Hello all,
The Internet killed Black Friday for me! (For those of you not based in the USA, Black Friday is a huge shopping day right after the Thanksgiving Day holiday). I used to collect newspaper fliers, circle store opening times, plan my driving route, map out where my quarry was located in each store, so that I was as efficient as humanly possible. It was a big-game hunt that my children and I looked forward to each year. Of course, the criminal element didn’t let the shopping frenzy go unnoticed, parking lot thieves were out in force, knowing that people were going from store to store in search of treasure, leaving brand new just purchased items in their cars while they did so.
Alas, the times have changed, ending a family tradition. This year was the first year that I didn’t even bother to go out shopping. There was zero reason. Retailers advertise the entire week and make their Black Friday deals available online. It just isn’t worth losing sleep over anymore. Sure, there are some loss leaders in the stores that are only available in person, but seriously, how many larger-screen TVs or Air Fryers does a person need? And getting deals from the comfort of home, instead of freezing outside of a store waiting for it to open, is certainly significantly more pleasant and less stressful. However, the ubiquity of online shopping, and subsequent invoice and delivery notifications has created an incredible opportunity for cyber-criminals. Both the FBI and CISA are warning of increased Business Email Compromise (BEC) attacks over the holiday season. I’ve personally received no less than 5 text messages about “package deliveries” that “need” me to click a link. From parking lot to couch, criminals have also made the trek online. Stay vigilant, don’t expose your valuables and have them purloined. Onward to other cyber news of the past week.
As usual, my commentary is followed by a plethora of links to other items that are worth skimming to see if they interest you or pertain to your particular environment or of those you support.
Headline NEWS:
- 7-Zip has been revealed to have a severe vulnerability in versions below 24.07. If yours is lower, update as soon as you are able.
- FBI and CISA warn of increased risk of BEC attack during the holidays. Stay aware, always check with the sending party before opening unexpected attachments, don’t call the number in the email, call what you know is the correct number for the person, and never, ever, change financial information or send funds based solely on an email.
- HPE has patched a defect in their Insight Remote Support product. You notice that it is a “remote support” product, right? Threat actors love these. If you use this, don’t wait, and check your version. Also, follow HPE’s advice and turn on automatic updating.
- Microsoft had a global meltdown due to a failed update. The details were amazingly scant, but Big Redmond attempted to undo the changes, and their affected infrastructure ignored them. They eventually restored access by shutting down affected portions of their global network and then rolling back to the prior version. It was not a fun day for IT folks.
- QNAP has rereleased updates to fix multiple vulnerabilities, check yours for updates if you have one.
- Veritas has made patches available to fix defects in their Veritas Enterprise Vault. This is one thing you definitely don’t want compromised if a bad guy makes it into your network. Patch quickly!
- VMware has released patches for their Aria Operations product. If you use it, patch it.
- Zabbix has been found to have a SQL injection defect. This is a rather popular network and application monitor product that has wide deployment. Please update before the criminals burrow through this hole.
In Ransomware, Malware, and Vulnerabilities News:
- DEF CON is a massive cyber conference that takes place in Las Vegas, NV every year for the past 32 years. At the most recent event, a “Hacker Volunteer Army” was formed. The first blood these elite geeks will draw is to “investigate the security of six water companies based in Utah, Vermont, Indiana, and Oregon, fix any issues, and then pass the knowledge on.” Way to go!
- Blue Yonder which provides managed services to thousands of organizations worldwide was hit with a ransomware attack on November 21st. They are still attempting to recover, with the last update on their website coming over 6 days ago. Major corporations such as Starbucks, DHL, Kroger, Fred Meyer, and Proctor & Gamble are listed among their clients. Most clients had “no comment” regarding this event.
In Other News Events of Note and Interest:
- Breakthrough Material Perfectly Absorbs All Electromagnetic Waves piqued my interest, this has far reaching potential in blocking unwanted signal noise, security applications, directional targeting of radio signals, and much more.
- Uniswap, an enormous decentralized exchange for swapping crypto currencies is offering a staggering $15.5 million dollars in a bug bounty to help secure their systems. If you’ve got the skills, you could earn a serious Christmas bonus!
Musings:
Hot on the heels of Black Friday (which has turned rather gray for me) is Cyber Monday! Online retailers are banking on tech-aficionados and electronics hunting consumers to fatten their coffers to make their holiday jolly. Their online stores, shopping carts, and remote operators are standing by to take your orders. And while deals are indeed there to be found if you hunt, be wary of offers that are too good to be true, because they probably are! Remember that threat actors also have online stores, shopping carts, and operators standing by, not to take your order, but instead to steal your money.
Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Critical 7-Zip Vulnerability Let Attackers Execute Arbitrary Code
- FBI, CISA warn of heightened risk of BEC attacks during holiday season
- HPE Insight Remote Support Vulnerabilities Let Attackers Execute Remote Code
- Microsoft outage affects workers worldwide
- QNAP addresses critical flaws across NAS, router software
- Multiple Vulnerabilities In Veritas Enterprise Vault Let Attackers Execute Remote Code
- VMware Patches High-Severity Vulnerabilities in Aria Operations
- Zabbix urges upgrades after critical SQL injection bug disclosure
Ransomware, Malware, and Vulnerabilities News
- Volunteer DEF CON hackers dive into America’s leaky water infrastructure
- Over 1,000 arrested in massive ‘Serengeti’ anti-cybercrime operation
- Wanted Russian Hacker Linked to Hive and LockBit Ransomware Arrested
- Intruder Launches Intel: A Free Vulnerability Intelligence Platform For Staying Ahead of the Latest Threats
- CISA Strongly Recommends Phishing-Resistant MFA
- US, Australian cybersecurity agencies update BianLian ransomware threat, following recent attacks
- US Cyber Force Surges Global Operations Amid Rising Threats
- UN cybercrime treaty faces uncertain future under Trump administration
- China’s Cyber Offensives Built in Lockstep With Private Firms, Academia
- Linux devices hit with even more new malware, this time from Chinese hackers
- China has utterly pwned ‘thousands and thousands’ of devices at US telcos
- Microsoft credited with spotting sophisticated Chinese hack that hit telecoms including T-Mobile
- T-Mobile Disputes Claims of Chinese Hack on Customer Data
- Salt Typhoon Builds Out Malware Arsenal With GhostSpider
- Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels
- Code found online exploits LogoFAIL to install Bootkitty Linux backdoor
- Russia-linked hackers exploited Firefox and Windows bugs in ‘widespread’ hacking campaign
- DOJ: Man hacked networks to pitch cybersecurity services
- Firefox 133 Released With Fix For Multiple Security Vulnerabilities
- 20 Years Old macOS Vulnerability Allow Attackers To Gain Root Access Remotely
- Cyberattack at UK hospital prompts outpatient appointment cancellations
- Gambling tech vendor’s IT systems impacted by cyberattack
- New Elpaco Ransomware Actors Connect Via RDP To Deploy Ransomware
- Ransomware payments are now a critical business decision
- Microsoft Patches Exploited Vulnerability in Partner Network Website
- Active Directory Certificate Services Vulnerability Let Attackers Escalate Privileges
- IoT devices across the world targeted by major new botnet
- Major Cyberattack Disrupts Costa Rica RECOPE Digital Systems
- Cyber attack shuts down Hoboken, NJ government
- Huge data breach exposes over 600,000 records, including background checks, vehicle, and property records
- Ransomware hits supply chain software firm Blue Yonder ahead of Thanksgiving
- UK, US retail giants hit by ongoing disruption after ransomware attack on supply chain firm
- Starbucks vendor hit by ransomware attack, affecting pay and schedules
- International Game Technology targeted by cyberattack
- A US soldier is suspected of being behind the massive Snowflake data leak
- Growth in phishing, changes in ransomware crews mark threat landscape
- New Rockstar 2FA phishing service targets Microsoft 365 accounts
- Phishing Prevention Framework Reduces Incidents by Half
- IBM Engineering Systems Flaw Let Attackers Bypass Security Restrictions
- Skimmer Malware Targets Magento Sites Ahead of Black Friday
- Hackers abuse popular Godot game engine to infect thousands of PCs
- Hackers Can Access Laptop Webcams Without Activating LED Indicator
- New GodLoader Malware Attacking Windows, macOS, Linux, Android, & iOS Devices
- RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated Cyberattacks
- New VPN Attack Demonstrated Against Palo Alto Networks, SonicWall Products
- New NachoVPN attack uses rogue VPN servers to install malicious updates
- Zello asks users to reset passwords after security incident
Other News Events of Note and Interest
- Breakthrough Material Perfectly Absorbs All Electromagnetic Waves
- Netgate Releases pfSense Plus Software Version 24.11
- Arizona chip plants could make 2nm chips from 2028, claims TSMC
- ByteDance seeks $1.1 million damages from intern in AI breach case
- Remember James Howells Who Lost His Hard Drive With 8,000 Bitcoins Now Worth $760M? His Ex-Girlfriend Reveals It Was She Who Threw It Away
- Google Maps Navigation Ends Tragically After Three Men Drive off Unfinished Bridge
- AMD releases Windows 11 24H2 RAID driver for Ryzen 9000/7000, X870, X670, and B650
- Cloudflare Improves Systems After Data Loss Incident
- Browser Alliance is accusing Microsoft of limiting user choice with Edge browser
- Google blocked 1,000-plus pro-China fake news websites from its search results
- AWS bends to Broadcom’s will with VMware Cloud Foundation as-a-service
- Uniswap offers biggest-ever ‘bug bounty,’ promises up to $15.5 million to those who spot code vulnerabilities
- Meta plans to lay down a $10 billion subsea fiber optic cable
- Microsoft’s new Copilot AI Voice mode is now available for everyone for free
- Microsoft’s Response to Its Major Outage Is the 1 Thing No Company Should Ever Do
- Microsoft re-releases Exchange updates after fixing mail delivery
- Microsoft OneDrive’s New Feature Helps You Move Work Between Devices
- Asus, Dell confirm new issues in Windows 11 24H2 update, including shutdown bug
- New Windows Server 2012 zero-day gets free, unofficial patches
- New Windows 10 0x80073CFA fix requires installing WinAppSDK 3 times
- Windows 11 24H2 is now incompatible with USB scanning devices, too