
Hello all,
This week’s news has an unusual number of items related to firewalls and networking equipment. Cisco, Fortinet, and SonicWall are all under active attack for known vulnerabilities and are being exploited successfully by malactors to gain unauthorized access to networks. Once there, they then use other products’ vulnerabilities and defects to burrow deeper and do more.
As usual, my commentary is followed by a plethora of links to other items that are worth skimming to see if they interest you or pertain to your particular environment or of those you support.
Headline NEWS:
- CISA added several items to the Known Exploited Vulnerabilites (KEV) catalog this week. Two that I found significant were the ScienceLogic SL1 defect that Rackspace found and reported. The second is for Cisco’s Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), both of which are subject to Denial of Service (DoS) attacks. A third item CISA called-out is for a Cross Site Scripting (XSS) defect in RoundCube webmail.
- Cisco also fixed a defect that allowed for DoS via their VPN when getting password sprayed.
- FortiGate/Fortinet has had rumblings on Reddit for the past week about a major flaw. The manufacturer finally acknowledged the issue and has released version updates and mitigation guidance for this zero-day bug, dubbed FortiJump. Do not delay, this has the potential to compromise every Fortinet product that is managed by your FortiManaager.
- Pwn2Own Ireland just concluded, and more than 70 zero-day vulnerabilities were used by the hackers participating. Expect an incoming storm of patches soon for things such as, QNAP, Synology, TrueNAS, Ubiquiti, Canon, HP, Lexmark, Sonos, and more.
- Unifi, was mentioned a moment ago, they just released an update for their UniFi Network Server, if you use this, update quickly.
- VMware attempted to patch a defect in vCenter last month that was found at the Chinese Matrix Cup competition last month. Apparently, it was only partially successful. Another patch has been released. Update your vCenters as soon as you are able.
In Ransomware, Malware, and Vulnerabilities News:
- Evil increasing should be the headline. This section has several links to items such as Q3 sees 75% Surge in Cyber Attacks, Healthcare sees 300% Surge in Ransomware Attacks, Ransomware gang stoops to new low, AI impersonation, and more. It is vital to stay aware and properly prioritize your mitigation efforts.
In Other News Events of Note and Interest:
- DMCA (Digital Millennium Copyright Act) Exemption for Ice Cream Machines Is a long-awaited headline! Just this week I was at McDonalds wanting a milkshake and their ice cream machine was down. They really should fly their flag at half-mast or something so we don’t waste time pulling in, but I digress. Up until now, only licensed companies were permitted to perform repairs, and apparently those repair people are in short supply. Hence the plethora of broken ice cream machines. Now, any capable technician will be permitted to make needed fixes. Ice Cream and Milkshake lovers rejoice!
In Cyber Insurance News:
- Global Insurance Rates Decline in a sign that insurers are getting a better handle at managing their risks, and clients are becoming more resilient, there are signs that rates are declining.
Musings:
For most of the world we are rapidly approaching multiple holidays. While it is a time for feasting, celebration, fun, family, and friendship, threat actors are well aware that due to the typical end-of-year increase in personal time off, cyber-defenders will be short staffed. The opportunistic dirt bags don’t take these holidays off, so don’t let your guard down so that you can enjoy your time off. Spoil a hacker’s holiday and enjoy yours!

Keep the shields up.
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack
- CISA Warns of Cisco ASA & Roundcube Vulnerabilities Exploited in Wild
- Cisco fixes bug under exploit in brute-force attacks
- Cisco fixes VPN DoS flaw discovered in password spray attacks
- FortiGate admins report active exploitation 0-day. Vendor isn’t talking
- Fortinet warns of new critical FortiManager flaw used in zero-day attacks
- Over 70 zero-day flaws get hackers $1 million at Pwn2Own Ireland
- High-risk vulnerability affecting UniFi Network Server
- VMware Struggles to Fix Flaw Exploited at Chinese Hacking Contest
Ransomware, Malware, and Vulnerabilities News
- House Homeland Security leaders seek briefing on Salt Typhoon attacks from FBI, CISA after telecom breaches
- A Closer Look at Q3 2024: 75% Surge in Cyber Attacks Worldwide
- Four firms charged, fined over handling of SolarWinds hack disclosures
- CISA Warns of Active Exploitation of Microsoft SharePoint Vulnerability
- FBI and CISA investigate Chinese-affiliated hackers in telecom breach
- Half of Organizations Have Unmanaged Long-Lived Cloud Credentials
- AI impersonation is now the hardest cyberattack vector to defend against
- Exploit released for new Windows Server “WinReg” NTLM Relay attack
- Red Hat NetworkManager Flaw Let Attackers Gain Root Access To Linux Systems
- Google Warns of Samsung Zero-Day Exploited in the Wild
- Amazon seizes domains used in rogue Remote Desktop campaign to steal data
- ByteDance intern fired for planting malicious code in AI models
- Internet Archive breached again through stolen access tokens
- Why Phishing-Resistant MFA Is No Longer Optional: The Hidden Risks of Legacy MFA
- Phishing attacks continue to wreak havoc for average Americans
- Bitdefender and Trend Micro security software patched after multiple critical vulnerabilities exposed
- $400,000 Extracted From ATMs Across New York As Criminals Hit Banks in Sophisticated Scheme
- 800,000 people just had their full names, SSNs and more exposed in massive insurance admin company data breach
- Over 6,000 WordPress hacked to install plugins pushing infostealers
- Pixel perfect Ghostpulse malware loader hides inside PNG image files
- DPRK Uses Microsoft Zero-Day in No-Click Toast Attacks
- Unknown threat actors exploit Roundcube Webmail flaw in phishing campaign
- Lazarus Group Exploits Chrome 0-Day for Crypto with Fake NFT Game
- Meet Latrodectus: Initial access brokers’ new favorite malware loader
- CAPTCHAs are novel delivery method for Lumma Stealer malware
- Hackers Using Weaponized RDP Setup Files to Attack Windows Servers
- New Windows Driver Signature bypass allows kernel rootkit installs
- Avast Releases Free Decryptor for Mallox Ransomware
- SonicWall firewalls the common access point in spreading ransomware campaign
- Akira Ransomware is encrypting victims again following pure extortion fling
- Akira Ransomware Actors Developing Rust Variant To Attack ESXi Servers
- Has BlackCat returned as Cicada3301? Maybe.
- Ransomware gang stoops to new low, targets prominent nonprofit for disabled people
- Black Basta ransomware poses as IT support on Microsoft Teams to breach networks
- New Qilin.B Ransomware Variant Emerges with Improved Encryption and Evasion Tactics
- Russia’s APT29 Mimics AWS to Steal Windows Credentials
- Russia sentences REvil ransomware members to over 4 years in prison
- Healthcare Sees 300% Surge in Ransomware Attacks
- 389 healthcare companies hit by ransomware this year, Microsoft finds
Other News Events of Note and Interest
- Cool Tool: UniGetUI is the ultimate package manager for Windows PCs
- 9 useful Windows PowerToys features you might’ve overlooked
- US Copyright Office Grants DMCA Exemption for Ice Cream Machines
- San Francisco to pay $212 million to end reliance on 5.25-inch floppy disks
- Delta sues cybersecurity firm CrowdStrike over tech outage
- Cloudflare: Latest Record-Breaking DDoS Attack Hits 4.2Tbps
- Apple creates Private Cloud Compute VM to let researchers find bugs
- Google Cloud burst by 12-hour power outage in German region
- China Extends the “Great Firewall” Into Space
- Linus Torvalds affirms expulsion of Russian maintainers
- CISA seeks public input on renewed information collection request by November 20
- FTC fake online review ban: Avoid these 5 prohibited practices
- Finland seizes servers of ‘Sipultie’ dark web drugs market
- Huawei makes divorce from Android official with HarmonyOS NEXT launch
- AMD releases new Windows 11/10 chipset driver for Ryzen 9000, 8000, 7000, 5000, 3000, more
- Former Nvidia engineer discovers 41-million-digit prime — largest prime number known to man was uncovered and verified with the help of GPUs
- Recovering ESXi 7.x & 8.x host after forgetting or losing root password
- The Best Ways to Transfer All Your Stuff From Your Old Phone to Your New iPhone 16
- Mozilla advises Firefox users to update if they want their browser add-ons to keep working
- Microsoft confirms app freezes when using camera in Windows 11 24H2
- Microsoft Authenticator gets three major improvements to enable secure authentication
- Microsoft fixes Windows 11 24H2 UI, 8.63GB update data, SFC, DirectAccess bugs
- Microsoft improves multitasking in Office on iOS and Android
- Windows 10 KB5045594 update fixes multi-function printer bugs
- Windows 11 updates now install significantly faster and use less CPU
Cyber Insurance News
- When Cyber Crooks Steal Payments, Think Insurance Makes Up The Loss?
- To insure or not? Cyber insurance helps recover losses from cyberattacks
- Global insurance sees rate declines as property competition heats up