January 14, 2023

Hello all,
The Red-N Weekly Security newsletter is below the Notable Callouts.

Notable Callouts:

  • Fortinet has warned of a VPN flaw that is being actively exploited
  • Microsoft released a Windows Defender updated that triggered ASR to delete Windows shortcuts and some applications. It has been nicknamed – ASRmageddon.
  • Patch Tuesday was last week. There are nearly 100 items that Microsoft patched along with Adobe and other vendors. There are several zero-days that need quick attention.
  • Cisco has some EoL routers that have auth bypass bugs. They need to be replaced.
  • Linux Control Web Panel has a critical RCE that is being exploited.
  • Auth0 has released a fix for an RCE in JsonWebToken library that is used by 22,000 projects.
  • AMD has issued patch guidance for 31 new CPU vulnerabilities.
  • In a surprisingly unreported bit of news Cott Systems was apparently ransomwared recently and state agencies all over the USA have been impacted. The news doesn’t appear to have connected the dots since the reports are coming from individual municipalities, not mentioning the 400 local governments scattered across 21 states nationwide that use their system.

Being on the internet is like shopping in a Guatemalan Mercado. There are amazing things to see, smell, hear, and even taste – with great deals to be had if you know how to shop. But, unless you are careful and situationally aware, you may be robbed, poisoned, or worse.

Visc. Zebullon Wamboldt Pike

Headline NEWS
Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest
Cyber Insurance News

For a PDF version of this week’s report, click here

Share this with: