Weekly Cyber Security
News Events &Information
From sources found online in the past seven days
Hello all,
Last week I called it the calm before the storm, boy was it ever! A large swath of vendors released updates for all sorts of vulnerabilities this week. I’ll call some out below but recommend that you check pretty much everything you’re running for updates.
The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.
Notable Callouts:
- Adobe starts out the cavalcade of patching with updates to Acrobat, Reader, and several other products. Don’t wait to apply these as some are critical.
- Apple released updates for iPhones, iPads, macOS, and more. They even backported some updates to older iPhones. Again, don’t wait to update as at least one was a zero-day that was uncovered at Pwn2Own in Vancouver a few months ago.
- Git has fixed five vulnerabilities, the most critical being a Remote Code Execution (RCE) that is triggered when cloning. Since this is something that is commonly done, update quickly.
- Google Chrome had two separate releases to fix zero-day vulnerabilities this week. They were the fifth, sixth and seventh of the year. At this pace, restarting your Chrome browser daily (which triggers an update) to keep safe may be your best bet.
- ICS (Industrial Control Systems) and IoT (Internet of Things) manufacturers Johnson Controls, Siemens, Rockwell, and Mitsubishi all released advisories this week regarding vulnerabilities that they’ve found and/or fixed in their products. There’s a lot, so check the list.
- Intel issued 41 advisories for 90 vulnerabilities across a wide range of products such as processors, graphics cards, UEFI, and more; including a critical 10 out of 10 on the CVSS scale for their Intel Neural Compressor which is used in AI work.
- Microsoft wanting everyone to remember that they were responsible for Patch Tuesday, unleashed 61 updates and addressed 3 zero-days. At least it wasn’t as large as last month’s record-breaking 147 fixes. However, Big-Redmond has yet to fix seven zero-days that were successfully exploited at Pwn2Own in Vancouver earlier in the year. Edge also received five security updates, most were Chromium related (same as Google’s updates), but a few were specific to Microsoft’s browser.
- SAP has plugged critical holes in Customer Experience (CX) Commerce and NetWeaver Application Server ABAP and ABAP Platform, releasing 14 new updates and revising 3. SAP advises customers to update as soon as possible.
- VMware patched three zero-day holes that were successfully used at Pwn2Own in Workstation and Fusion desktop hypervisors. They further fixed an additional item that was reported through Trend Micro’s Zero Day Initiative.
In Ransomware, Malware, and Vulnerabilities News:
- AI Red Teaming tool helped IBM’s X-Force break into a major manufacturer in only 8 hours. As we’ve all said, AI is both an incredible thing and potentially terrifying, if in the wrong hands. Thankfully, this time it was the good guys using it to find issues that were then fixed.
- Justice Dept. FBI, and FCC are all in the news this week, scoring several wins for the good guys!
- SE Asian scammers steal $64 billion annually. Wow! That’s unbelievable.
In Other News Events of Note and Interest:
- Veeam, has announced that their forthcoming version will have native support for Proxmox V With this out there, it looks like Proxmox might just become a viable alternative to Broadcomm’s VMware.
In Cyber Insurance News:
- Should you buy Cyber Insurance is an excellent article that does a great job describing what this product is, and what it does for you.
Clarence Bleicher, President Chrysler Corporation DeSoto automobile division, stated before congress in 1947, “I have taught my foremen this for some months now—if you get a tough job, one that is hard, and you haven’t got a way to make it easy, put a lazy man on it, and after 10 days he will have an easy way to do it…” There’s something to be considered here. As Frank B. Gilbreth Sr discovered in 1920, the lazy person will find a way to “eliminate unnecessary movement and reduce fatigue”. Now don’t get me wrong, I’m not saying that you shouldn’t work hard, but you should be efficient and that means reducing complexity, making things easier, or in another word – convenient. Why am I going down this trail? This past Friday on the Buffalo Plaid Breakfast show, my Co-host, Jeremy, and I talked about Convenience vs. Security. I believe that the notion of reduction of effort is right in line with that theme. So, managers, foremen, bosses of all kinds, if you need to find a way to secure things in a more convenient manner, assign the job to the laziest employee you have. The result may astound you! However, in the famous words of President Regan, “Trust, but verify.”
And remember, keep the shields up. They really are out to get you.
Viscount Zebulon Wamboldt Pike
Red-N Weekly Cyber Security News
Headline NEWS
- Adobe released 8 separate updates for several products
- Adobe Patches Critical Flaws in Reader, Acrobat
- Apple Patch Day: Code Execution Flaws in iPhones, iPads, macOS
- Apple backports fix for RTKit iOS zero-day to older iPhones
- Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own
- Critical Git vulnerability allows RCE when cloning repositories with submodules
- Google Chrome emergency update fixes 6th zero-day exploited in 2024
- Google patches third exploited Chrome zero-day in a week, number 7 for the year
- ICS Patch Tuesday: Advisories Published by Siemens, Rockwell, Mitsubishi Electric
- Intel issues advisories for 90 security vulnerabilities — includes critical level 10 for AI tools
- Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
- Microsoft Has Yet to Patch 7 Pwn2Own Zero-Days
- Microsoft Windows 10 KB5037768 update released with new features and 20 fixes
- Microsoft Windows 11 KB5037771 update released with 30 fixes, changes
- Microsoft Edge gets fixes for five more security vulnerabilities
- SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver
- VMware fixes three zero-day bugs exploited at Pwn2Own 2024
Ransomware, Malware, and Vulnerabilities News
- AI red-teaming tools helped X-Force break into a major tech manufacturer ‘in 8 hours’
- FBI seize BreachForums hacking forum used to leak stolen data
- Justice Dept. makes arrests in North Korean identity theft scheme involving thousands of IT workers
- FCC names and shames Royal Tiger AI robocall crew
- Financial institutions have 30 days to disclose breaches under new rules
- Backlogs at National Vulnerability Database prompt action from NIST and CISA
- GE Ultrasound Gear Riddled With Bugs, Open to Ransomware & Data Theft
- iOS 17.5 includes these 15 security patches for iPhone users
- iPhone owners say the latest iOS update is resurfacing deleted nudes
- CISA Warns of Actively Exploited D-Link Router Vulnerabilities – Patch Now
- PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers
- Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code
- NHS Digital hints at exploit sightings of Arcserve UDP vulnerabilities
- Grandoreiro banking trojan unleashed: X-Force observing emerging global campaigns
- 2023 Kaspersky Incident Response report
- Hackers Weaponize Word Files To Deliver DanaBot Malware
- How attackers deliver malware to Foxit PDF Reader users
- LockBit strikes back with ransomware spree
- Ongoing Malvertising Campaign leads to Ransomware
- WebTPA data breach impacts 2.4 million insurance policyholders
- Windows Quick Assist abused in Black Basta ransomware attacks
- Black Basta target orgs with new social engineering campaign
- Black Basta ransomware group is imperiling critical infrastructure, groups warn
- Botnet sent millions of emails in LockBit Black ransomware campaign
- Australian government investigating ‘large-scale ransomware’ data breach of script provider MediSecure
- Southeast Asian scam syndicates stealing $64 billion annually
- Massive Compilation Of Many Breaches (COMB) data breach reveals info on over a billion people
- Christie’s £670m art auctions hit by cyber attack
- QakBot attacks with CVE-2024-30051 Windows zero-day
- INC ransomware source code selling on hacking forums for $300,000
- Russian hackers use new Lunar malware to breach a European govt’s agencies
- Russian Actors Weaponize Legitimate Services in Multi-Malware Attack
- Russia directing hackers to attack UK and west, says director of GCHQ
- China-Linked Hackers Targeted Commercial Shipping Companies
- China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT
- Head of Canada’s intelligence agency says Chinese government can access TikTok user data
- North Korean Hackers Exploit Facebook Messenger in Targeted Malware Campaign
- Ebury botnet malware infected 400,000 Linux servers since 2009
- Mortgage lender Firstmac cyberattack, customer data, driver’s license numbers, banking details leaked
- Georgia county’s network taken down after potential cyberattack
- Leveraging DNS Tunneling for Tracking and Scanning
- New WiFi Vulnerability: The SSID Confusion Attack
- Helsinki suffers data breach after hackers exploit unpatched flaw
- Ongoing Campaign Bombards Enterprises with Spam Emails and Phone Calls
- Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach
- Notes on ThroughTek Kalay Vulnerabilities and Their Impact on the IoT Ecosystem
- Bank Employee Attacks Hundreds of Accounts, Sells Customers’ Payment and Personal Data in Insider Scheme
- US AI Experts Targeted in SugarGh0st RAT Campaign
- Video shows exactly why you shouldn’t run unsupported Windows and stick to 10/11
Other News Events of Note and Interest
- Cool Tool: VMware giving away Workstation Pro, Fusion Pro free for personal use
- Cool Tool: ADeleg: The Active Directory Security Tool You’ve Never Heard Of
- Cool Tool: Put Rescuezilla 2.5 on a bootable key – before you need it
- Archie, the Internet’s first search engine, is rescued and running
- Arc vs. Edge: Should you switch from Microsoft’s web browser?
- The Fall of the National Vulnerability Database
- Google launches Trillium chip, improving AI data center performance fivefold
- What CIOs need to know about the newly proposed Critical Infrastructure Cyber Incident Reporting Rule
- CISOs and Their Companies Struggle to Comply With SEC Disclosure Rules
- Cyber trust label could be in place by end of the year, White House says
- Free speech scholars skeptical that TikTok ban survives Constitutional challenge
- Veeam acquires ransomware recovery company Coveware
- Private equity company to acquire Squarespace
- Nearly all Nintendo 64 games can now be recompiled into native PC ports
- (Cyber) Risk = Probability of Occurrence x Damage
- MITRE Unveils EMB3D: A Threat-Modeling Framework for Embedded Devices
- Core security measures to strengthen privacy and data protection programs
- Clock is ticking for companies to prepare for EU NIS2 Directive
- Global Chips Battle Intensifies With $81 Billion Subsidy Surge
- Critical infrastructure security will stay poor until everyone pulls together
- RSA Conference 2024: The good, the bad, and the downright worrying
- NIST aims to cut ‘tech speak’ from cyber workforce framework
- Ridding your network of NTLM
- Threat Modeling Process | OWASP Foundation
- Linux Daddy Linus Torvalds releases kernel 6.9
- Go Passwordless: How to Setup a Passkey on Your Google Account
- Google’s new ‘Find My’ device network is useful but a stalking risk
- Tips for navigating and downloading from new Broadcom Support Portal
- Meta is shutting down Workplace, its enterprise communications business
- Microsoft to start enforcing Azure multi-factor authentication in July
- Microsoft aware of Windows Server KB5037765 0x800f0982 error
- Microsoft will add improvements in Outlook to better fight off spam and malicious mails
- Microsoft shares temp fix for Outlook encrypted email reply issues
- Microsoft fixes Windows Server bug causing crashes, NTLM auth failures
- Microsoft fixes broken VPN in Windows 10 and 11 in KB5037771 and KB5037768
- Microsoft is ending Edge support on computers without SSE3
- Veeam Extends Data Freedom for Customers with Support for Proxmox VE