March 25, 2023


Hello all,
The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual.

Notable Callouts:

  • The FBI announced the arrest of Breach Forums owner, Connor Brian Fitzpatrick (aka Pompompurin) last week. This week Breach Hacking Forum shut down, fearing that the FBI had infiltrated and had access. Later in the week the FBI confirmed that they indeed did.
  • Netgear Orbi routers have several critical vulnerabilities that Cisco Talos uncovered. Most now have patches available. However, the 90-day quiet period has expired, so Talos published their findings. A PoC exploit is already out there. If you have Orbi routers, patch them immediately, and watch for further updates.
  • Veeam patched a critical vulnerability a few weeks ago. There is now an exploit in the wild that takes advantage of the unpatched flaw. Patch or mitigate now to prevent credential theft.
  • The Pwn2Own conference just concluded in Canada. As expected, there was a goodly number of new exploits and vulnerabilities exposed. Expect incoming patches from the likes of Microsoft for Windows and Teams, Oracle for VirtualBox, Ubuntu Desktop, and even Tesla. In all 27 new zero-day exploits were used.
  • The 2023 Cybersecurity Maturity Model Report from Cye Security reveals that most organizations are not prepared for cyber-attacks. The report determined that most companies have sufficient tools in place. It recommends, “…organizations should invest in capabilities, rather than tools; perform comprehensive assessments to prevent hackers from exploiting vulnerabilities…”
  • The Microsoft Outlook vulnerability from two weeks ago is still dominating news headlines. Most organizations have now patched, now they are going through the time-consuming process of scanning Exchange databases for prior use of the vulnerability. Microsoft released some new tools and guidance to aid in that effort.
  • In Ransomware, Malware, and Vulnerabilities News, Dish network is still experiencing major issues, with customers trying to reach someone for help, remaining on hold for 14 hours or more.
  • In Other News Events of Note and Interest, Microsoft botched a Geo-location IP update and identified a large swath of the internet as being in Uzbekistan. The net effect was that it blocked logins for the unfortunate ones identified – if they had policies in place that used Geo-IP blocking.
  • In Cyber Insurance News, CFC Underwriting has made available a rather nifty 28 page downloadable cyber insurance guide.

There’s a musical group named 1023MB. However, they’re mostly unknown. They haven’t had a gig yet.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News
Share this with: