-Life (EOL). If you continue to use them it is not a matter of if, but when you will be compromised, replace them ASAP!
- Microsoft threw the European Union (EU) under the bus for the global CrowdStrike outage. It is reported that they said that a 2009 agreement with the EU opened access to the Windows OS to security providers in a way which made the CrowdStrike BSOD possible. The EU responded later in the week stating that was untrue and that “Microsoft is free to decide on its business model. It is for Microsoft to adapt its security infrastructure to respond to threats in line with EU competition law. Additionally, consumers are free to benefit from competition and choose between different cybersecurity providers.” That doesn’t sound like a very solid denial to me, but what do I know?
- Okta has a browser plugin that is vulnerable to cross site scripting (XSS) attacks. Update to the latest version to mitigate this attack vector.
- Service Now has a critical RCE that is being actively used to steal credentials. A patch was made available on July 10, and on July 11 a researcher released proof-of-concept (PoC) code to exploit the vulnerability. Naturally, the slavering evil hordes jumped on it and began active exploitation before many organizations self-hosting were even aware of the flaw and update. Note, hosted instances were updated in May to plug this hole.
- Telerik Report Server by Progress Software, has an RCE in versions 10.1.24.514 and earlier. This is being actively exploited, if you use it patch immediately and check logs for exploitation.
In Ransomware, Malware, and Vulnerabilities News:
- CrowdStrike was top of mind for many in the IT industry last week, and for many in the dark dens of evil doers as well. Hundreds of fake CrowdStrike domains have popped up with “helpful advice”, which will download and install malicious software. Likewise phishing and malvertising campaigns were rampant. Don’t take the bait.
- Meta removes 63,000 accounts linked to sextortion. Evil people taken offline for at least a bit. This same article lists some additional wins for the good guys! With so much negative out there, it is important to celebrate the wins!
- Secure Boot is completely broken on 200+… this is an emerging story that bears watching. The implications are pretty severe. We defenders need to apply updates as soon as they become available and are vetted as safe.
In Other News Events of Note and Interest:
- CrowdStrike obviously continued to make news this past week. There are over a dozen links in this section that discuss various aspects of this global failure. Additionally, on the Buffalo-Plaid Breakfast show this Friday, my co-host Jeremy and I discussed the CrowdStrike Apocalypse.
- Alexa may soon have an AI sibling that is accessible behind a paywall. I tend to agree with the article’s author. I suspect that Amazon subscribers will be reluctant to pay additional fees, especially since the base price of Prime has continued to steadily increase over the past few years. But we’ll see.
In Cyber Insurance News:
- Companies Ready Insurance Claims Over CrowdStrike Outage. The total global economic impact was estimated at the start of the week to end up at around $5.4 billion dollars. While high, insurers and re-insurers (the guys that underpin the smaller companies) are confident that they have the resources to weather this storm, especially considering that claims will be capped at whatever limits a policy has on it.
The Summer Olympic Games have started in Paris France and I’m happy to report that for the most part the good guys are winning! No, I’m not talking about my favorite nation or even athlete, I’m talking about the security professionals that are defending what is likely the most interconnected games ever. There’s only been one known data breach, and it was likely an insider job. So, cyber-warrior athletes, I salute you! May you win Gold!
Keep the shields up. They really are out to get you.
Viscount Jan Broucinek
Red-N Weekly Cyber Security News
Headline NEWS
- Acronis warns of Cyber Infrastructure default password abused in attacks
- Critical Docker Vulnerability Lets Hacker Bypass Authentication
- Cisco VPN Routers Flaw Let Attackers Execute Remote Code
- Docker fixes critical 5-year old authentication bypass flaw
- Microsoft says EU to blame for the world’s worst IT outage
- Okta Browser Plugin Vulnerable To Cross-Site Scripting Attacks
- Critical ServiceNow RCE flaws actively exploited to steal credentials
- Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk
Ransomware, Malware, and Vulnerabilities News
- Two Russians sanctioned over cyberattacks on US critical infrastructure
- CBI and FBI jointly bust global cyber fraud racket, 43 arrested
- CrowdStrike ‘Updates’ Deliver Malware & More as Attacks Snowball
- Beware of fake CrowdStrike domains pumping out Lumma infostealing malware
- Chrome 127 Patches 24 Vulnerabilities
- Secure Boot is completely broken on 200+ models from 5 big device makers
- CISA Warns of Exploitable Vulnerabilities in Popular BIND 9 DNS Software
- TikTok sent sensitive data on U.S. users to ByteDance in China, DoJ says
- Patched Microsoft Defender flaw still being used to deliver information-stealing malware to vulnerable machines
- French Authorities Launch Operation to Remove PlugX Malware from Infected Systems
- Breach Roundup: ICANN Warns .top Domain About Phishing
- Biggest-ever leak of digital pirates: 10 million exposed by Z-Library copycat
- French cybercrime unit enlisted to remove leaked private data on Israeli athletes
- FBCS data breach impact now reaches 4.2 million people
- Meta Removes 63,000 Instagram Accounts Linked to Nigerian Sextortion Scams
- Crooks Bypassed Google’s Email Verification to Create Workspace Accounts, Access 3rd-Party Services
- Ferrari exec foils deepfake plot by asking a question only the CEO could answer
- Hackers Leak Documents From Pentagon IT Provider Leidos
- Hackers Abuse Cloudflare WARP To Hijack Cloud Services
- Hackers Exploited a PC Driving Sim to Pull Off Massive Disney Data Breach
- Real estate wire fraud: Silicon Valley exec had $400,000 stolen
- BreachForums v1 hacking forum data leak exposes members’ info
- Greece’s Land Registry agency breached in wave of 400 cyberattacks
- Cyber attacks on shipping rise amid geopolitical tensions
- Data breach exposes US spyware maker behind Windows, Mac, Android and Chromebook malware
- Ransomware ecosystem fragmenting under law enforcement pressure and distrust
- Russian ransomware gangs account for 69% of all ransom proceeds
- Town of Summerville, SC targeted in ransomware-based cyberattack
- Phone lines down in multiple courts across California after ransomware attack
- Columbus hit by cybersecurity ‘incident’
- Russia’s shadow war against Europe has begun as cyber attacks abusing Microsoft infrastructure increase
- Security Firm Discovers Remote Worker Is Really a North Korean Hacker
- North Korean charged in ransomware attacks on American hospitals
- North Korean hacking group makes waves to gain Mandiant, FBI spotlight
- US, allies say North Korean hackers steal military secrets
- Goodbye? Attackers Can Bypass ‘Windows Hello’ Strong Authentication
- Check Point Research Reports Highest Increase of Global Cyber Attacks Seen in Last Two Years
- Nvidia Patches High-Severity Vulnerabilities in AI, Networking Products
- Telegram zero-day for Android allowed malicious files to masquerade as videos
- Malicious npm Packages Found Using Image Files to Hide Backdoor Code
- VMware ESXi servers targeted by new Linux ransomware variant
- Burglars are jamming Wi-Fi security cameras — here’s what you can do
- WhatsApp for Windows lets Python, PHP scripts execute with no warning
Other News Events of Note and Interest
- Cool Tool: Sniffnet 1.3.1
- Cool Tool: Sandboxie 1.14.5 Plus / Classic 5.69.5
- Cool Tools: Sysinternals Suite 2024.23.07
- Linux Mint 22 “Wilma” Is Now Available for Download
- Firefox 128.0.3 fixes the problem with websites not loading, on-screen keyboard, and more
- Apple Maps launches on the web to take on Google
- AMD releases new chipset driver for Windows 10 and 11
- AT&T failed to test disastrous update that kicked all devices off network
- Amazon’s paid Alexa is coming to fill a $25 billion hole dug by Echo devices
- Arc Browser is getting native ad blocker, tracking prevention, and more
- iFixit CEO takes shots at Anthropic for ‘hitting our servers a million times in 24 hours’
- US regulator privately finds weak risk-management at half of large banks, Bloomberg reports
- ECB finds ‘shortcomings’ in banks’ ability to cope with cyber attacks
- OpenAI faces bankruptcy within a year, projecting $5B losses
- Oracle’s Java pricing brews bitter taste, subscribers spill over to OpenJDK
- Switzerland now requires all government software to be open source
- China details expanded law on state secrets, eyeing data security
- Deleted GitHub data is forever accessible to anyone, researchers claim
- Fortune 500 companies loss $5.4B in CrowdStrike outages: report
- Kaspersky says Uncle Sam snubbed proposal to open up its code for third-party review
- How Microsoft, CrowdStrike IT outage is hitting global supply chain
- CrowdStrike crash showed us how invasive cyber security software is. Is there a better way?
- CrowdStrike offers a $10 apology gift card to say sorry for outage
- CrowdStrike faces backlash as ‘thank you’ gift cards are blocked
- Massive CrowdStrike Tech Outage Highlights Global Vulnerabilities
- CrowdStrike could have an EU-sized data problem on its hands
- European Commission denies responsibility for massive Microsoft IT outage
- CrowdStrike CEO to testify about massive outage that halted flights and hospitals
- CrowdStrike CEO says 97% of Windows sensors are back online
- CrowdStrike Falls Further While Rivals Extend Gains After Outage
- CrowdStrike: the massive companies you’ve never heard of with a hidden grip on our lives
- Prior to Microsoft Meltdown, CrowdStrike Exec Warned of ‘Single Point of Failure’
- S. regulators are investigating why Delta Air Lines failed to recover as quickly as other airlines
- How Microsoft helped clean up CrowdStrike’s mess
- Microsoft calls for Windows changes and resilience after CrowdStrike outage
- Google scraps plans to kill third-party cookies in Chrome
- Google fixes Chrome Password Manager bug that hides credentials
- Solo to squad: AI workers will be able to talk to each other by 2025
- Intel says it has found the issue causing 13th and 14th Gen CPUs to crash
- VMware sends vSphere 7 into extra time by extending support for six months
- Explaining Microsoft’s new checkpoint updates for Windows 11
- Windows 10 KB5040525 fixes WDAC issues causing app failures, memory leak
- Windows 11 strikes again with annoying pop-up that can’t be disabled
- Windows 11 KB5040527 update fixes Windows Backup failures
- Windows July security updates send PCs into BitLocker recovery
- Microsoft updates Windows 11 23H2 and 22H2 initial setup (OOBE) with KB5041655
- Microsoft Backtracks: Office 365 Connector retirement delayed after developer outcry
- Microsoft has delayed a previously announced hardware requirement change for Edge
- Microsoft is trying to improve browsers like Edge and Chrome by tackling annoying video playback issues
- July Windows Server updates break Remote Desktop connections
- WordPress Releases 6.6.1 To Fix Fatal Errors In 6.6
Cyber Insurance News
- Insurers to see limited hit from CrowdStrike disruption, Fitch says
- Companies Ready Insurance Claims Over CrowdStrike Outage
- CrowdStrike losses and warning from Warren Buffett on cyber insurance
- Cyber Insurance Market Evolves as Threat Landscape Changes