September 2, 2023


Hello all,

For those of you in the United States, happy Labor Day weekend! May the computer muses smile on you during this extra day off and may your systems continue to hum along without you.

As usual, the complete Red-N Weekly Cyber Security News newsletter report is below the Notable Callouts. Don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • DediPath a USA-based hosting provider gave their clients 24 hours’ notice that they were shutting down operations. Thankfully for those affected, they do appear to be giving some leeway in time to migrate away. I wonder if this is something Cyber Insurance would cover? Dedipath’s abrupt departure should be a poignant reminder of the importance of having your own backups that are not stored at the host site. Yes, it may be time consuming to restore elsewhere, but at least you don’t risk losing everything.
  • Every Cellphone and TV in the USA will scream out a nationwide alert test at 11:20 a.m. Pacific time on Oct. 4, 2023. If you plan on having any meetings at that time, it may be wise to mute or shut down your phones.
  • FBI along with an international coalition of defenders, took down a huge portion of the QakBot infrastructure in an operation named, “Operation Duck Hunt”. Due to the scope of the disruption, it will take the dirtbags quite some time to ramp back up. It is nice to have the good guys get a win for a change.
  • Mozilla Firefox and Google Chrome both received patches this week for vulnerabilities. Update quickly as criminals are always waiting for things like this. Also, a reminder that Google will be updating Chrome weekly from now on. So, shut your Chrome browser down at least once a week to remain updated.
  • Pigeon transport is still faster than gigabit ethernet, at least for distances less than 600 miles. Some researcher actually tested this by strapping a 3TB flash drive to the avian transporter and timed the results. There is actually an RFC, 1149, for “A Standard for the Transmission of IP Datagrams on Avian Carriers”. It needs a bit of updating, but the principle is clearly still sound. It reminds me of the old axiom, “Nothing beats the bandwidth of a station wagon fully loaded with mag-tape.”
  • SentinelOne has put the kibosh on any merger or take over talks. Last week we’d reported that Wiz was interested in acquiring S1. That process has been halted and no further merger or takeover talks appear imminent.
  • Splunk, makers of security and infrastructure monitoring products has patched high-severity flaws in their Splunk Enterprise product. If you use, it patch soon.
  • VMware has released patches for their Aria Operations for Networks (formerly vRealize Network Insight). If you use this, patch immediately. As you’ll see later, a PoC has already been released into the wild that exploits one of the two holes.

In Ransomware, Malware, and Vulnerabilities News:

  • Some grayhat hackers have deleted over 75,000 phones records from WebDetetive’s database, preventing the devices from connecting and sending any more data to the spyware host.
  • In an interesting twist on extortion, Ransomware operators dealing with EU “customers” are now threatening them with GDPR The intent is to get the victims to pay hush-money to avoid GDPR penalties and notification rules.

In Other News Events of Note and Interest:

  • The Jewish Children’s Museum in Brooklyn, New York will be host to the Jewish CyberSecurity Conference dubbed “Hacker’s HakhelCon” on September 5, 2023.
  • Microsoft is making a change to how photo storage is calculated in OneDrive. If you store photos, and if you use albums, pay attention as this will affect you.

In Cyber Insurance News:

  • Many insurers are now requiring specific security controls be in place before providing coverage. If not already existing, they must be purchased. Many of these revolve around access management, including IAM, PAM, MFA, and password management. Read more in The Reality of Cyberinsurance in 2023.

On this labor day weekend, raise an adult beverage of your choice, or flame up a beef or veggie burger, in honor of your tireless servers and cloud computing resources. While we take a day off, they are still hard at work shoveling electrons at light-speed all around the globe and even into space.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: