Hello all,
It has been a busy news week with quite a few critical items, some of which are already being exploited. One item that jumped out at me was a report from Guru Baran, the co-founder of Cyber Security News. His article’s headline reads, 40,000+ CVEs Published In 2024, Marking A 38% Increase From 2023. Let those numbers sink in for a moment. Did your budget or staff scale up proportionally? Baran reported that 108 new vulnerabilities showed up daily on average, with May 3rd seeing 824 of them. Additionally, 231 of the 2024 defects received a Common Vulnerabilities and Exposure (CVE) score of a perfect 10.0. All I can say is bring on the AI, there’s no way that we humans can keep up with this onslaught. There’s a lot more that happened in the last week, so onward.
As usual, my commentary is followed by a plethora of links to other items that are worth skimming to see if they interest you or pertain to your particular environment or of those you support.
Headline NEWS:
- Google Chrome and Mozilla Firefox both received updates this past week. For Chrome’s part, it would appear that yet another cylinder of the V8 JavaScript Engine was misfiring and needed repair. Both vendors fixed several flaws, so update them if you’ve got them.
- GFI Keri Control Firewall has an unpatched vulnerability that has an available Proof of Concept (PoC) exploit. This defect exists in versions 9.2.5 through 9.4.5. So far there has been no response from GFI.
- Ivanti has yet another zero-day that is under active exploitation, and as a result their Ivanti Connect Secure appliances are rather insecure right now with threat actors installing malware called ‘Dryhook’ and ‘Phasejam’ on them. Google’s Mandiant believes that the exploitation began in mid-December and is the work of Chinese based attackers. Ivanti urges that you run their Integrity Checker Tool, and perform a factory reset and then upgrade to the latest versions. Several other of their products, apparently sharing a codebase, have a similar defect and require updating. If you use this, you may already be compromised. Quickly take the appropriate measures.
- License Plate Readers from Motorola are leaking data and video in real time. Motorola responded that the issue is due to misconfigurations and will be fixed quickly and upcoming firmware will include additional security hardening. It is bad enough that the government is tracking my every move, I’ve pretty much resigned myself to that reality, but for any script-kiddie out there have the same ability is a bit much.
- SonicWALL revealed a new critical vulnerability in their SSL-VPN this past week. They urge immediate updates to the latest SonicOS firmware versions. The new firmware also addresses several other less critical defects.
- Robot Vacuums Hack to Spy on their Owners. I have to say it, this sucks. Not only is my vehicle travel being spied on, now my vacuum cleaner is a double-agent? Dirtbags have taken control of formerly well-behaved cleaners and reprogrammed them to chase pets and spew racial slurs from their microphones. Couple this with the newest dirt-suckers that were just revealed at the Las Vegas Consumer Electronic Showcase (CES), that have robotic arms attached to them so they can move objects out of their way, and you have the makings of a Hollywood horror movie.
In Ransomware, Malware, and Vulnerabilities News:
- PowerSchool is a hosted platform for K-12 schools that offers tools that encompass the gamut of the execution of learning and management of education. Sadly, they experienced a breach in their PowerSchool Student Information System (SIS) platform that resulted in the exfiltration of a massive amount of data. They have over 18,000 customers in more than 90 countries, serving 60 million students. For their part, PowerSchool says that they’ve paid the ransom demand and that the enterprising criminals behind this massive attack cooperated and the “data has been deleted without any further replication or dissemination.” Uh huh. Nice political statement, but what part of “criminal” did they miss? I have no doubt that their purloined data will be sold and disseminated – a lot.
In Other News Events of Note and Interest:
- New HIPAA rules coming this year. Recognizing that many of the voluntary portions of the Health Insurance Portability and Accountability Act of 1996 and the 2003 HIPAA Security Rule protections set forth around Electronic Protected Health Information (ePHI) are not being implemented, or are ineffective, The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) has proposed modifications to HIPAA protections, which are now under a 60-day public comment period at regulations.gov. If enacted, this will bring sweeping changes and significant hardening, mandatory encryption, enhanced controls, regulatory oversight, and massive updates to what has been shown to be a toothless law – up to now. If enacted, this new rule will require that HIPAA regulated entities such as healthcare providers, health plans, clearinghouses, business associates, and vendors, comply with all security standards, with very limited exceptions. Once enacted, HIPAA entities will be given 180 days to become compliant. Let the mad scramble begin.
Musings:
The Los Angeles fires are truly tragic in their scope, seeing the devastation is heartbreaking. In security there is a holy triad of Confidentiality, Integrity, and Availability. I can’t help but wonder how many of the businesses that have been scrubbed from the face of the earth by the massive conflagration had an Incident Response Plan that foresaw this eventuality, a Disaster Recovery Plan that tells them what to do in this scenario, and a Business Continuity Plan that will enable them to survive and somehow be available to employees and customers. Don’t wait until you smell smoke.
Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Update Chrome and Firefox now to patch these critical security flaws
- GFI Kerio Control Firewall Vulnerability Allows 1-Click Remote Code Execution
- Ivanti warns of new Connect Secure flaw used in zero-day attacks
- Ivanti Warns of New Zero-Day Attacks Hitting Connect Secure Product
- Google: Chinese hackers likely behind Ivanti VPN zero-day attacks
- Misconfigured license plate readers are leaking data and video in real time
- SonicWall urges admins to patch exploitable SSLVPN bug immediately
- Robot Vacuums Hacked To Spy On Their Owners
Ransomware, Malware, and Vulnerabilities News
- 40,000+ CVEs Published In 2024, Marking A 38% Increase From 2023
- Cybersecurity Trends to Watch in 2025
- How AI will transform cybersecurity in 2025 – and supercharge cybercrime
- Cryptocurrency wallet drainers stole $494 million in 2024
- CISA says Treasury was the only US agency breached via BeyondTrust
- Treasury hackers also breached US foreign investments review office
- Cybersecurity Experts Explain Why China’s Alleged U.S. Treasury Hack Is a Big Deal
- Only 26% of Europe’s top companies earn a high rating for cybersecurity
- Proton worldwide outage caused by Kubernetes migration, software change
- A Day in the Life of a Prolific Voice Phishing Crew
- Beware, that Social Security email could be hiding dangerous malware
- Multiple Vulnerabilities Found in Palo Alto Networks Expedition Tool
- Dell Update Package Framework Vulnerability Let Attackers Escalate Privileges
- How initial access brokers (IABs) sell your users’ credentials
- The TikTok Ban Heads to the Supreme Court Today. Here’s What to Know.
- Billionaire Frank McCourt’s Project Liberty bids for TikTok
- Mitel 0-day, 5-year-old Oracle RCE bug under active exploit
- 2 HIPAA Business Associates Pay HHS Ransomware Settlements
- Ransomware is doubling down — What you need to know about the recent surge
- Critical Infrastructure Ransomware Attack Tracker Reaches 2,000 Incidents
- Researchers Expose NonEuclid RAT Using UAC Bypass and AMSI Evasion Techniques
- PowerSchool hit by cyberattack which saw student and teacher data stolen
- PowerSchool data breach leaks info of students and staff at schools across the US
- PowerSchool Reportedly Pays Ransom to Prevent Student Data Leak
- Cybersecurity issues impact 2 Maine public school districts
- Addison Northwest School District shuts down computers after cyberattack
- School districts in Maine, Tennessee respond to holiday cyberattacks
- Data about N.J. students, teachers stolen in nationwide cyberattack
- Mid-Michigan school records impacted by data breach
- Security pros baited with fake Windows LDAP exploit traps
- Facebook awards researcher $100,000 for finding bug that granted internal access
- New Banshee Stealer Variant Bypasses Antivirus with Apple’s XProtect-Inspired Encryption
- Casio says data of 8,500 people exposed in October ransomware attack
- Google warns of legit VPN apps being used to infect devices with malware
- Criminals backdoored the backdoors they supplied to other miscreants. Then the domains lapsed
- Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers
- New Mirai botnet targets industrial routers with zero-day exploits
- PoC Exploit Released for Windows Registry Privilege Elevation Vulnerability
- PoC Exploit Released For OpenSSH Arbitrary Code Execution Vulnerability
- PoC Exploit Released For Apache Struts Remote Code Execution Vulnerability
- Online gift card store exposed hundreds of thousands of people’s identity documents
- Nuclei flaw lets malicious templates bypass signature verification
- Redis Server Vulnerabilities Let Attackers Execute Remote Code
- STIIIZY data breach exposes cannabis buyers’ IDs and purchases
- Nikki-Universal Cyber Attack – Hackers Claim 761.8 GB of Data Stolen
- Green Bay Packers defenses breached as fans’ credit card details stolen
- American Addiction Centers data breach affected 400K+, class action claims
- Visionworks data breach compromised info of about 40K customers, class action claims
- Ransomware Targeting Infrastructure Hits Telecom Namibia
- Space Bears Ransomware: What You Need To Know
- Japan links Chinese hacker MirrorFace to dozens of cyberattacks targeting security and tech data
- Telefónica confirms internal ticketing system breach after data leak
- Chinese hack of US telecoms compromised more firms than previously known, WSJ says
- China’s Salt Typhoon Adds to Telecom Cyber Victim List
- Chinese hackers ran amok in US telecom network for 18 months — got info on over 1 million people
- China Condemns US Sanctions Over Hacking Attacks
- Eagerbee backdoor deployed against Middle Eastern govt orgs, ISPs
- WordPress Backup Plugin Vulnerability Affects 3+ Million Sites
Other News Events of Note and Interest
- Cool Tool: Wireshark 4.4.3 released: Updated protocol support, bug fixes
- The best smart home tech of CES 2025
- In Appreciation: Amit Yoran, Tenable CEO, Passes Away
- Palisades and Eaton wildfires burn out of control across Los Angeles area
- New HIPAA rules coming
- Website certificates that expire every six weeks? What IT should know
- Banks’ IT Priorities—And What They Could Mean For Businesses In 2025
- White House new cyber EO would give CISA more authorities
- US govt launches cybersecurity safety label for smart devices
- US military allocated about $30 billion to spend on cybersecurity in 2025
- Dell kills the XPS brand
- Dell Announces All-New Branding with Dell, Dell Pro and Dell Pro Max Laptops
- TSMC Arizona allegedly now producing AMD’s Ryzen 9000 and Apple’s S9 processors
- What the End of U.S. Net Neutrality Means
- Meta is ending its fact-checking program in favor of a ‘community notes’ system similar to X’s
- Nvidia announces $3,000 personal AI supercomputer called Project Digits
- Broadcom filing mentions major VMware Cloud Foundation releases in March and July
- Roborock’s Roomba competitor gets a robot arm
- LG and Samsung are adding Microsoft’s Copilot AI assistant to their TVs
- What Is an AI Agent? A Computer Scientist Explains the Next Wave of AI Tools
- Microsoft surprises analysts with massive $80B AI investment plans for 2025
- Microsoft is using Bing to trick people into thinking they’re on Google
- In a machine-led economy, relational intelligence is key to success
- Comparing CMD, PowerShell, and Windows Terminal
- Don’t Ignore These 10 Wi-Fi Network Security Tips
- 2025 End-of-Support Milestone in Microsoft 365
- The unlicensed OneDrive free ride ends this month
- How to Set Up Quick Share on Windows for Painless File Transfers
- Windows 10 users urged to upgrade to avoid “security fiasco”
- Microsoft declares 2025 ‘the year of the Windows 11 PC refresh’
- Microsoft keeps backporting Windows 11 24H2 features to Windows 11 23H2
- Windows 11 update allows installation on older PCs, finally easing restrictions
- New year, new Windows 11 24H2 bug to add to the list: 13 and counting
- Windows 11 24H2 to get new features in February
- Microsoft to force install new Outlook on Windows 10 PCs in February
- Microsoft fixes bug causing Outlook to freeze when copying text
- Microsoft fixes OneDrive bug causing macOS app freezes
- Microsoft embarrasses itself with Windows 10 pop-up that hogs the desktop urging an upgrade to Windows 11 – then promptly crashes
- Microsoft confirms Windows 11 Explorer overlaps content bug
- Microsoft Teams Introduces a Live Chat Widget for Customer Service