September 23, 2023


Hello all,

After the flurry of vulnerability announcements and patch releases last week, this one has been a welcome respite, unless you have any of the affected products in our Notable Callouts.

This week, Microsoft will be introducing a goodly number of product changes, updates, and new items. Many are listed in our Other News and Events of Interest section, and I’m sure a few more will sneak in during the releases and reveals.

As usual, the complete Red-N Weekly Cyber Security News newsletter report is below the Notable Callouts. Don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

Notable Callouts:

  • Apple leads the headline news with emergency updates to fix 3 new zero days that were under active exploitation. Pretty much everything currently supported was patched. So, if you have iFruit, update it ASAP.
  • Atlassian, makers of Confluence, Jira Service Manager, Bamboo Server, and more have released patches for several of their products. If you use Atlassian items, check for updates. In a related note, the Internet Consortium has released updates for Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite.
  • TransUnion, the credit agency, was hacked by dirtbags known as USDoD, who have now leaked a trove a highly sensitive information pilfered from their victim. If you haven’t yet put restrictions on your credit data at the 3 major agencies, this should serve as a wakeup call to do so before other scumbags start utilizing the stolen data.
  • Fortinet, has released the patch-of-the-month, or is it week? It seems that they have more than their fair share of vulnerabilities and exploits. But perhaps that is simply due to Fortinet’s large base, making them a desirable target. Thankfully, Fortinet does release patches and updates quickly when bad things are found. Now if only those that own and manage the devices would apply those updates in a timely manner…
  • Nagios makes IT Infrastructure monitoring software. Four vulnerabilities were patched recently. If you use this, don’t wait for it to be exploited, patch now.
  • Siemens Automation License Manager (ALM) has two zero-day Remote Code Execution flaws that were recently patched. Siemens also released mitigation and hardening guidance.
  • Trend Micro, in a slightly different flavor of hole, had to release an update to their endpoint protection to address a zero-day (meaning it is being exploited in the wild) flaw in a third-party uninstaller that allowed for RCE. A number of Trend products were impacted. Check for updates and apply them quickly. “Customers are strongly encouraged to update to the latest versions as soon as possible.”

In Ransomware, Malware, and Vulnerabilities News:

  • MGM Resorts have gotten their casino operations back online after being down for 10 days, losing an estimated $8.4 million per day. As of this writing, the Hotel portion of the business, including online reservations, was still down.
  • OT and ICS (including IoT) attacks are increasing rapidly. It should come as no surprise that Threat Actors are pivoting to attacking Operational Technology, Industrial Control Systems, and Internet of Things devices at an accelerated pace. Defenders are getting better at patching holes and mitigating vulnerabilities in your typical items such as software and network devices. However, OT, ICS, and IoT, are often neglected by manufacturers after they are released and they seldom receive any patches or updates, and thus vulnerabilities are left unpatched for months or years. And, due to the cost of replacing those items, sometimes ranging in the millions of dollars, that is often not an option.

In Other News Events of Note and Interest:

  • ConnectWise has said that “An IPO is an option” that could come in their future.
  • Passkeys are rapidly taking over. There are several announcements in this section about this technology. Microsoft has announced that the next release of Windows 11, expected this coming week, will include passkey functionality.
  • Linux has given up on 6 years of support for their LTS (Long Term Servicing) versions of the kernel, saying that it is too much work. That can only be a boon for Google that announced last week that beginning in 2024 Chromebooks would receive support for 10 years.

In Cyber Insurance News:

  • A report on how the investigation portion of a Cyber Incident is now as costly, if not more so, than the actual ransom demand and mitigation process.

In the paraphrased words of Paul Revere, “AI is coming! AI is coming!”. Microsoft is about to unleash AI on the masses this coming week, and will now have it baked into Windows 11 23H2. Be it for evil or good, Pandora is out of her box, and just like trying to get toothpaste back into the tube, it is not going to happen. AI is here to stay. Learn all you can about it so that AI serves you, and not the other way around.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: