January 21, 2023

Hello all,
The Red-N Weekly Security newsletter is below the Notable Callouts as usual.

Notable Callouts:

  • Google Ads are becoming a quagmire of malware. Threat actors are spending top-dollar to show up first in Google searches – duplicating legitimate websites.
    • “NFT God” an internet personality, had a “Life-Changing” sum of cryptocurrency drained and other horrible things happen after clicking on a malicious Google Ad.
  • Fortinet warned last week about their VPN vulnerability. It turns out that a Chinese APT may have planted back-doors in the gear between the discovery and announcement of the vulnerability the patch fixed.
  • Zoho Manage Engine has a PoC exploit out not for a critical RCE.
  • Sophos patched a severe firewall vulnerability months ago. Unbelievably, there are still over 4,000 devices accessible on the internet that have not patched!
  • Norton LifeLock said that thousands of customer’s accounts were breached.
  • TP-Link and Netcomm Routers have critical vulnerabilities and should be patched immediately.
  • T-Mobile – again… This time 37 million accounts have been compromised.
  • If you use Git, update your software to prevent RCE.
  • Biden administration prepares to enact tacit declaration of cyberwar, with new cybersecurity policy, against all adversaries, including preemptive attacks.

I miss the internet of waiting for interminable long downloads to finish, cat videos, and busy signals while you redialed your 19.2k modem hoping for it to connect this time.

Visc. Zebullon Wamboldt Pike

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

For a PDF version of this week’s report, click here.

Share this with: