Hello all,
Happy first week of 2024! Thankfully, the digital apocalypse did not happen over the Christmas and New Years’ holiday period. Yet there are still plenty of news items relating to Cyber Security out there that were reported in the past seven days, some tragic, some comical, some that just make you go ‘huh?’. Read on faithful cyber warrior to see what they are.
The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.
Notable Callouts:
- 23andMe the DNA database company was hacked recently. In a mindboggling PR move they are blaming the victims for reusing passwords. A simple feature known as 2FA would have rendered that moot. I suspect that this will not go well for them.
- Apache ERP specifically Apache OFBiz had a zero-day vulnerability that they remediated last week. Apparently the first patch wasn’t quite sufficient, and another had to be pushed out on its heels. If you use this check for updates.
- $10.5 Trillion is the estimated global total that cyberattacks may soon cost. That is shocking!
- Ivanti makers of Endpoint Management software (EPM) have released a patch that should be applied immediately by anyone using this software. The exploit, under the right conditions, is trivial.
- Juniper patched multiple vulnerabilities in their Juniper Secure Analytics – JSA Series Virtual Appliance. The vulnerability has a CVVS score of 9.8 out of 10. Prioritize this patch.
- Finland experienced “unprecedented Global Positioning System (GPS) interference” at the end of December. If this is some new sort of cyberattack, I’m going to be very unhappy. I may need to resort to a paper map again. And I pity the younger generation. I don’t think most know what a map even is.
In Ransomware, Malware, and Vulnerabilities News:
- San Francisco-based Orrick, Herrington & Sutcliff an international law firm dealing with cyber incidents and victims was itself a victim. And it looks like the evil hacking scum got everything – passports, government ID numbers, medical info, addresses, birth dates… and the list goes on. Unbelievable. You’d think the legal eagles would have had the data encrypted, having seen this same thing happen to their hapless clients over the years.
In Other News Events of Note and Interest:
- Open Source AI voice cloning is now here, for free. Reports are that it is pretty good, not perfect, but it works. I suspect that we’ll see this perfected by year’s end. You will soon not be able to trust what you hear. And video is not that far behind.
- Kohler’s Newest Bidet Finally Brings Alexa and Google to Your Butt. Huh? I think I’ll just let the headline speak for itself here. No, I won’t. There are some places where AI does not belong. Ok, now I’ll let the headline sit on the throne.
In Cyber Insurance News:
- Merck settles with insurers who denied $700 million NotPetya claim In 2017 the NotPetya cyberattack hit Merck (and many others). Insurance carriers tried to get out of paying by citing “acts of war” clauses. It looks like they settled this case just before the last appeal.
Digital technology is a wonderful thing that has truly enhanced our lives in myriad ways. However, it is vital to remember that we are in fact organic beings and require time among other organic beings and in nature for us to recharge. Make sure that you are taking care of your personal machine at least as much as you are your digital servants.
Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News
Headline NEWS
- 23andMe tells victims it’s their fault that their data was breached
- Apache ERP Zero-Day Underscores Dangers of Incomplete Patches
- Cyberattacks Might Soon Cost Businesses $10.5 Trillion Every Year
- Ivanti warns critical EPM bug lets hackers hijack enrolled devices
- Juniper Releases Security Advisory for Juniper Secure Analytics
- NATO Nation Hit By ‘Unprecedented’ GPS Attack
Ransomware, Malware, and Vulnerabilities News
- How ransomware could cripple countries, not just companies
- First American says system has been restored; perpetrator stole data
- The State of Ransomware in the U.S.: Report and Statistics 2023
- Cybersecurity Year in Review 2023: A zero-day nightmare
- 21 New Mac Malware Families Emerged in 2023
- Snatch Ransomware: Digital Cat and Mouse
- How To Disable LLMNR & Why You Want To
- Oops! Black Basta ransomware flubs encryption
- How End-Users Bypass Exchange Online Protection
- Hackers employ nuanced tactics to evade detection
- Law firm that handles data breaches was hit by data breach
- Cybercriminals Flood Dark Web with X (Twitter) Gold Accounts
- Millions still haven’t patched Terrapin SSH protocol vulnerability
- Mandiant’s account on X hacked to push cryptocurrency scam
- New DLL Hijacking Technique-Attackers Bypass Windows Security
- Nearly a million people exposed after ambulance service attack
- New JinxLoader Targeting Users with Formbook and XLoader Malware
- New ‘SpectralBlur’ macOS Backdoor Linked to North Korea
- New Bandook RAT Variant Resurfaces, Targeting Windows Machines
- Kai Zhuang: Cyber kidnapping in US illustrates growing crime trend
- Lawmakers must build on Feds’ ransomware success in 2024
- Ransomware payment ban: Wrong idea at the wrong time
- Dangerous new malware uses cookies to break into Google accounts
- INC RANSOM ransomware gang claims to have breached Xerox Corp
- Xerox says subsidiary XBS U.S. breached after ransomware gang leaks data
- Don’t trust links with known domains: BMW affected by redirect vulnerability
- UAC-0050 Group Using New Phishing Tactics to Distribute Remcos RAT
- Barracuda Says ‘Small Number’ Of ESG Customers Impacted In New Attacks
- Android game dev’s Google Drive misconfig highlights cloud security risks
- Online museum collections down after cyberattack on service provider
- Russia Kyivstar Hack Should Alarm West, Ukraine Security Chief Warns
- Zeppelin ransomware source code sold for $500 on hacking forum
- SMTP Smuggling: New Flaw Lets Attackers Bypass Security and Spoof Emails
- Kaspersky reveals previously unknown hardware ‘feature’ exploited in iPhone attacks
- Freight giant Estes refuses to deliver ransom, says personal data opened and stolen
- Popular Password Vault Was Breachable By Bypassing Windows Hello Security Measures
- Post-quantum cryptography: Encryption upgrade in 2024 will keep data safe from quantum computers
Other News Events of Note and Interest
- How IBM Stumbled Onto RISC
- UAE Banks on AI to Boost Cybersecurity
- The Drive Stats of Backblaze Storage Pods
- On January 1, 30 years ago, Windows 3.11 released
- 2024 could mark the end of the road for passwords
- SpaceX’s Latest Launch Will Bring Starlink to T-Mobile Phones
- FTC offers $25,000 prize for detecting AI-enabled voice cloning
- 4 keys to cybersecurity to improve your digital habits
- Key cybersecurity skills gap statistics you should be aware of
- Emerging cybersecurity trends and expectations for 2024
- Google Just Disabled Cookies for 30 Million Chrome Users
- Google Groups is ending support for Usenet to combat spam
- Ex-Googler of 15 Years Says Tech Giant Is Rife With Fiefdoms
- Google has been lying to us for years about the Incognito Mode
- New registrations plummet after Squarespace takes over Google Domains
- Accounts in danger: Google recommends enhanced safe browsing and extra care
- Knightscope receives Authority to Operate within the U.S. government
- BreachForums admin jailed again for using a VPN, unmonitored PC
- Kohler’s Newest Bidet Finally Brings Alexa and Google to Your Butt
- Wi-Fi 7 ( 802.11be): The new wireless network standard explained
- Have 10 Hours? IBM Will Train You in AI Fundamentals – For Free
- Open source AI voice cloning arrives with MyShell OpenVoice
- NIST: If someone’s trying to sell you some secure AI, it’s snake oil
- Biggest AI trends of 2024: According to top security experts
- Google wants to know what new Bard features you want in 2024
- Tetris was finally beaten after 34 years, game kill screen pops up at Level 157
- Statcounter: Microsoft Edge edges near 12% market share for the first time
- PowerToys will soon get a redesigned Keyboard Manager with new features
- LastPass now requires 12-character master passwords for better security
- Microsoft and Oracle Launch Oracle Database@Azure for Azure Customers
- Microsoft’s new Copilot key is the first big change to Windows keyboards in 30 years
- Introducing a new Copilot key to kick off the year of AI-powered Windows PCs
- Microsoft-branded accessories transition to the Incase brand
- Microsoft kills off Windows app installation from the web, again
- PowerToys’ upcoming tool will help you use PowerShell
- Microsoft Teams added lots of improvements in December including in-chat searches
- The oldest-known version of MS-DOS’s predecessor has been discovered and uploaded
- New proposed rule for CMMC 2.0 lays out security requirements, raises some eyebrows