August 12, 2023


Hello all,

Reporting live from DefCon 31 in Las Vegas is proving to be very challenging due to the need for heightened security. But, as you can see, the Red-N Security news has emerged victorious! The trifecta of Hacking Boot Camps is producing a plethora of announcements about vulnerabilities and flaws. Thankfully, most have already received mitigations and these are just announcements. Many of this week’s news items that mention patches were uncovered as a result of some of the conference presenters’ efforts, and they they shared from the stage, in gory detail, the inner workings of what they’d found. Alas, some have not been patched – yet.

As usual, the complete the Red-N Weekly Cyber Security News newsletter report is below the Notable Callouts. Don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Adobe has released patches for a good number of products. Check and update.
  • AMD Zen CPU’s have a weakness that allows data stealing.
  • Google has a couple of headline items, the first is that they will be releasing weekly updates to Chrome, and they have revealed a zero-day vulnerability in their Pixel 6 phones, urging users to turn off the 2G functionality.
  • Intel, not wanting to lag behind AMD has a similar flaw that allows information theft. Unfortunately, the patch can reduce performance of the processor nearly in half.
  • Microsoft Patch Tuesday was this Tuesday. There were 87 bugs fixed, with at least two zero-days. Windows 11 had 27 fixes. A rather unusual entry is that they released a kernel mitigation that has the potential to break Windows. Initially it was to be turned off by default. Instead it is now on by default. And Visual Studio has a bug that lets extensions steal passwords.
  • PaperCut had a vulnerability show up late last week, so we’re repeating the warning again this week. Patch before you’re exploited.
  • Zoom fixed over a dozen flaws with their latest update. So, update quickly.
  • In Ransomware, Malware, and Vulnerabilities News, Microsoft has finally patched the Office zero-day from last month.CISA has added a Microsoft .NET vulnerability to their Known Exploited Vulnerabilities Catalog.
  • In Other News Events of Note and Interest, two reports about the trio of security conferences underway in Las Vegas, NV.Microsoft will start enforcing DMARC policy in Exchange Online.

The attackers do not sleep, and if they do, it is in a time zone opposite yours. So, make sure you keep your shields up 24/7.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: