December 24, 2022

Hello all,
Merry Christmas, Kwanza, Festivus, Hanukkah, Happy Holidays, and Happy New Year!

The Red-N Weekly Security newsletter is below the callouts below. Just because we are celebrating holidays does not mean that the dirt-bags out there are taking a break. Notable callouts from this week include:

  • Patch Tuesday fallout is now in process. There have been several issues identified, with most having received fixes, work-arounds, or roll-backs.
  • Microsoft Exchange Servers are under active exploitation for the OWASSRF vulnerability that was patched via the November Exchange updates. The mitigations that were in place prior to the patch being released are not enough any longer. The patch MUST be applied.
  • LastPass continues to reveal new information about the breach they suffered. The news is NOT good. If you didn’t have a sufficiently secure Master Password, you need to immediately reset it, and all passwords that you care about that are in your vault.
  • Passwordstate Enterprise Password Manager has a critical security flaw.
  • Comcast Xfinity accounts have been hacked despite having 2FA enabled. Suspicions are that the web authentication portal has a major hole allowing bypass.
  • January 2023 marks the end of Basic Authentication for Microsoft Exchange Online. If you have apps or functions using it, beware.
  • In a surprising announcement, due to ever increasing malicious ads found on legitimate websites, the FBI is recommending that consumers install ad-blockers.
  • What can we say about Rackspace… Hopefully you didn’t have hosted Exchange with them. It is increasingly looking like Hosed Exchange. A little glimmer of hope for the hosed came on Thursday when Rackspace announced that they’ve recovered 50% of their customer data and were making PST files available for download.

A DDoS attack is similar to holiday meals. You have one at your in-laws, one at your home, one at your parents home, and to top that off, another one at your kid’s home. Your brain shuts down and all you want to do is lay back and moan that you can’t take another bite. The solution is to carefully monitor what you allow in and push aside anything that would overwhelm your system.

Visc. Zebullon Wamboldt Pike

Headline NEWS

For a PDF version of this week’s report, Click Here.

Share this with: