
Hello all,
You’d think that there’d be a bit less chaos a whole week after Patch Tuesday. Well, you’d be wrong. On Tuesday November 18, 2025, Cloudflare botched a routine update and took down major portions of their network and as a result a large swath of the internet. One of my favorite stories was about the website downdetector being down. This site is where people report and see what sites are having issues. Someone quickly made a downdetectordowndetector site. But, just in case that was down as well, someone made a downdetectordowndetectordowndetetor and on it went. There is an article linked in our Other News Events of Note and Interest section about this bit of comic relief that came about due to a day of major frustration. In addition to the above mess, there was quite a bit of other news to report about. So, onward.
This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. So, on to the headline news.
Headline NEWS:
- Fortinet Warns of a New FortiWeb Vulnerability. Last week we reported that there was a major defect in FortiWeb. This week another hole was patched. Update quickly if you use this.
- Grafana Enterprise patched a maximum severity defect in SCIM (System for Cross-domain Identity Management) which could allow for privilege escalation and use impersonation. Since this tool ties into your identity provider, it is vital that you patch quickly to prevent compromise not only of the items Grafana is orchestrating, but also your IDAM systems.
- Microsoft was hit with a Distributed Denial of Service attack by the Aisuru botnet that employed more than 500,000 attack sources and hit a whopping 15.72 Tbps. Though it didn’t reach the record of 22.2 Tbps, it was still impressive, consuming enough bandwidth to stream 1 million 4K videos simultaneously.
- Salesforce says some of its customers’ data was accessed after Gainsight’s breach. This story is still evolving as the investigation is ongoing. Mandiant has been brought in by Gainsight to investigate, and it has reported that over 200 companies were affected in this supply chain breach, that may actually be a result of another earlier breach of SalesloftDrift, where Gainsight was a victim.
- SolarWinds Patches Three Critical Serv-U Vulnerabilities is a headline that should make anyone that lived through the 2020 Orion supply chain attack shudder a bit. These flaws are in their Serv-U file-transfer utility and could allow for remote code execution (RCE). There were also some other patches released for their Observability Self-Hosted that plug Cross Site Scripting (XSS) defects. Vet these soon and apply quickly.
- SonicWall released new firmware for their Gen7 and Gen8 SonicOS SSLVPN software. If left unpatched, a threat actor can send specially crafted packets to affected units that can crash the firewall, causing it to reboot, resulting in a denial-of-service attack. Gen6 firewalls are not known to be vulnerable to this attack, nor is it currently known to be exploited in the wild – yet.
In Ransomware, Malware, and Vulnerabilities News:
- Oracle E-Business Suite victims are piling up like a high-speed autobahn accident, including Oracle itself. The evil organization known as Cl0p has claimed that they have exfiltrated data from Oracle, Cox Enterprises, Broadcom, and dozens of other companies, in a crime spree that goes all the way back to April 2025. This is the Christmas fruitcake gift that will be giving for quite some time, I fear.
In Other News Events of Note and Interest:
- IRS deploys AI agents through Salesforce’s AI program. That sounds like a nice recipe for disaster to me. I just hope that the IRS hasn’t been using Salesloft Drift or Gainsight. Otherwise, the IRS’ databases might be in threat actors’ hands already. But even if they aren’t yet. If recent experience with AI agents is any indication and especially given the apparently failings of our government’s technology initiatives, such as the decades long modernization effort, it is only a matter of time before the AI-IRS agent hallucinates some hefty bills or refunds for taxpayers, or helpfully gives private information out to anyone who asks in the right way. Nope, I do not like this one bit.
Musings:
In the United States of America, this coming week is when we celebrate the holiday of Thanksgiving, a day when we pause with family, loved ones, friends, and even strangers to share a meal and to reflect on the blessings that we have in our lives. There’s always something to be thankful for. And I am thankful for you, my readers and viewers; thankful that you continue to fight the good fight, thankful that you do not give up in the face of unrelenting opposition by increasing hordes of evil. And I am grateful that you dedicate yourselves to tirelessly watching, monitoring, analyzing, and fighting back the attacks. You are true unsung heroes. I pray that your Thanksgiving holiday is a peaceful and uninterrupted one. And of course, even though the tryptophane fueled stupor of too much food and holiday cheer may be there…

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild
- Grafana Enterprise security update: critical severity security fix for CVE-2025-41115
- Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation
- Microsoft: Azure hit by 15 Tbps DDoS attack using 500,000 IP addresses
- Microsoft Azure Blocks 15.72 Tbps Aisuru Botnet DDoS Attack
- Salesforce says some of its customers’ data was accessed after Gainsight breach
- Google says hackers stole data from 200 companies following Gainsight breach
- SolarWinds Patches Three Critical Serv-U Vulnerabilities
- New SonicWall SonicOS flaw allows hackers to crash firewalls
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- CISA gives govt agencies 7 days to patch new Fortinet flaw
- CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks
- CISA warns Oracle Identity Manager RCE flaw is being actively exploited
- Myanmar military raids online scam hub, arrests nearly 350 on Thai border
- Data centers in the Netherlands raided, 250 servers seized
- US, UK, and Australia sanction Russian ‘bulletproof’ web host used in ransomware attacks
- Europe is scaling back its landmark privacy and AI laws
- Russian hacking suspect wanted by FBI arrested on Thai resort island of Phuket
- TV streaming piracy service with 26M yearly visits shut down
- International operation traces $55 million crypto trail of digital piracy sites
- Take fight to the enemy, US cyber boss says
- FCC to vote on reversing cyber rules adopted after Salt Typhoon hack
- US states consider banning VPNs for minors
- State-level crackdowns in the US threaten to ‘break VPN access for the entire internet,’ claims online privacy nonprofit
- Cloudflare hit by outage affecting global network services
- Cloudflare issues disrupt internet service
- Cloudflare outage causes error messages across the internet
- Cloudflare Outage Not Caused by Cyberattack
- Cloudflare says outage that hit X, ChatGPT and other sites is resolved
- SEC Drops Remaining Claims Against SolarWinds Over 2020 Hack
- Vulnerabilities and Exploits
- Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability
- Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day
- New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT
- Hackers Leverages Microsoft Entra Tenant Invitations to Launch TOAD Attacks
- Watch out – this fake Microsoft Teams app is actually dangerous malware
- Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums
- New MobileGestalt Exploit for iOS 26.0.1 Enables Unauthorized Writes to Protected Data
- IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands
- Meta Expands WhatsApp Security Research with New Proxy Tool and $4M in Bounties This Year
- Uhale digital picture frames are secretly installing malware on boot, exposing home networks and personal data globally to hackers
- Bypassing WiFi Client Isolation
- A Cracker Barrel vulnerability
- 50k more ASUS routers pwned by evolving Beijing-linked op
- Hackers Attacking Palo Alto Networks’ GlobalProtect VPN Portals with 2.3 Million Attacks
- D-Link warns of new RCE flaws in end-of-life DIR-878 routers
- W3 Total Cache WordPress plugin vulnerable to PHP command injection
- WhatsApp Vulnerability Exposes 3.5 Billion Users’ Phone Numbers
- Multi-threat Android malware Sturnus steals Signal, WhatsApp messages
- Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability
- Give Us Your Face or Lose Your Account: AI Age Verification Is Here, and Experts Are Worried
- Iranian Hackers Target Defense and Government Officials in Ongoing Campaign
- AI Attack Surface: How Agents Raise the Cyber Stakes
- Security 101: Cyber Training Still Fails Miserably
- Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image
- Disgruntled IT worker pulls massive cyber stunt in Houston
- Phishing, Malware, and similar
- AI-powered cyberattacks surge as Anthropic unveils China hack
- Researchers Detailed Techniques to Detect Outlook NotDoor Backdoor Malware
- Be careful responding to unexpected job interviews
- 5 Reasons Why Attackers Are Phishing Over LinkedIn
- ‘MatrixPush’ C2 Tool Hijacks Browser Notifications
- Unremovable Spyware on Samsung Devices Comes Pre-installed on Galaxy Series Devices
- Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT
- China’s ‘PlushDaemon’ APT Hijacks Software Updates
- Cursor Issue Paves Way for Credential-Stealing Attacks
- North Korean threat actors use JSON sites to deliver malware via trojanized code
- EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
- Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar
- Sneaky2FA PhaaS kit now uses redteamers’ Browser-in-the-Browser attack
- LLM-generated malware improving, but not operational (yet)
- APT24’s Pivot to Multi-Vector Attacks
- US Secret Service issues holiday warning on insidious new techniques cyber criminals are using to defraud Chicago-area victims
- Breaches, Leaks, and Ransomware
- Veeam Analysis: Ransomware Payments Decline, But Data Resilience Remains Critical for EMEA Enterprises
- Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack
- Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack
- Cox Enterprises discloses Oracle E-Business Suite data breach
- Iberia discloses customer data leak after vendor security breach
- Hackers claim to have hit Under Armour in massive data breach
- North Korean Hackers Infiltrated 136 U.S. Companies to Generate $2.2 Million in Revenue
- Pennsylvania AG confirms data breach after INC Ransom attack
- Eurofiber confirms November 13 hack, data theft, and extortion attempt
- UK cyber ransom ban risks collapse of essential services
- Princeton University Data Breach Impacts Alumni, Students, Employees
- Surveillance tech provider Protei was hacked, its data stolen, and its website defaced
- AI misuse fears grow after Anthropic reports China-linked cyber campaign
- Eurofiber France warns of breach after hacker tries to sell customer data
- LG battery subsidiary says ransomware attack targeted overseas facility
- Hyundai AutoEver America hack exposes 2,000 employee records and data
- ‘The Gentlemen’ Ransomware Group with Dual-Extortion Strategy Encrypts and Exfiltrates Data
- Tsundere Botnet Abusing Popular Node.js and Cryptocurrency Packages to Attack Windows, Linux, and macOS Users
Other News Events of Note and Interest
- Cool Tool: PowerToys 0.96 is out with new features to Command Palette, Light Switch, and other modules
- Thunderbird adds native support for Microsoft Exchange accounts
- Mushroom Color Atlas
- PC hobbyist charged $684 in tariffs on $355 shipment of parts as low-value import exemptions vanish
- Elon Musk tried to bury tape forever, yet LTO just fired back with a 40TB beast for the AI era
- Meta wins monopoly trial, convinces judge that social networking is dead
- Server virtualization market heats up to win VMware refugees
- Google adds new “Images” tab for visual inspiration
- Google’s latest swing at Chromebook gaming is a free year of GeForce Now
- X launches Chat, its new encrypted DMs
- SAP apologizes for customer portal outage
- Europe joins the US as an exascale superpower
- TaskHound Tool – Detects Windows Scheduled Tasks Running with Elevated Privileges and Stored Credentials
- Towards interplanetary QUIC traffic
- Memory chip crunch set to drive up smartphone prices
- Veeam bets on more VMware alternatives
- After Downdetector itself went down, someone made a Downdetector Downdetector, and then someone made a Downdetector Downdetector Downdetector, and then…
- AI, LLM’s, and Skynet
- ChatGPT Achieves a New Level of Intelligence: Not Using the Em Dash
- ChatGPT launches group chats globally
- A free version of ChatGPT built for teachers
- IRS deploys AI agents through Salesforce’s AI program
- Google to release Nano Banana Pro next week
- WeatherNext 2: Google DeepMind’s most advanced forecasting model
- Introducing Microsoft Agent Factory
- Microsoft Sentinel MCP server – Generally Available With Exciting New Capabilities
- Yann LeCun Has Been Right About AI for 40 Years. Now He Thinks Everyone Is Wrong
- I Scammed My Internet Provider to Try to Lower My Bill – Business Insider
- Amazon satellite network gets a rebrand — and drops its affordability pitch
- Judge dismisses lawsuit twice due to alleged deepfake video testimony
- Microsoft is preparing Copilot for Chrome, because not everyone wants to use Edge
- Microsoft
- Windows 1.0 released 40 years ago this week – and started Microsoft’s road to success
- What’s new in Microsoft Intune at Ignite – Microsoft Intune Blog
- Introducing Windows Admin Center: Virtualization Mode (vMode)
- Microsoft Teams Adds Option to Report Misidentified Threat Messages
- Windows Digital Signage mode hides BSoDs after 15 seconds
- Security Copilot for SOC: bringing agentic AI to every defender
- Microsoft 365 Copilot’s Project Opal aims to eliminate mundane tasks
- Microsoft finally admits almost all major Windows 11 core features are broken
- Nvidia confirms Windows 11 25H2, 24H2 update is hurting gaming performance, releases a new driver
- Microsoft: Windows bug blocks Microsoft 365 desktop app installs
- Microsoft announces potential game-changer feature for Word and PowerPoint
- Microsoft to integrate Sysmon directly into Windows 11, Server 2025
- Microsoft really wants partners to use the new Outlook, offers free service for transition
- Windows Autopatch — Elevate Your Update Experience for Modern Work
- Microsoft unveils Agent 365 to help companies control, track AI agents
- Windows 11’s November patch brings new annoying issues with it
- Microsoft: Out-of-band update fixes Windows 11 hotpatch install loop
- Windows 11 is getting a new point-in-time restore feature and other advanced recovery tools
- Microsoft warns IT admins that Windows Server 2025 is the last edition to support WINS
