June 10, 2023


Hello all,

The Red-N Weekly Cyber Security News newsletter is is below the Notable Callouts as usual and can be found online as well at https://red-n-security.com. The biggest news item this week is a three way tie with Barracuda, Microsoft, and MOVEit.

Notable Callouts:

  • Barracuda thought they’d stemmed the tide last week with patches. This week two new devastating revelations. The first being that Clop might have been aware and using the flaw since 2021. The second is an urgent announcement to replace all affected ESG This means the threat actors have embedded themselves so deep that Barracuda cannot be certain they can clean the devices.
  • Cisco has released fixes for their VPN AnyConnect software to repair a flaw that allows Windows System privilege access.
  • Clop ransomware criminal gang is mass extorting hundreds of organizations worldwide as a result of compromising the MOVEit file transfer system.
  • DefCon 31 is coming to Las Vegas, and SpaceX, along with NASA is putting a satellite into orbit for the sole purpose of having it live-hacked at that conference to improve satellite security.
  • Google has issued a patch for a new Chrome Zero-Day vulnerability. Patch now!
  • Managed Service Providers are starting to get some recognition. Tech Republic put out a good article describing the Top 6 benefits of managed IT services.
  • Microsoft has had a rough week. Numerous of their services have been down at times this past week, such as Azure AD, Outlook, OneDrive Live, and more. Threat group Anonymous Sudan is claiming responsibility via DDoS attacks.
  • MOVEit by Progress Software, is still being actively exploited, with thousands of devices showing via internet scans as still vulnerable. This week, with the help of cybersecurity group Huntress, yet another vulnerability was uncovered that has now had a patch released.
  • NetApp has had five bugs identified by CERT-In. Patch now.
  • VMware vRealize Network Insight (now Aria Operations for Networks) has patched several critical vulnerabilities.
  • Zipper giant YKK (I couldn’t resist the letter Z reference) has confirmed that their US network was victim to a cyberattack.
  • In Ransomware, Malware, and Vulnerabilities News, a new report shows that vulnerabilities have increased by 25 percent over the same period last year.
  • In Other News Events of Note and Interest, the CEO of ConnectWise has said that ‘cybersecurity has reached a tipping point’ where IT must come up with a better game plan to further mitigate risks. Naturally, the comments were followed by product integration announcements.
  • In Cyber Insurance News, the interest in a federal backstop for cyberinsurers continues to grow.

A late-breaking news item is that Fortinet has fixed a critical RCE flaw in Fortigate SSL-VPN devices, patch now.

Stay vigilant. It is better to cry wolf and be mistaken than to have your entire flock eaten.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News
Share this with: