June 24, 2023

Hello all,

The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual and can be found online as well at https://red-n-security.com.

Notable Callouts:

  • Apple starts us out with emergency patches for actively exploited zero days. Patch now, I’ll wait.
  • ASUS has released patches for quite a few of their routers. Botnets love these unpatched routers, so please patch yours.
  • Fortinet fixed several items, including an RCE.
  • Microsoft’s recent DDoS attack was likely not from Africa, but was perpetrated by a Russian-backed group.
  • MOVE-it continues to make news with new compromised companies being revealed daily. The US Government is offering up to $10 million dollars in reward for information leading to the capture of the attackers.
  • Pinellas County, FL – near and dear to many readers of this newsletter, failed to redact Social Security numbers on citations posted online for all the world to see.
  • Schneider Power Meters have a vulnerability that opens locations to a post-apocalyptic blackout, well, at least power outages.
  • VMware has had a busy couple of weeks with vRealize (aka Aria) now under active exploitation, and this week a new vCenter Server bug allowing all sorts of things it shouldn’t.
  • Zyxel finishes the headlines with critical flaws in their NAS devices. They make NAS devices? If you have them, patch them immediately.
  • In Ransomware, Malware, and Vulnerabilities News, Sophos has put out a multi-part series titled “The Ransomware Documentary”. Also, Chinese hackers are exploiting a zero-day in ESXi that VMware fixed last week. Finally, SpaceX and NASA have successfully placed a satellite in orbit that will be live-hacked by 8 teams at DefCon 31 in Las Vegas.
  • In Other News Events of Note and Interest, WD NAS drives flash failure warnings and cripple NAS devices, when nothing is wrong. One more item, Proposed SEC rules have companies scrambling to figure out how they will be able to comply with the Cyber Expert requirements being proffered.
  • In Cyber Insurance News, some advice on how to use Cyber Insurance requirements as selling opportunities to better secure business that are supported by MSPs.

I ran across a quote written by Sir Francis Bacon in Meditationes Sacrae (1597).

“Scientia iIpsa potentia est” = “Knowledge itself is power”

May the knowledge you gain from the links below empower you to better understand, enjoy, and secure your world

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News
Share this with: