March 11, 2023


Hello all,
The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual. This week is a bit lighter on news than prior weeks, Tuesday is Patch Tuesday, so I expect next week will be rather busy.

Notable Callouts:

  • Fortinet has released patches and mitigation advice for numerous products for an unauthenticated RCE vulnerability. This is as bad as it gets. Patch now if you have it.
  • SonicWall Secure Mobile Access (SMA) appliance, if not already patched, is vulnerable to a newly discovered suspected Chinese malware campaign that installs into the OS, and establishes persistence that survives reboots and firmware updates.
  • Veeam released updates for version 11 and 12 of their software. If left alone, hackers could breach the backup infrastructure by extracting credential hashes from the database. Version 10 is out of support and will need to follow mitigation advice from Veeam, or upgrade to a supported version.
  • CISA is warning about an exploit in VMware‘s Cloud Foundation that is being actively abused. CISA is requiring all agencies to patch by March 31. Additionally, CISA has added 3 new vulnerabilities to their KEV catalog.
  • Google released Chrome 111, patching 40 vulnerabilities, and this version retired their Chrome Cleanup Tool, removing it from the browser.
  • Medusa ransomware group found a unique way of providing proof of exfiltration by releasing a video showing the content of folders stolen from their victim – Minneapolis schools.
  • In Ransomware, Malware, and Vulnerabilities News there are several reports that detail trends and statistics from 2022. They are worth going through.
  • In Other News Event of Note and Interest TikTok continues to earn a black mark from governments worldwide. Belgium is the latest to ban TikTok on all government devices. And AmigaOS, yes, THAT Amiga has just received an update to version 3.2.2.

No electrons or photons were harmed in the creation of this report. We use only laboratory grown, and ethically sourced electrons and photons to generate the content you are reading. Although some of them require more coaxing into place than is normal and may in fact be morons.

Visc. Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

For a PDF version of this week’s Red-N-Security Cyber Security News, click here.

Share this with: