
Hello all,
After a slow start to the week, we closed it out with a few very serious vulnerabilities made public by Cisco, SonicWall, and Ubiquiti. This coming week is Patch Tuesday and if historic numbers are a valid guide, I expect about 40 items to be patched by Microsoft, and a normal smattering from other vendors.
Headline NEWS:
- Cisco released patches to plug 35 holes and defects across several products, the most severe of these has a CVSS of 10.0 and can enable full root access. These defects are in Cisco IOS XE Wireless Controllers, the management API of Catalyst Center, and the CLI of Catalyst SD-WAN Manager. Additionally, they updated their list of products affected by the critical Erlang/OTP SSH security defect, as well as the status of any patches.
- Microsoft has announced a new OneDrive feature that is slated for release next month – the ability to sync both personal OneDrive and Corporate OneDrive content. While this sounds like a great productivity boost, it is massive vulnerability being created by Big Redmond that will facilitate simple exfiltration of files, and it will be enabled by default! What are they thinking? This is not “Secure by Design”. If you manage systems and don’t want this glaring hole available, you’ll need to disable this newly announced “feature” via Intune policy, Group Policy Object, or Registry change.
- SonicWall sent out notices to customers that SMA100 Series VPN appliances need patching to fix three defects. If not patched, attackers can gain root access. Amazingly, their email to customers essentially said that these older VPN technology devices should be replaced with new technologies – even though they are still being supported – due to the difficulty in securing VPNs.
- SysAid, an IT Management product, revealed four critical defects that can be used to enable root access in the on-premise versions of their software. The fix is to update to the latest version, and you should do so quickly since a Proof of Concept (PoC) exploit is already available. The last one of these a couple of years ago was used by ransomware operators to wreak havoc on SysAid customers.
- TeleMessage is an encrypted communication platform used by the US Government. It was hacked, leaking sensitive conversations, contact information of government officials, back-end login credentials for TeleMessage; and more. The application itself was not the issue, but instead the message archive location was not encrypted and that’s where data was able to be extracted. Smarsh, the company that owns TeleMessage is still investigating.
- Ubiquiti released updates to their UniFi Protect Cameras and the UniFi Protect Application to plug holes that can allow Remote Code Execution (RCE). These defects have a CVSS of 10.0, so make sure to get this applied quickly to avoid being compromised.
In Ransomware, Malware, and Vulnerabilities News:
- PowerSchool was exfiltrated and ransomwared in December of 2024. At the time, PowerSchool paid the ransom in an attempt to keep the stolen data from ever becoming public. And the criminals behind the attack promised that they’d deleted the data. Well, they lied. Schools across North America have started receiving emails demanding payment to prevent release of information which has been shown to contain, “students’ and staffers’ names, contact information, birthdays, medical information, parental information, and in some cases Social Security numbers”. I guess you can’t trust criminals to keep their word, who knew?
- LockBit Ransomware Gang Hacked in a bit of vigilante justice, XOXO from Prague has struck again and hacked into some of LockBit’s infrastructure and has released a nice trove of information to the world. The parting shot on LockBit’s admin panels all read, “Don’t do crime CRIME IS BAD xoxo from Prague”. Thank you Czech Mate.
In Other News Events of Note and Interest:
- Energy use in Kuwait fell by over 50% after crypto mining crackdown is a startling statistic that shows how much power is needed to perform this activity. The locations that were shut down were consuming 20 times more power per month than the average Kuwaiti home. In a somewhat related article, Google agrees to fund the development of three new nuclear sites, adding to one other that they’ve already committed to purchasing power from. This need for power is driven by the rapid expansion of AI and the voracious power needs of the datacenters to enable our new overlords’ functions.
Musings:
Since this is coming out on Mother’s Day Weekend, here in the USA, I’m taking a moment to honor the legacy of the Mother of Modern Programming, Admiral Grace Hopper December 9, 1906 – January 1, 1992. She was singularly responsible for revolutionizing how we interacted with and programmed computers, coming up with the idea of a compiler that converted English terms into Computer programming code. And she succeeded, radically transforming programming. Her opus was to create COBOL (an acronym for COmmon Business-Oriented Language) a programing language which is still in use today. To all of the mothers out there, Happy Mother’s Day!

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT
- Cisco Patches 35 Vulnerabilities Across Several Products
- Cisco IOS XE Vulnerability Allows Attackers to Gain Elevated Privileges
- Cisco IOS XE Wireless Controllers Vulnerability Lets Attackers Seize Full Control
- Microsoft OneDrive New Feature Allows Default Sync of Personal & Corporate Accounts
- SonicWall urges admins to patch VPN flaw exploited in attacks
- Multiple SonicWall SMA 100 Vulnerabilities Let Attackers Compromise Systems
- SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root
- SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
- TeleMessage, a modified Signal clone used by US govt. officials, has been hacked
- Ubiquiti UniFi Protect Camera Vulnerability Allows Remote Code Execution by Attackers
Ransomware, Malware, and Vulnerabilities News
- Windows RDP Bug Allows Login With Expired Passwords
- Microsoft Defends Controversial RDP Behavior: Revoked Passwords Still Work for Remote Access
- CISA warns of hackers targeting critical oil infrastructure
- FBI: End-of-life routers hacked for cybercrime proxy networks
- Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks
- 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
- Florida bill requiring encryption backdoors for social media accounts has failed
- I set up an SSH honeypot, and the internet is a scary place
- Apple notifies new victims of spyware attacks across the world
- Apache Parquet exploit tool detect servers vulnerable to critical flaw
- Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
- Why MFA is getting easier to bypass and what to do about it
- How cybercriminals exploit psychological triggers in social engineering attacks
- RSAC wrap: AI and China on everything, everywhere, all at once
- Separating Fact from Fiction: Here’s How AI Is Transforming Cybercrime
- Google rolls out AI tools to protect Chrome users against scams
- Darcula PhaaS steals 884,000 credit cards via phishing texts
- Sophisticated PhaaS Phish Toolkits are Now Generating Realistic Fake Phishing Pages
- New Chinese Smishing Kit Dubbed ‘Panda Shop’ Steal Google, Apple Pay & Credit Card Details
- CoGUI phishing platform sent 580 million emails to steal credentials
- Malicious PyPi package hides RAT malware, targets Discord devs since 2022
- Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
- Mirai Botnet Actively Exploiting GeoVision IoT Devices Command Injection Vulnerabilities
- Hackers Weaponizing PDF Invoices to Attack Windows, Linux & macOS Systems
- This has been the largest DDoS attack of 2025: What happened?
- Early 2025 DDoS Attacks Signal a Dangerous Trend in Cybersecurity
- New T1555.003 Technique Let Attackers Steal Passwords From Web Browsers
- Legacy Login in Microsoft Entra ID Exploited to Breach Cloud Accounts
- 19 billion passwords compromised — here’s how to protect yourself right now
- Major password breach sees over 19 billion leaked
- Email-Based Attacks Top Cyber Insurance Claims
- North Korean’s OtterCookie Malware Upgraded With New Features for Windows, Linux & macOS
- New Chimera Malware That Outsmarts Antivirus, Firewalls, & Humans
- Google links new LostKeys data theft malware to Russian cyberspies
- Critical Microsoft Telnet 0-Click Vulnerability Exposes Windows Credentials
- New “Bring Your Own Installer” EDR bypass used in ransomware attack
- Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware
- UDP Vulnerability in Windows Deployment Services Allows 0-Click System Crashes
- Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
- iHeartMedia suffers breach
- Over 1.1 million user files leaked following huge data breach at top jobseeker platform
- VC giant Insight Partners confirms investor data stolen in breach
- Education giant Pearson hit by cyberattack exposing customer data
- PowerSchool paid a hacker’s ransom, but now schools say they are being extorted
- School districts hit with extortion attempts months after education tech data breach
- New Mamona Ransomware Attack Windows Machines by Abusing Ping Commands
- Qilin Ransomware Ranked Highest in April 2025 with Over 45 Data Leak Disclosures
- Play Ransomware Group Used Windows Zero-Day
- Play ransomware exploited Windows logging flaw in zero-day attacks
- Kickidler employee monitoring software abused in ransomware attacks
- Coweta County Schools becomes latest victim of ransomware attack
- Iowa County computer network outage caused by ransomware
- 160-Year-Old IT Firm Closed Following Ransomware Attack: Director Sounds Alarm
- LockBit ransomware gang hacked, victim negotiations exposed
Other News Events of Note and Interest
- Cool Tool: AI taught to analyze Windows crash dumps, released to open source
- Cool Tool: Windows 11/10 package manager UniGetUI gets big performance boost with TRIM support
- Star Wars cargo robot follows people around and carries their objects like a backpack
- LegoGPT creates Lego designs using AI and text inputs — tool now available for free to the public
- Claude is quietly crushing it — here’s why it might be the smartest AI yet
- Cursor is now free for Students
- OpenAI abandons plan to become a for-profit company
- How to Prevent AI Agents From Becoming the Bad Guys
- AI code is legacy code from day one
- Maker of AI ‘vibe coding’ app Cursor hits $9bn valuation
- Microsoft 365 Copilot Chat gets SafeLinks protection and more
- Musk’s Colossus is fully operational with 200,000 GPUs backed by Tesla batteries
- Satya Nadella says AI performance is doubling every 6 months
- Clippy resurrected as AI assistant — project turns infamous Microsoft mascot into LLM interface
- An Interview with Meta CEO Mark Zuckerberg About AI and the Evolution of Social Media
- Google Releases 76-Page Whitepaper on AI Agents: A Deep Technical Dive into Agentic RAG, Evaluation Frameworks, and Real-World Architectures
- Energy use in a Kuwaiti city fell by over 50% after authorities cracked down on crypto mining
- Google agrees to fund the development of three new nuclear sites
- Amazon, CrowdStrike, Google and Palo Alto Networks claim no change to threat intel sharing under Trump
- Why Windscribe’s court case proves how important VPN no-logging policies are
- Eric Schmidt apparently bought Relativity Space to put data centers in orbit
- Citrix finds new use for virtualization: Avoiding PC price hikes caused by tariffs
- Surfshark launches DNS servers
- Some Connecticut schools evacuated over ‘dangerous’ TikTok trend
- Broadcom Sends Cease-and-Desist Letters to VMware Perpetual License Holders
- Meet Sdelete, the obscure Microsoft tool that wipes data for good
- Introducing a new generation of Windows experiences – Copilot+ PC Agent can change settings
- How to disable Microsoft Recall (yes, you can turn it off)
- 10 passkey survival tips: Prepare for your passwordless future now
- Microsoft’s new “passwordless by default” is great but comes at a cost
- Users left deeply concerned as Microsoft announces major move to a ‘passwordless’ world
- Microsoft adopts Google’s standard for linking up AI agents
- Microsoft Announces Limited-Time Windows 365 Discount
- Microsoft finally making Windows New Outlook and Classic switching attractive for haters
- Microsoft silently fixes Start menu bug affecting Windows 10 PCs
- Microsoft: April updates cause Windows Server auth issues
- Microsoft pushes fix for Windows 11 24H2 update failures
- Windows 11 now auto-downloads the 24H2 update, whether you want it or not
- Windows 11 Version 24H2 Enters Final Deployment Phase, Microsoft Lists Known Issues
- Windows 11 Enterprise to Get First Hotpatch Update This Month