December 17, 2022

Hello all,

The Red-N Weekly Security newsletter is below the callouts below.

Notable callouts this week include:

  • Patch Tuesday Microsoft and several other vendors released patches. There are goodly number of critical vulnerabilities, with some already under active exploitation. Vet the patches quickly and apply them if you are able as soon as you are able. There were a number of fixes for items lingering from prior patches. One fix was hopefully the final nail in fixing the Mark-of-the-Web flaw that allowed all sorts of bad stuff in.
  • There may be some issues with Patch Tuesday items from Microsoft, so as mentioned above, vet them carefully.
  • Citrix released patches to address RCE’s in their ADC and Gateway products
  • VMWare has released patches for a couple of critical RCE’s.
  • Fortinet has a critical RCE in their SSL-VPN. And it is being actively exploited.
  • SPNEGO an authentication mechanism is being exploited
  • Samba has issued security updates for multiple high severity vulnerabilities.
  • Uber suffered a data breach due to an attack on a vendor.
  • Apple released a new update to address an actively exploited zero-day vulnerability.
  • CISA decided that a bug Veeam patched in March is now a required update for all Gov orgs.

Just like attempting to drive a car that has a hole in a tire is fraught with issues, running a computer system with an unpatched hole will eventually result in either damage to the system, or a serious incident for the operator. Patch those holes!

Visc. Zebullon Wamboldt Pike

Headline NEWS

Other News Events of Note and Interest

For a PDF version of this week’s report, click here.

Share this with: