March 18, 2023


Hello all,
The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual. There’s a lot this week, so let’s get right to it.

Notable Callouts:

  • Microsoft Patch Tuesday’s releases are the biggest news item this week, with the zero-user interaction Outlook vulnerability dominating tech headlines worldwide. We’ve learned that this particular zero-day vulnerability has been in use by state sponsored malactors since at least April 2022. Simply receiving, not even opening or viewing, the email is sufficient to execute the exploit. Organizations worldwide are scrambling to patch and search their Exchange databases for malicious emails (Microsoft has provided tools for this) that may have been received prior to the patch being applied. In total, Patch Tuesday brought two zero-day vulnerability fixes and 83 patches for other issues.
  • Fortinet announced new firmware last week to patch actively exploited vulnerabilities. This week they are warning that active exploitation is underway, specifically against government networks.
  • Adobe is warning that their Cold Fusion product has a zero-day that is being exploited in ‘very limited attacks’, whatever that means. If you’re using it, patch it. If not, remove it.
  • SAP has released updates for critical vulnerabilities.
  • CISA is going to start proactively scanning critical infrastructure and warning organizations if they determine that they are vulnerable.
  • Microsoft is warning about large-scale use of phishing kits to send millions of emails daily to potential victims. In related news, Emotet is back with a vengeance and is part of the malicious email hailstorm being reported worldwide in support and chat forums.
  • Ring Network is keeping quiet about a potential ransomware attack, even though there is mounting evidence of foul play.
  • Dish Network is still trying to recover from their ransomware attack that hit them just as they were transitioning to a new cloud-based infrastructure.

“If you spend more on coffee than on IT security, you will be hacked.”– Richard Clarke.

Visc. Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

For this week’s Red-N Weekly Cyber Security News in PDF format, click here.

Share this with: