Hello all,
The Red-N Weekly Cyber Security News newsletter is below the Notable Callouts as usual and can be found online as well at https://red-n-security.com.
I thought Patch Tuesday would be the big news item, but Amazon AWS took a major dump this past week and took good chunks of the internet with it for several hours. I tried to ask Alexa what was going on, but alas, she was down too. I breathed a sigh of relief when all was resolved several hours later and the digital apocalypse was averted yet again.
Notable Callouts:
- Amazon – when AWS has issues, it gets noticed quickly. It is amazing how much of our day-to-day lives depend on this cloud megastructure – maybe too much.
- Fortinet showed up in our Red-N-Security Newsletter last week as a late breaking item for their SSL-VPN Remote Code Execution bug. This week they announced that the RCE may have been exploited by threat actors prior to being patched. We generally call that a zero-day Fortinet, just sayin’.
- Microsoft, on the other hand, did not have any zero-days disclosed in their Patch Tuesday releases this past week. There were 78 bugs, including 38 RCEs, so do patch as soon as you vet that they are safe in your network. There were goodies for Exchange, SharePoint, and Office in the releases.
- Microsoft, in this past week’s Patch Tuesday rolled out the third phase of Netlogon and Kerberos hardening that was announced in November 2022. If you experience login and authentication issues after patching, check the logs for these patch enforcement items as a possible issue. Changes and hardening will continue until January 2024.
- SAP also released patches for some high-severity vulnerabilities.
- MOVEit continues to make headlines with victims cropping up worldwide, Cl0P is now releasing names of extorted companies, and this week – a third vulnerability. If you have this, turn off http and https access immediately until a new patch is made available to address this third hole.
- Verizon, the phone giant, publishes a yearly data breach report. We’ve linked this week to a fascinating article that cites the top 10 cybersecurity findings in the 2023 report.
- Windows 11 has a rather strange bug in Patch Tuesday’s KB5027231 where if you have Malwarebytes installed, Google Chrome won’t work. This reminds me of the 1980’s slogan attributed tongue-in-cheek to Microsoft, “Word’s not done until Lotus won’t run.” Malwarebytes has subsequently released a patch to fix this issue.
- In Ransomware, Malware, and Vulnerabilities News, JPL, yes, that JPL! (NASA’s Jet Propulsion Laboratory), has created the world’s largest archive of PDF files to aid in malware research. And an Illinois Hospital is closing, citing, in part, a ransomware incident as cause for their inability to continue to do business.
- In Other News Events of Note and Interest, an excellent article that lists 14 shocking data loss and disaster recovery statistics, such as average downtime being 16.2 days to recover from ransomware. Also, Cyber security favorite, Have I been Pwned has undergone a major update. Check out Troy Hunt’s blog post for more. Finally, Microsoft revealed, that Yes, they were in fact under attack two weeks ago, and that is what disrupted several large portions of their network.
- In Cyber Insurance News, Premiums are surging by up to 50%. And AWS has announced that their customers can get cyber insurance in as little as two days via their partner program.
The internet is like a delicious looking cookie that you just dropped on the floor. As you swiftly pluck it from the linoleum, you mentally contemplate the pathogen count. Do you trust the 5-second-rule? Do you throw it away and get another? Do you trust your immune system to protect you? How much harm could it be? After all, it is just one little cookie, right Do you click the link?
Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News
Headline NEWS
- Outage of Amazon’s cloud service, AWS, causes some websites to go dark
- Fortinet fixes critical RCE flaw in Fortigate SSL-VPN devices, patch now
- Fortinet: New FortiOS RCE bug “may have been exploited” in attacks
- Microsoft June 2023 Patch Tuesday fixes 78 flaws, 38 RCE bugs
- Microsoft rolls out third-phase DC hardening for Kerberos and Netlogon security flaw
- SAP Patches High-Severity Vulnerabilities With June 2023 Security Updates
- MOVEit mayhem 3: “Disable HTTP and HTTPS traffic immediately” – Third vulnerability
- Top 10 cybersecurity findings from Verizon‘s 2023 data breach report
- Windows 11 KB5027231 update breaks Google Chrome for Malwarebytes users
Ransomware, Malware, and Vulnerabilities News
- JPL Creates World’s Largest PDF Archive to Aid Malware Research
- Adversaries increasingly using vendor and contractor accounts to infiltrate networks
- China calls hacking report ‘far-fetched’ and accuses the US of targeting the cybersecurity industry
- The US Navy, NATO, and NASA Are Using a Shady Chinese Company’s Encryption Chips
- Swiss government warns of ongoing DDoS attacks, data leak
- An Illinois hospital links closure to ransomware attack
- Threat intelligence programs poised for growth
- Password Reset Hack Exposed in Honda’s E-Commerce Platform, Dealers Data at Risk
- Americans should prepare for cyber sabotage from Chinese hackers
- Have I Been Pwned warns of new Zacks data breach impacting 8 million
- BreachForums Returns Under the Control of ShinyHunters Hackers
- Obfuscation tool ‘BatCloak’ can evade 80% of AV engines
- Chinese hackers used VMware ESXi zero-day to backdoor VMs
- Brand Impersonation Campaign Targeting Big Brands
- Microsoft 365 Defender Adds Threat-Informed Security Posture Recommendations
- US government extends software security deadline because vendors aren’t ready
- New ‘Shampoo’ Chromeloader malware pushed via fake warez sites
- Russian hackers use PowerShell USB malware to drop backdoors
- U.S. government says several agencies hacked as part of broader cyberattack
- Clop Leaks: First Wave of Victims Named
- Popular email provider leaves systems wide open
- Mercury Marine impacted by ‘IT security incident’
- XSS Vulnerabilities Found in Microsoft Azure Cloud Services
- LockBit Ransomware Extorts $91 Million from U.S. Companies
- WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1
- Researchers Report First Instance of Automated SaaS Ransomware Extortion
- New Supply Chain Attack Exploits Abandoned S3 Buckets to Distribute Malicious Binaries
- Microsoft says early June disruptions to Outlook, cloud platform, were cyberattacks
- From Cryptojacking to DDoS Attacks: Diicot Expands Tactics with Cayosin Botnet
- Proofpoint’s 2023 Human Factor Report: TA’s Scale and Commoditize Uncommon Tools and Techniques
- Text ‘scam’ losses total $330 million in 2022, FBI and UWF cybersecurity expert weigh in
- Business email compromise scams take new dimension with multi-stage attacks
- Cloud Security Incident Response Guidance
Other News Events of Note and Interest
- 14 Shocking data loss and disaster recovery statistics
- People Are Still Terrible at Creating Passwords
- Troy Hunt: Have I Been Pwned Domain Searches: The Big 5 Announcements!
- Microsoft Teams integration is being removed from Windows 11
- Can a chatbot preach a good sermon? Hundreds attend church service generated by ChatGPT
- Apple’s Safari Private Browsing Now Automatically Removes Tracking Parameters in URLs
- Western Digital boots outdated NAS devices off of My Cloud
- ChatGPT Draws The Line: 5 Actions It Flat Out Refuses To Perform
- Lumen, Google, Microsoft unveil new optical networking platform
- Microsoft stole our stolen dark web data, says security outfit
- Google’s AI photo editor lets you use words to describe what to edit
- IT Admins Can Set Up Multi-App Kiosk Mode on Windows 11
- Handy Outlook keyboard shortcuts for Windows and Mac
- Intel releases 31.0.101.2125 Windows WHQL driver for 7th, 8th, 9th, 10th Gen, and more
- Microsoft: Windows 10 21H2 has reached end of servicing
- Microsoft Windows has a secret emergency restart button
- US intelligence confirms it buys Americans’ personal data
- Microsoft fixed a file copy issue that affects 32-bit apps that are large address aware
- Pax8 Unveils Vision for the Future of its Cloud Marketplace
- Pax8 Execs On Revamped Marketplace: MSPs ‘Ready To Move Today’ Will Win
- Microsoft offers workaround for SMB authentication failing in Windows 11
- Microsoft: Windows Kernel CVE-2023-32019 fix is disabled by default
- Everything You Need to Know About MSP Cybersecurity
- Google Tells Employees to Stay Away from Its Bard Chatbot