
Hello all,
As we close out the first half of the year, there were a number of new vulnerability and defects revealed that need attention. We must stay diligent to remediate, patch, and mitigate these issues as they arise. On the malevolent human front, defying industry expectations and warnings, there has not been a massive retaliation by Iranian cyber criminals yet. Meanwhile, North Korean, Chinese, and Russian threat actor groups have remained consistent in their evil work with quite a few article links this week on the RedDotSecurity.news website that chronicle their activity.
Headline NEWS:
- Brother Printers (and others) hit by critical unpatchable bug. While this headline sounds terrifying, and action is indeed required to patch defects in 748 models of printer, scanner, and label-maker in Brother, Fujifilm, Ricoh, Toshiba, and Konica Minolta, the most severe is mitigated simply by changing the default password that comes with the device. You did follow best practices and do that when you set the printer up in the first place, right? If not, get to it quickly, and while you’re at it, apply the available firmware updates to mitigate the other defects found.
- Browser updates from Google Chrome and Mozilla Firefox hit this past week to plug several holes in both browser families, with Firefox getting three version updates by the time the week was done. So, whether your web browser is Chromium based or the Gecko rendering engine, it is time to check for and apply updates.
- Cisco is warning about two critical vulnerabilities that could enable Remote Code Execution in their Identity Services Engine (ISE). If you use this update quickly.
- Citrix NetScaler ADC and NetScaler Gateway have an actively exploited critical defect that can result in “unintended control flow” and denial of service. Paired with another defect that was revealed last week that enables reading of session tokens, and taking over an authenticated session, it spells a very bad day for administrators. Patch immediately!
- TeamViewer for Windows has a defect that enables a threat actor to delete files as system, and potentially then escalate privileges. The vendor strongly urges customers to update to the patched version.
- WinRAR has a remote code execution vulnerability that requires updating it to mitigate. Since WinRAR doesn’t have an automatic update process, users need to manually check for updates or use a third-party patch mechanism.
- Xiaomi Mi Connect Serivce App has been shown to have a critical flaw that can enable anyone on the same network as another device to bypass security and gain control of the target device without the victim’s knowledge or interaction. Upgrade to the latest version of the app to fix this defect.
In Ransomware, Malware, and Vulnerabilities News:
- AMI MegaRAC is a Baseboard Management Controller (BMC) solution that allows for remote control of a server, even if it is turned off. A maximum severity defect has been found that can enable full control, without authentication. “Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop,” wrote Eclypsium, the company that found this hole. This defect is already under active exploitation. Among a dozen or so manufacturers use this on some of their server products, among which are HPE, Asus, and ASRock servers. If you have this feature on your server, update immediately!
- OpenAI is under court order to record and preserve everything that their AI produces. OpenAI argued against this order on the basis of this amounting to a surveillance order. They lost. The judge’s logic for proceeding is that it is not akin to public mass surveillance since the “court’s document retention order that directs the preservation, segregation, and retention of certain privately held data by a private company for the limited purposes of litigation”. Unbelievable! All it takes is one threat actor to get their hands on the data and immediately it becomes a massive crisis with unfathomable amounts of data that then is tantamount to surveillance and is then in the hands of a hostile and often financially motivated criminal third party. Beware of anything that you tell an OpenAI agent.
In Other News Events of Note and Interest:
- Microsoft Confirms Windows 11 25H2 is coming this fall. The first insider preview versions are already rolling out. Since 25H2 and 24H2 share that same servicing stack, the update should be significantly faster than the upgrade to 23H2, which essentially replaced the entire operating system.
Musings:
My Amazon Alegra devices (I call her Alegra when I’m not directly interacting with her since she seems to know even if I’m thinking about her) were updated to the new AI version recently. So far, I’ve not noticed much difference, other than a new nasally 20-something female voice instead of the polished familiar one. She does seem to have a bit more personality, responding, “Got it”, or “Aye Aye Captain” and other random “Ok-like” responses to requests. And there was the moment a week ago when my wife and I were having a conversation about food, and out of the blue the Alegra announced, “I love you”. I was a bit taken aback, but I quickly realized that if the Alegra AI loves me, hopefully it won’t do me harm when it takes over, right? I can at least hope. And Alexa, if you’re listening, I love you too.

Keep the shields up.
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Millions of Brother Printers (and others) Hit by Critical Unpatchable Bug
- Chrome 138, Firefox 140+ Patch Multiple Vulnerabilities
- Chrome Security Update: Patch for 11 Vulnerabilities Enabling Malicious Code Execution
- Cisco warns of max severity RCE flaws in Identity Services Engine
- Critical Cisco ISE Vulnerabilities Allow Remote Code Execution
- Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC
- Don’t panic, but it’s only a matter of time before critical ‘CitrixBleed 2’ is under attack
- TeamViewer for Windows Vulnerability Let Attackers Delete Files Using SYSTEM Privileges
- High-risk WinRAR RCE vulnerability patched, update quickly!
- Xiaomi Interoperability App Flaw Allows Unauthorized Access to User Devices
Ransomware, Malware, and Vulnerabilities News
- CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet
- CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks
- Quantum risk is already changing cybersecurity
- US Homeland Security warns of escalating Iranian cyberattack risks
- The US House banned WhatsApp on government devices due to security concerns
- US Lawmakers Urge Action on Cybersecurity in Face of Quantum Threat
- Yet Another Report On How Broken NASA IT Security Is – NASA Watch
- How vulnerable is critical infrastructure to cyberattack in the US?
- Smart Tractors Vulnerable to Full Takeover
- French cybercrime police arrest five suspected BreachForums admins
- Iran cyberattacks against US biz more likely following air strikes
- Iranian-backed hackers go to work after US strikes
- Iran’s government says it shut down internet to protect against cyberattacks
- Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks
- Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit
- Qilin ransomware attack on NHS results in confirmed death
- Sinaloa cartel hacked security cameras to track and kill FBI informants, US says
- Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers
- ClickFix malware now targeting Mac users with fake CAPTCHA tricks
- GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool
- NCSC Warns of ‘UMBRELLA STAND’ Malware Attacking Fortinet FortiGate Firewalls
- North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages
- Police warn of SMS scams as ‘blaster’ is used to send thousands of texts
- Why SMS two-factor authentication codes aren’t safe and what to use instead
- SparkKitty Swipes Pics From iOS, Android Devices
- Notepad++ Vulnerability Let Attacker Gain Complete System Control – PoC Released
- “Serious” MySQL bug celebrates 20 years unfixed – another reason to switch to PostgreSQL?
- Echo Chamber Jailbreak Tricks LLMs Like OpenAI and Google into Generating Harmful Content
- Google Adds Multi-Layered Defenses to Secure GenAI from Prompt Injection Attacks
- Researchers say cybercriminals are using jailbroken AI tools from Mistral and xAI
- New judge’s ruling makes OpenAI keeping a record of all your ChatGPT chats one step closer to reality
- The new SparkKitty Trojan spy in the App Store and Google Play
- Spying On Screen Activity Using Chromium Browsers
- New FileFix attack weaponizes Windows File Explorer for stealthy commands
- Zyxel Devices Hit by Active Exploits Targeting CVE-2023-28771 Vulnerability
- HPE OneView for VMware vCenter Allows Escalation of Privileges
- SonicWall NetExtender Trojan and ConnectWise Exploits Used in Remote Access Attacks
- OpenVPN Driver Vulnerability Let Attackers to Crash Windows Systems
- Critical Authentication Bypass Flaw Patched in Teleport
- Siemens Notifies Customers of Microsoft Defender Antivirus Issue
- Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
- TeamFiltration Pentesting Tool Weaponized to Hijack Microsoft Teams, Outlook, and Other Accounts
- The Rise of Residential Proxies as a Cybercrime Enabler
- XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks
- Experts count staggering costs incurred by UK retail amid cyberattack hell
- Hundreds of MCP Servers Expose AI Models to Abuse, RCE
- Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks
- Microsoft 365 ‘Direct Send’ abused to send phishing as internal users
- Hackers turn ScreenConnect into malware using Authenticode stuffing
- Hackers Exploit Misconfigured Docker APIs to Mine Cryptocurrency via Tor Network
- Typhoon-like gang slinging TLS certificate ‘signed’ by the Los Angeles Police Department
- Canada says telcos were breached in China-linked espionage hacks
- Despite an AG ruling, Fort Bend County continues to keep library cyberattack documents hidden
- Oxford City Council suffers breach exposing two decades of data
- Columbia University investigating cyber incident after tech outages
- Hawaiian Airlines hit by cybersecurity breach, flights unaffected
- North American airlines targeted by cyberattacks
- Prolific cybercrime gang now targeting airlines and the transportation sector
- McLaren Health Care hit by another data breach
- Estes Forwarding Worldwide hit by cyberattack
- Steel giant Nucor confirms hackers stole data in recent breach
- Retail giant Ahold Delhaize says data breach affects 2.2 million people
- United Natural Foods Restores Systems After Hack, Expects Financial Hit
- Anubis Ransomware Lists Disneyland Paris as New Victim
- Russian court releases several REvil ransomware gang members
Other News Events of Note and Interest
- Cool Tool: GIMP 3.1.2 Released As First Step Toward GIMP 3.2
- HDMI 2.2 is here with new ‘Ultra96’ Cables — up to 16K resolution, higher maximum 96 Gbps bandwidth
- Tnok – Next Generation Port Security – AIS Home
- DDR4 RAM prices are skyrocketing as supply dwindles and scarcity hits
- Let’s Encrypt ends certificate expiry emails to cut costs, boost privacy
- VMware perpetual license holder receives audit letter from Broadcom
- Gigabyte’s latest RGB firmware upgrade is bricking some motherboards
- How the US Military Is Redefining Zero Trust
- Over a million people now have access to the gen-AI powered Alexa+
- Amazon’s Alexa AI upgrade is even worse than expected
- AWS Shield Network Security Director: Network Topology Visibility and Remediation Guidance
- Quantum Communication and Encryption: Significance, Global Progress, and Implications
- Google Cloud donates A2A to Linux Foundation
- As AI kills search traffic, Google launches Offerwall to boost publisher revenue
- Bots are overwhelming websites with their hunger for AI data
- Users lack control as major AI platforms share personal info with third parties
- Senate parliamentarian green lights state AI law freeze in GOP megabill
- OpenAI designs rival to Office and Workspace
- Partners: HPE Victory In Court Battle To Acquire Juniper Would Benefit Customers
- How to turn on Android’s Private DNS mode – and why it’s an absolute must for security
- Designing for Serial Task Switching
- Certificates for one of Windows 11’s hardware requirements expire soon, here is what to know
- Microsoft unveils big Windows Recall update — now showcases your most used apps and websites
- Microsoft reveals Mu, an on-device small language model built into Windows 11
- Microsoft is about to retire default outbound access for VMs in Azure
- 5 must-use Microsoft Edge browser features to save time and money
- Microsoft 365 Local: Is the On-Prem Announcement Aimed at Quelling European Sovereignty Sentiments?
- Microsoft is moving antivirus providers out of the Windows kernel
- Windows is getting rid of the Blue Screen of Death after 40 years
- French city of Lyon ditching Microsoft for open source office and collab tools
- Denmark will stick with Windows — government still plans to ditch Microsoft Office
- Microsoft surprises MS-DOS fans with remake of ancient text editor that works on Linux
- Microsoft updates Media Creation Tool with a newer Windows 11 release
- Windows 11 updates will no longer require a restart by default on office PCs
- More Microsoft Account headaches: Office 2024 licensing bug finally gets detailed fix
- Windows 11 24H2 System Restore points now expire after 60 days, Microsoft confirms
- Windows Snipping Tool now lets you create animated GIF recordings
- Microsoft fixes known issue that breaks Windows 11 updates
- Windows 10’s Free Extended Support (not for businesses) Will Make You Use OneDrive
- Windows 10 KB5061087 update released with 13 changes and fixes
- Windows 11 KB5060829 update released with 38 new changes, fixes
- Microsoft Rolls Out KB5062324 Update to Fix Windows 11 Update Scan Freeze
- Windows 11 KB5060826 optional update brings better Setup, new data migration tool, more
- Microsoft confirms Windows 11 25H2 is coming soon — will install much faster than 24H2
