April 15, 2023


Hello all,

This past week has brought a tsunami of vulnerability fixes and patches. Many of these are for zero-days, so patch quickly! The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual.

Notable Callouts:

  • Apple, last week they patched their new and current items. This week they patched older hardware. Update your fruit devices.
  • Adobe has patched a huge amount of their products this week. Some holes are being actively exploited and are trivial to use. Patch ASAP.
  • Microsoft Patch Tuesday was unleased upon us with 97 (or more) items that were fixed or remediated. There were several zero-day exploits patched, so don’t delay in applying the updates. Microsoft also reported a new attack that uses Azure AD Connect. And they shared guidance on how to detect BlackLotus’ UEFI bootkit.
  • SAP has released two patches for critical flaws.
  • Fortinet didn’t want to feel left out so they patched a large number of products as well.
  • Google said, “But wait, there’s more!” and released a patch for a zero-day being exploited in Chrome, the first for them for 2023.
  • Hikvision the camera company didn’t want to miss the party, so they also patched a critical flaw.
  • Siemens and Schneider Electric both addressed dozens of vulnerabilities in their Industrial Control Products.
  • ManageEngine patched a critical Command injection vulnerability.
  • And finally, for those in the MSP space, there are rumblings that ConnectWise may be purchased soon by a new private equity firm.
  • In Ransomware, Malware, and Vulnerabilities News, the headlining item is the AI-created malware that required almost no coding skills by the human instructing the AI. Speaking of AI, a linked report in this section shows how quickly passwords can be defeated.
  • In Other News Event of Note and Interest, Microsoft Exchange 2013 has reached End of Support. If you’re still using it, stop! Upgrade to a newer version or migrate to the cloud. In an annoying trend, Microsoft is rolling advertisements to the Start Menu in Windows 11. And Patch Tuesday’s updates brought a built-in LAPS (Local Administrator Password Solution) natively to Windows 10 and 11.

One observation that I’ve made over the years is that as an industry we tend to focus on the new and shiny, the high-tech, and the fancy, but often ignore the simple, mundane, and easy while looking for a solution. Think low tech. Don’t spend hours searching for a new printer driver, bus conflict, or protocol error when the issue is a paper jam.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News
Share this with: