April 1, 2023


Hello all,
The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual.

Notable Callouts:

  • 3CX is leading the news everywhere this week. Apparently, nation-state actors have managed to alter 3CX’s desktop software, weaponizing it for nefarious purposes. This one may have long-lasting effects for those affected. 3CX’s guidance currently is for customers to uninstall the desktop app and use the web version. Even after uninstalling, what was potentially left behind?
  • In a moment of happier news, Microsoft has made available a newer, faster, more efficient version of Microsoft Teams.
  • Google Chrome has received an update for multiple high-risk vulnerabilities. Patch now.
  • The GoAnywhere zero-day that was patched recently is still claiming victims, those who are just now finding what the bad guys did are working to clean up, and those who didn’t get the message to patch are still being infected.
  • Apple released patches for just about everything they make. Update now.
  • IBM Aspera Faspex software, which uses their proprietary FASP—short for Fast, Adaptive, and Secure Protocol, has a critical vulnerability that is being exploited by threat actors.
  • Proposed US legislation named, “Restricting the Emergence of Security Threats that Risk Information and Communications Technology (RESTRICT)”, to deal with things like TikTok has language in it that would potentially criminalize use of VPNs. This is definitely one to watch.
  • QNAP is warning customers to patch. They have a Linux Sudo vulnerability that could allow bypass and privilege escalation.
  • We’d mentioned this a few months ago, and now it is here. In new spending legislation due to take effect on Wednesday, the FDA is requiring medical device manufacturers to prove they have a cybersecurity plan prior to being permitted to sell their products.
  • In Ransomware, Malware, and Vulnerabilities News, Microsoft has unveiled more ChatGPT powered products. Security Copilot is touted to be a boon for overworked security teams to produce correlated actionable intel into potential threats.
  • In Other News Events of Note and Interest, some wonk managed to marry his 1984 IBM PC to ChatGPT via MS-DOS.
  • In Cyber Insurance News, Lloyds of London is fighting with insurers over ‘state-backed’ cyber attacks. Many policies have similar exclusion language, but how do you define it. And even more so, how do you prove it?

If someone from the 1950s time traveled into the future and suddenly appeared today, what would be the most challenging thing to explain about modern life?

One answer: “I possess a device in my pocket that is capable of accessing the entirety of information known to man. I use it to look at pictures of cats and get into arguments with strangers.”

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News
Share this with: