July 1, 2023


Hello all,

The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual and can be found online as well at https://red-n-security.com.

Notable Callouts:

  • ArcServe UDP Backup has an RCE bug that requires patching. If you have it patch it.
  • CISA has several news items this week peppered about the red-n-security newsletter. But our headlining item is that they have new security leadership for the upcoming 2024 elections. And for those wondering, yes, Jen Easterly is still leading CISA.
  • Ethernet just turned 50 years old. Yep, the good ole network that runs much of the world. The article from The Register gives a rather nice concise jaunt down memory lane.
  • Google Chrome patched yet again. So, update ASAP to avoid falling victim.
  • A news item that I missed when it happened crossed my radar this week. Gordon Moore, author of Moore’s Law, passed away recently. The linked article from nature.com is a good read and tribute to a brilliant man.
  • Microsoft is warning about widescale credential stealing by Russian hackers. The bad guys are continually upping their game. Awareness on the part of the defenders is the first step in combatting this scum.
  • Speaking of scum, human traffickers dealing in cybercrime were recently raided in the Philippines by the police. 2,700 slaves from 18 different countries were rescued from dormitories and boiler room operations for nefarious activity.
  • Airline Pilots from American Airlines and Southwest recently had their personal data compromised. Several other articles in this week’s news talk about the use of AI to create convincing false personas for the purpose of theft, extortion, and more. Not good.
  • SAP has patches for 4 bugs. Patch now if you use it.
  • Social Login, a plugin for WordPress, has a critical security flaw. Patch immediately or shut down the plugin until you’re able to patch. Speaking of WordPress, if you’re using it, especially if you are doing so commercially, install and subscribe to something like WordFence. (No, I don’t make anything off of the recommendation.)
  • In Ransomware, Malware, and Vulnerabilities News, the top item talks about how Cyberattacks on hospitals should be considered a regional disaster. The article makes a compelling argument. One more item is a ‘What were you thinking?!!’, moment. A school, which I shall not shame here, sent an email to every student telling them their passwords had been reset to ‘Ch@ngeme!’. Yep, every student. If you were the first to hit someone’s account, you could log in as them and read everything they had. This major flub was quickly retracted, but not before the damage had been done. Wow.
  • In Other News Events of Note and Interest, there is a lengthy, but worth it, article from vice.com about 40-year-old (brand new in box) forgotten computers, 2,200 of them, suddenly turning up for sale online, and the obscure network they were designed to run on.
  • In Cyber Insurance News, an article on how insurers are now starting to utilize AI for underwriting and due diligence.

Knowledge is freely and readily available and growing at an exponential rate. However, as we’ve all experienced, I’m sure, there are plenty of knowledgeable idiots out there. Unless knowledge is properly applied, it is at best useless, and at worst dangerous. Knowledge properly applied and governed by a self-respecting individual is known as Wisdom.

May you handle your world and those in it with wisdom this week.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: