Hello all,
There are quite a number of things to report on this week. It has been a busy one. Poor Ivanti is still in the news. I’m starting to feel sorry for them. Anyway, let’s move on.
The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.
Notable Callouts:
- Atlassian has patched a bug in Confluence Data Center and Confluence Server that allows unauthenticated Remote Code Execution. It is as bad as it gets with a rating of 10 out of 10. If your version is dated prior to December 5, 2023, you are vulnerable and need to patch immediately and check for compromise. Atlassian noted that end-of-life instances (version 8.4.5 and before) are also affected and will not receive patches. If you have an EOL version, disconnect it from the internet and replace it.
- CISA has directed those under their control to immediately patch the two Ivanti zero-day vulnerabilities (one in Connect Secure VPN and the other in Endpoint Manager) without delay. A new discovery from Volexity revealed that on compromised Connect Secure systems, the internal Integrity Checker Tool was modified to report all was OK despite being compromised. As I said last week, if you have this, unplug it. The scale of the attack is staggering and the subsequent damage to secrets, PII, PHI, and more will be extreme.
- Citrix is in the news again with yet another Netscaler ADC and Gateway appliances zero-days that are actively being exploited. Patch now if you have a supported version. If your Netscaler isn’t supported, both Citrix and I recommend you disconnect it from the internet.
- Google can’t seem to let a month go by without another zero-day being patched in Chrome. This week brought our first for 2024. Thankfully they do an adequate job of updating their browser, provided you restart it or your computer periodically. Of course, a wise move would be to proactively update as soon as a new version is released.
- IT consultant fined is a chilling headline. In essence some dude found a vulnerability and reported it. “He was charged with unlawful data access under Section 202a of Germany’s Criminal Code, based on the rule that examining data protected by a password can be classified as a crime under the Euro nation’s cybersecurity law.” Wow, talk about killing the messenger that is telling you that your dike has sprung a leak.
- Juniper Networks has patched an RCE in Juno OS J-Web configuration interface on SRX firewalls and EX switches. If you have Juno hardware, patch before you become a casualty.
- Oracle unleashed patches for a massive swath of their products addressing 191 CVEs. Unfortunately, just as the last time I reported on this, many patches are behind an Oracle paywall and many are patches that are dependent upon other vendors that must incorporate them into their product updates. More to come on this, I’m sure.
- VMware has confirmed that a critical vCenter bug has been under active exploitation. A patch was released in October… A new vulnerability was found in VMware Aria Automation. There is a patch available, so update as soon as possible.
- XOrg Server and Xwayland display implementations have received patches for a number of vulnerabilities. Patch yours now if you use this.
In Ransomware, Malware, and Vulnerabilities News:
- Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software. I am having a hard time seeing a problem with this. If you use pirated software, you deserve what you get. It reminds me of Mad Magazine’s Spy vs. Spy. In this case one criminal vs. another criminal.
In Other News Events of Note and Interest:
- Inventor of NTP protocol, David Mills passed away at 85. Literally billions of devices every moment of every day rely on Network Time Protocol, which he created. NTP is a vital part of the glue that holds the internet together. The article is well worth reading.
In Cyber Insurance News:
- Southwest Airlines scored a victory and won an appeal against their insurance carrier and lives to fight another day in their claim to receive an insurance payout after suffering what they say should be a covered massive computer failure in 2016 that disrupted travel for nearly a half-million people. Weeks before the July 2016 outage, Southwest had purchased a cyberrisk policy with “system failure” coverage.
Information is readily available everywhere. We are literally bombarded by it daily from every form of imaginable media and source. Some is useful, some is entertaining, some is bland or boring, and some is downright terrifying. Yet none of it does any good if you don’t synthesize what you’re ingesting into some cogent thought and actionable ideas. It is said that data, aka, information doubles every year. In that light, the following may be a controversial statement, but AI is likely the only way we’ll be able to keep up and make sense of those things that truly matter to us individually. Otherwise, what we value will simply be a needle lost in the ever-growing haystack of bits and bytes. However, with an AI assistant tailored to our continually changing tastes, interests, events, roles, and projects, I see great potential for a phenomenal explosion in productivity and efficiency. It is going to be an exciting few years as this all shakes out.
Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News
Headline NEWS
- Atlassian Bug Allows Unauthenticated RCE – Max Severity Rating
- CISA emergency directive: Mitigate Ivanti zero-days immediately
- Citrix warns of new Netscaler zero-days exploited in attacks
- Google fixes first actively exploited Chrome zero-day of 2024
- IT consultant fined for daring to expose shoddy security
- Ivanti patches a critical bug in Ivanti Endpoint Manager that would allow for device take over
- Thousands of Juniper Networks devices vulnerable to critical RCE bug
- Oracle January 2024 Critical Patch Update Addresses 191 CVEs
- VMware confirms critical vCenter flaw now exploited in attacks
- XOrg Server and Xwayland Patched Against Multiple Security Vulnerabilities
Ransomware, Malware, and Vulnerabilities News
- Ivanti Connect Secure VPN Exploitation Goes Global
- Ivanti Connect Secure VPN Exploitation: New Observations
- Microsoft executive emails hacked by Russian intelligence group
- Critical Vulnerabilities Found in Open Source AI/ML Platforms
- How hackers are making Google Ads a dangerous threat
- FBI: Androxgh0st malware botnet steals AWS, Microsoft credentials
- Homeland Security warns of hackers targeting Google Chrome, Excel spreadsheets
- Just ten groups were responsible for nearly half of all cyberattacks last year
- GitHub rotates keys to mitigate impact of credential-exposing flaw
- Hacker spins up 1 million virtual servers to illegally mine crypto
- MacOS info-stealers quickly evolve to evade XProtect detection
- Windows SmartScreen flaw exploited to drop Phemedrone malware
- Remote Code Execution Vulnerability Found in Opera File Sharing Feature
- Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers
- BreachForums hacking forum admin sentenced to 20 years supervised release
- Possible cyberattack disrupts classes at Kansas State University on first day of new semester
- A negotiator says a ‘bad day’ is likely coming for K-State after cybersecurity breach
- Npm Trojan Bypasses UAC, Installs AnyDesk with “Oscompatible” Package
- Innefu Labs Data Breach: Major Cyberattack Hits Indian Cybersecurity Firm
- US court docs expose fake antivirus renewal phishing tactics
- Over 178K SonicWall firewalls vulnerable to DoS, potential RCE attacks
- Vulnerabilities Expose PAX Payment Terminals to Hacking
- PixieFail flaws impact PXE network boot in enterprise systems
- Bigpanzi botnet infects 170,000 Android TV boxes with malware
- Google: Russian FSB hackers deploy new Spica backdoor malware
- Docker hosts hacked in ongoing website traffic theft scheme
- Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software
- Detecting iOS malware via Shutdown.log file
- Kaspersky releases utility to detect iOS spyware infections
- Unpatched Rapid SCADA Vulnerabilities Expose Industrial Organizations to Attacks
- Microsoft: Iranian hackers target researchers with new MediaPl malware
- Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
- Have I Been Pwned adds 71 million emails from Naz.API stolen account list
- TeamViewer abused to breach networks in new ransomware attacks
- JPMorgan Chase says hacking attempts are increasing
- Chinese hackers exploit VMware bug as zero-day for two years
- New Bluetooth vulnerability allows takeover of iOS, Android, Linux, and MacOS devices
- Vans, Supreme owner VF Corp says hackers stole 35 million customers’ personal data
- CISA, FBI warns of Chinese-manufactured drones
- Quantum Computing to Spark ‘Cybersecurity Armageddon,’ IBM Says
- Invoice Phishing Alert: TA866 Deploys WasabiSeed & Screenshotter Malware
- UC Irvine students sent to hospital after hackers send graphic images to their Discord server
- Graphics card flaw enables data theft in AMD, Apple, and Qualcomm chips by exploiting GPU memory
Other News Events of Note and Interest
- Cool Tool – WinToUSB 8.5
- Cool Tool – Rufus 4.4.2103
- Cool Tool – VirtualBox 7.0.14
- Cool Tool – Media Player Classic – Home Cinema 2.1.4
- Cool Tool – WSCC – Windows System Control Center 7.0.7.7
- Cool Tool – How to set up a powerful home VPN with Tailscale
- FTC secures first databroker settlement banning sale of sensitive location data
- As hacks worsen, SEC turns up the heat on CISOs
- Starlink authorizes Peplink as its first technology provider
- Apple’s App Store rule changes draw sharp rebuke from critics
- What is credential stuffing and how can I protect myself?
- What Is Microsoft Edge Workspaces and How to Use It?
- Microsoft launches a Pro plan for Copilot
- Microsoft Drops the Restrictions for Copilot for Microsoft 365
- Microsoft working on a fix for Windows 10 0x80070643 errors
- Microsoft Teams meeting reminders are coming to the Windows 11 Start menu
- Microsoft releases new free Windows 11 virtual machines with the latest updates
- Windows Server 2022 KB5034129 crashes Edge, Chrome and Firefox with white screen
- NIST Offers Guidance on Measuring and Improving Your Company’s Cybersecurity Program
- Google to shut down Business Profile websites starting March
- Google updates Chrome Incognito disclaimer amid $5 billion lawsuit settlement
- Google now admits it could collect data in Chrome’s Incognito mode
- AMD’s new CPUs will halve your SSD speed and slash GPU performance
- Inventor of NTP protocol that keeps time on billions of devices dies at age 85
- British Library begins restoring digital services after cyber-attack
- Shop Safely: How to Set Up Passkeys for Your Amazon Account
- You want the CISO Title & Pay? Responsibility Comes Also!
- VMware End of Availability on Many VMware vSphere Editions
- Wine 9.0 released with major enhancements
- SSDs pricing to ‘skyrocket’ as flash shortages are already underway
- Computer RAM gets biggest upgrade in 25 years but it may be too little, too late
- Intel releases January 2024 drivers updates for Windows 11, Windows 10 with BSOD fixes
- National Cyber Director to Address Cybersecurity Talent Shortage by Removing Degree Requirement
Cyber Insurance News
- With Attacks on the Upswing, Cyber-Insurance Premiums Poised to Rise Too
- To Reverse Escalating Cyber Risk, Start Thinking Like A Cyber Insurer
- Risk of cyber incidents weigh heavily on businesses for 2024, report finds
- Southwest Airlines Wins Cyber Insurance Appeal Against Liberty
- Allianz Risk Barometer: A Cyber Event Is the Top Global Business Risk for 2024