August 15, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

As expected, Patch Tuesday was quite large. Microsoft recently warned that for the foreseeable future the amount of patches, and potentially even the frequency of patch releases, would be significantly higher, and they weren’t kidding. This month brought roughly 400 patches across most everything they offer. Not to be outdone, vendors from A to Z – Adobe to Zoom, and a slew of others in between, such as AMD, Cisco, Docker, Google, Fortinet, Mozilla, Palo Alto, Red Hat, SAP, and WordPress all announced patches for issues.

In Good News, there is a story about DEFCON hackers protecting the nation’s water utility infrastructure, a report of a honeypot operation to catch North Koreans looking to infiltrate companies by impersonating western workers, news of the USA giving permission to hack back, and some news of successful law enforcement activity against some of the evil underbelly of cybercriminals. Let’s take a look at a few of the items in a bit more detail.

Headline NEWS:

  • A to Z vulnerabilities found and patched. Adobe, Cisco, Fortinet, Microsoft, WordPress, and Zoom all announced patches for critical or severe vulnerabilities in their products this past week. Some of these require no action on the part of the victim, so be sure to check out the full articles for attack vectors, mitigation, patching instructions, and how to detect if you’ve been exploited. Or just enable auto-updates for anything that supports it, and check that you’re on the latest versions. If the product doesn’t support auto-updating, look for an alternative or ensure that you stay aware of, and perform updates, whenever a patch is needed. It is high time that every product, software and hardware, had reliable auto updating, and failed update rollback, capabilities.

In Ransomware, Malware, and Vulnerabilities News:

  • Delta Airlines reported a Wi-Fi Pineapple was detected on a flight. DEFCON, aka hacker summer camp, ended the day prior, and on a flight from that event, it seems that one of the participants decided to try out his (or her) newly acquired skills and/or toy. The message from the cockpit to Air Traffic control read, “A HEY ALERT CORP SECURITY WE HAVE A PAX ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”. And “NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”. Terse language and bad grammar aside, I’m amazed that this doesn’t happen more often. It probably does, but this one received news coverage due to the proximity to DEFCON, Black Hat, and BSidesLV. If you’ve been paying attention to the cyber news you would recall that quite a few hotel Wi-Fi networks are being similarly attacked worldwide right now. It isn’t safe out there, always use a VPN when connecting over any public form of Wi-Fi. Spoofing a legitimate one and routing all traffic for capture and later decryption and inspection is now quite trivial.

In Other News Events of Note and Interest:

  • Social media addiction lawsuits against Meta and TikTok can proceed, court rules. Companies such as Google, Facebook, Instagram, Snapchat, and TikTok are facing a nightmare scenario as the courts are permitting lawsuits to go through that remove personal responsibility and ask the content creation hosts to be the parent and guardian and limit what consumers can view, how, and how much. They are being accused of having “developed and refined a set of psychologically manipulative platform features designed to maximize young users’ time spent on its social media platforms”. I would counter that it is the responsibility of the company to their investors to do exactly that! The company isn’t the nanny, they are there to get clicks, views, likes, shares, and the most profit possible.  It is the parents’ responsibility to monitor and limit their children’s access, content, and time spent. But our society has devolved to the point that it must be someone else’s fault, and there’s always a lawyer willing to go for it. This is why we can’t have nice things for long. I predict this will not end well for the social media companies.

Musings

The social media addiction lawsuits brought by a handful of US states against Alphabet, Meta, Snap, ByteDance and similar have been given the green light by the 9th Circuit Court of Appeals to proceed. This is dangerous, irresponsible, and unwarranted. While it is undeniably true that the companies do indeed design their systems to keep viewers engaged and on their platforms, clicking, liking, sharing, commenting, and posting as much as possible; that is their obligation to their shareholders and investors. Any company that doesn’t maximize whatever their product is designed to do will ultimately fail against one that does. This lawsuit, and thousands like it, is an abdication of personal and parental responsibility. Nobody made you install that app on your phone; nobody made you center your life around clicks, watches, and likes; nobody made you keep doing it; and to contend that the manufacturer is responsible for your choices and any potentially negative personal result is wrong.

Visc. Jan Broucinek

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

 

Share this with:

Leave a Reply

Your email address will not be published. Required fields are marked *