October 7, 2023


Hello all,

Thankfully, after the flurry of stuff popping up last week, this week has been a bit slower. Albeit it is the calm before the storm as Tuesday is Patch Tuesday for Microsoft and other vendors. Despite the relative calm, there were some Headline News items this week that should be noted that are listed below.

As usual, the complete Red-N Weekly Cyber Security News newsletter report is below the Notable Callouts. Don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.

The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts and then skim the other link titles for items that pertain to you or your environment, or simply interest you. So, let’s get to it.

Notable Callouts:

  • Apple is in the headlines again for another zero-day patch. This one also fixes an overheating problem with the latest iPhones.
  • Arm and Qualcomm both have had flaws in their GPUs revealed that require patching. Watch for announcements of updates from your favorite GPU vendor and apply ASAP
  • Atlassian patched a critical zero-day that was already under active exploitation.
  • Exim mail server software has received several patches this week from Openwall. While there are still some unpatched holes, the worst of the lot now have a solution.
  • Linux – pretty much every version, has a Local Privilege Escalation bug dubbed “Looney Tunables”. Exploits are already out for this. Patch quickly.
  • Microsoft gets two headline mentions this week, the first is to remind anyone who has not been paying attention that Windows 2012 and 2012 R2 will receive their last update this Tuesday. The other is that Edge and Teams received fixes for zero-days found in open-source libraries.

In Ransomware, Malware, and Vulnerabilities News:

  • Starlink from Space-X, unbelievably, does not have 2FA available for account logins and users are having their accounts taken over.
  • NSA and CISA released a list of the top 10 cybersecurity misconfigurations.

In Other News Events of Note and Interest:

  • DEC aka Digital Equipment Corporation, was one of the pioneers in computing. In this section there’s a link to a great article that details how we’re still using technology and ideas from this legendary company.
  • Amazon has launched their first Project Kuiper satellites, in what they intend to be competition for Starlink.
  • OPatch – if you must keep older, unsupported versions of Windows, then 0Patch may be your answer. They are still releasing security patches for Windows 7 and will have them for Windows 2012 and 2012 R2 for three more years.

In Cyber Insurance News:

  • The Cyber Insurance Market is expected to grow at a rate of 22.3%.

It isn’t paranoia if they really are out to get you. And they are out to get you. Stay vigilant, stay safe.

Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Cyber Insurance News

Share this with: