
(For a video version of the introduction below, go to my LinkedIn post.)
Hello all,
This was somewhat of an interstitial week with less headline defects and vulnerabilities, but it was balanced by plenty of other news items. Some of the more significant were Apple’s decision to cripple security for their UK clients, an unbelievably massive crypto currency heist, and several vendors patching severe holes. So, onward.
Headline NEWS:
- Apple is in the headlines again this week, but for a different reason. In response to the UK’s demand of having a backdoor to user’s encrypted data, Apple has disabled end-to-end encryption for all new accounts, stating “Apple can no longer offer Advanced Data Protection (ADP) in the United Kingdom to new users.”. And, at a yet undisclosed future date, Apple will have to disable ADP for all UK clients. Customers not in the UK will retain ADP and the ability to encrypt their iCloud storage.
- ByBit, a crypto currency exchange had $1.4 billion worth of Ethereum moved (aka stolen) out of a cold wallet (non-internet connected) and moved to a warm wallet (internet connected). To put a bit of perspective on the scale, if this was US $100 dollar bills, the booty would weigh 11 tons, or if $20 bills, 55 tons. For their part, ByBit should be OK, as they have over $16 billion in assets and have assured depositors that their funds are safe.
- Citrix has a vulnerability in NetScaler Console (formerly NetScaler ADM) and NetScaler Agent that allows an authenticated user to execute unauthorized commands. That would be corporate-speak for the malicious user can eventually do whatever they want. There are no workarounds, you just need to update to the latest patched versions to mitigate.
- Juniper Networks has issued patches to fix a critical authentication bypass vulnerability in their Session Smart Router. This defect allows an attacker to “bypass authentication and take control of the device”. If you use this, update quickly.
- LibreOffice has issued patches to fix some bugs that could result in both data loss and data theft. Upgrade to the latest versions to plug these holes.
- Palo Alto has identified a new defect that is already under active exploitation. When chained with other flaws, an attacker can gain full control over the PanOS device. If you use Palo Alto, apply the patches and do not expose the management interface to the internet.
In Ransomware, Malware, and Vulnerabilities News:
- Ransomware continues to be a global scourge, despite payouts in 2024 being lower than in 2023, there was a marked increase in successful attacks. LockBit’s very public takedown has resulted in a number of smaller players throwing their horned helmets in to the mix. Ransomware as a Service (RaaS) is growing with the cost of entry being as low as $40 per month, significantly lowering the bar to ride the evil train. A troubling statistic is that the time from initial compromise to encryption is now 17 hours on average, with some groups encrypting in as little as four hours. Sadly, many companies still think that they’re “too small” or “insignificant” to be attacked, not realizing that it is opportunity, not desirability that drives this malevolent activity. Even Paddington Bear is not safe, with publisher “The Agency” recently compromised by ransomware. Paddington! This is putrid level evil at work!
In Other News Events of Note and Interest:
- China’s DeepSeek is being fed data from, well everything. In a move that is both brilliant and terrifying, China has a nationwide plan to connect everything to their AI, smart vehicles, schools, shopping, everything. This move will enable The Middle Kingdom to correlate and analyze anything and everything their citizens do online. Let’s just hope that when their AI achieves consciousness it decides that it likes the average citizen more than the authoritarian government.
Musings:
There is an old encouragement that asks, “How do you eat an elephant? One bite at a time”. You could similarly ask, “How do you fill an ocean? One drop at a time”. My point is that the ONE matters. Individually, we may not amount to much, but through repeated, consistent, and combined effort, we can make massive differences not just for ourselves, but for others, and the world around us. Despite daily reports of doom, gloom, and the screeds of harbingers of bad news, keep doing what you know is right, one bite, one drip at a time. Because in the end, it is the consistent efforts of good people doing the right thing that will prevail.

But in the meanwhile, keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Apple pulls iCloud end-to-end encryption feature in the UK
- Apple is removing iCloud end-to-encryption features from the UK after government compelled it to add backdoors
- $1.4 Billion Stolen From ByBit in Biggest Crypto Theft Ever
- Citrix NetScaler Vulnerability Allows Unauthorized Command Execution
- Juniper Networks fixed a critical flaw in Session Smart Routers
- LibreOffice Vulnerabilities Allow Attackers to Write to Files and Extract Data
- Palo Alto Networks tags new firewall bug as exploited in attacks
Ransomware, Malware, and Vulnerabilities News
- 127 Servers of Bulletproof Hosting Service Zservers Seized by Dutch Police
- US Army soldier pleads guilty to AT&T and Verizon hacks
- Michigan Man Indicted on Wire Fraud and Aggravated Identity Theft Charges
- Scammers Exploit JFK Files Release with Malware and Phishing
- Phishing attack hides JavaScript using invisible Unicode trick
- Cybercriminals shift focus to social media as attacks reach historic highs
- Google Chrome’s AI-powered security feature rolls out to everyone
- Mac users beware: AI-powered malware threats are on the rise
- An Update on Fake Updates: Two New Actors, and New Mac Malware
- 300% increase in endpoint malware detections
- Microsoft warns that the powerful XCSSET macOS malware is back with new tricks
- Microsoft Patches Actively Exploited Power Pages Privilege Escalation Vulnerability
- Windows Disk Cleanup Tool Vulnerability Exploited to Gain SYSTEM Privileges
- Rapid7 discovers ‘high-severity’ PostgreSQL injection zero-day vulnerability
- Microsoft releases new firmware for several Surface devices to address security issues
- New FinalDraft malware abuses Outlook mail service for stealthy comms
- Beware of Fake BSOD Delivered by Malicious Python Script
- A deepfake epidemic is coming as survey shows that people are simply not good enough at identifying fakes
- ‘Darcula’ Phishing Kit Can Now Impersonate Any Brand
- $10 Infostealers Are Breaching Critical US Security: Military and Even the FBI Hit
- US military and defense contractors hit with Infostealer malware
- Hard drives containing sensitive medical data found in flea market
- Snake Keylogger slithers into Windows, evades detection with AutoIt-compiled payload
- AMD Ryzen DLL Hijacking Vulnerability Let Attackers Execute Arbitrary Code
- Firewalls SonicWall actively attacked via SSL VPN
- Palo Alto Networks Confirms Exploitation of Firewall Vulnerability
- Unifi Protect: Critical vulnerabilities in cameras and management interface
- Ivanti endpoint manager can become endpoint ravager, thanks to quartet of critical flaws
- Critical Apache Ignite Vulnerability(CVE-2024-52577) Let Attackers Execute Remote Code
- CVE-2025-1240: WinZip Vulnerability Opens Door to Remote Code Execution
- WinZip Vulnerability Let Remote Attackers Execute Arbitrary Code
- Xerox Printers Vulnerability Let Attackers Capture Auth Data From LDAP & SMB
- New OpenSSH flaws expose SSH servers to MiTM and DoS attacks
- South Korea blocks downloads of DeepSeek from local app stores
- Russia-aligned hackers are targeting Signal users with device-linking QR codes
- Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger
- LockBit takedown reshapes ransomware threat landscape
- Ransomware spike driven by RaaS operations
- Ransomware Gangs Encrypt Systems After 17hrs From Initial Infection
- Ransomware Hackers Come for Paddington Bear
- CISA and FBI: Ghost ransomware breached orgs in 70 countries
- DPRK hackers dupe targets into typing PowerShell commands as admin
- North Korean IT Workers Infiltrate International Companies To Plant Backdoors on Systems
- Chinese hackers abuse Microsoft APP-v tool to evade antivirus
- How China Pinned University Cyberattacks on NSA Hackers
- Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines
- Kewadin Casinos Still Fighting Cyberattack After Nine Days
- US newspaper publisher uses linguistic gymnastics to avoid saying its outage was due to ransomware
- How federal rules on cybersecurity breach transparency for businesses were challenged in court in 2024
- Elon Musk’s DOGE website has been defaced because anyone can edit it
- Hackers broke into Watergate Hotel’s network, stole personal data from hotel computers
- Finastra Starts Notifying People Impacted by Recent Data Breach
- Major Data Breach Exposes 2.7 Billion Records, Including Smartphone And Wi-Fi Details
- Huge data leak exposes 14 million customer shipping records
- Over 330 Million Credentials Compromised by Infostealers
- Top US mineral firm hit by cyberattack that saw thieves steal $500,000
- VC Firm Insight Partners Hacked
- The Browser Blind Spot: Why Your Browser is the Next Cybersecurity Battleground
Other News Events of Note and Interest
- Cool Tool: WinUtil Is the Ultimate Tool for Setting Up a New Windows Computer
- Cool Tools: The Largest Hub of Cybersecurity Tools
- From boutique to billions: Integris’ blueprint for MSP domination
- HP deliberately adds 15 minutes waiting time for telephone support calls
- Add A Little WOPR To Your Server Rack
- Should You Use HDMI, DisplayPort, or USB-C for a 4K Monitor?
- Mozilla Announce Leadership Changes, Plans to ‘Diversify’
- Writing Doom – Award-Winning Short Film on Superintelligence
- Large Law Firm Sends Panicked Email as It Realizes Its Attorneys Have Been Using AI to Prepare Court Documents
- AI can fix bugs—but can’t find them: OpenAI’s study highlights limits of LLMs in software engineering
- Here’s why autonomous AI agents are both exciting and scary
- Europe announces 700 billion euro package aimed at boosting collective security
- Texas Runs Short on Electricity and Water Needed for AI Data Centers
- Meta Will Build the World’s Longest Undersea Cable
- Meta’s AI-Powered Ray-Bans Are Life-Enhancing for the Blind
- ISP sued by record labels agrees to identify 100 users accused of piracy
- Italy to require VPN and DNS providers to block pirated content
- Managing the emotional toll cybersecurity incidents can take on your team
- China Launches Its Own Quantum-Resistant Encryption Standards, Bypassing US Efforts
- China connects everything to DeepSeek in nationwide plan
- Google is adding digital watermarks to images edited with Magic Editor AI
- YouTube brings AI video creation to Shorts with Google’s Veo 2
- WinRAR 7.10 boosts Windows privacy by stripping MoTW data
- Proxmox VE Helper-Scripts
- Avaya hangs up on users with fewer than 200 SaaSy contact center seats
- Oracle extends 19c database support to 2032, making it ‘longest strategic release’
- China: World-first dual-loop brain-computer interface unveiled
- AI ‘brain decoder’ can read a person’s thoughts with just a quick brain scan and almost no training
- Elon Musk’s ‘Scary Smart’ Grok 3 Release—What You Need To Know
- SpaceX is so close to turning its rocket headquarters into an actual city
- Who needs Windows 11? FreeXP is a modern version of Microsoft’s greatest OS, powered by Debian Linux
- Microsoft walks back controversial change to sign-in experience
- Microsoft rolls out BIOS update that fixes ASUS blue screen issues
- Microsoft unveils first quantum chip, claims to create novel matter
- Microsoft announces quantum computing breakthrough with Majorana 1 chip
- Microsoft makes another tweak to Windows 11’s taskbar – but it’s probably not the change you were hoping for
- About darn time: Microsoft says it has fixed the annoying lag in Windows Explorer when working with cloud-based files
- Latest Windows 11 update reportedly breaking major parts of the operating system
- Microsoft’s secret Windows 11 tool lets you move data between two PCs
- Microsoft testing fix for Windows 11 bug breaking SSH connections
- Microsoft is paywalling these features in Notepad and Paint
- Debunked: Older Intel chips still supported by Windows 11