May 13, 2023


Hello all,
The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual. This week’s list of shame and fame is sponsored by Microsoft Patch Tuesday. But first, we start with Cisco and an expired certificate.

Notable Callouts:

  • CISCO let a certificate expire in some SD-WAN edge router that could result in the devices becoming unbootable. They are pushing a new certificate and patches.
  • Discord let it be known that they had a data-breach by sending emails out to the affected victims.
  • FTC, for some reason feels it is necessary to warn consumers that phishing is still a thing. So, for those of you who are new to email, please read their alert.
  • Microsoft unleased a smaller set of updates this past Patch Tuesday than usual. There were 3 zero-days, and 38 vulnerabilities or fixes addressed. One major patch is for UEFI BIOS to resolve ransomware embedding itself at the boot stage.
  • Netgear RAX30 routers were pwn’d recently by chaining 5 different vulnerabilities. Patches exist, so apply them if you use this equipment.
  • Rockwell Automation has been shown to have over a dozen vulnerabilities in their industrial products.
  • Ruckus Wireless has a Remote Code Execution flaw, patch now.
  • SAP completes the Patch-Tuesday week items with several critical vulnerabilities patched.
  • In Ransomware, Malware, and Vulnerabilities News, research shows that ransomware payments have nearly doubled in one year, and Google is making Dark-Web monitoring available to all users.
  • In Other News Event of Note and Interest, Backblaze has reported (along with others) that most hard-drives die within 3 years. The race for overlord of humanity continues to push ahead with Google unleashing their AI on the general public to compete with Microsoft.
  • In Cyber Insurance News, Cowbell reports that 90% of small businesses underestimate (by a large margin) how much a cyber-incident will cost them. And, “sharp price increases” are predicted to come.

One late breaking item. Citrix has released patches for vulnerabilities that have been discovered in Citrix ADC and Citrix Gateway.

With AI rapidly invading every area of our lives, how long will it be before AI breaches the cyber-divide and creates a human-spread virus?

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News
Share this with: