September 27, 2025

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

Cisco decided to grace us with a major vulnerability, SolarWinds is trying a third time to fix a defect, ransomware is severely impacting European airports, supply chain attacks on NPM packages by worms from Dune, and Windows 25H2 coming soon are just some of the items covered in the list of news items this week.

This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. So, on to the headline news.

Headline NEWS:

  • Cisco IOS XE has a zero-day that is under active attack. By chaining two of the three recently disclosed vulnerabilities, attackers take to heart Cisco’s slogan of “Bridge to Possible” and are able to gain full remote unauthenticated access to affected devices. CISA gave Federal agencies until Friday of this past week to either update or disconnect all of their Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software devices. Upgrade immediately.
  • Libraesva ESG (Email Security Gateway) has a rather severe problem that requires immediate attention. I’ll let their security bulletin speak for itself. “Libraesva ESG is affected by a command injection flaw that can be triggered by a malicious e-mail containing a specially crafted compressed attachment, allowing potential execution of arbitrary commands as a non-privileged user…” If you are a Libraesva cloud client, the patch was automatically applied. If you self-host, check to ensure you’ve been updated, and if not, update as soon as you can.
  • SolarWinds Web Help Desk is being a bit too helpful and could allow threat actors to execute remote code on vulnerable systems. This was originally patched in August 2024, and again in October 2024. And once again this month. Hopefully, they’ve actually patched this defect now. Make sure you update soon. It isn’t known to be under active exploitation yet, but historically, SolarWinds has been a popular target of threat actors.

In Ransomware, Malware, and Vulnerabilities News:

  • Man arrested in UK over cyberattack that has taken down hundreds of flights at European airports, including Dublin, Heathrow, Brussels, and Berlin. Collins Aerospace’s product, MUSE, which is used by multiple airlines for cross-company check-ins and baggage drop-off reportedly suffered a ransomware attack last week, forcing airlines to use manual processes. The manufacturer is working with authorities and forensics firms to restore operations. One of my friends is vacationing in the UK, I wonder…? Nah.

In Other News Events of Note and Interest:

  • IRS touts ‘major progress’ on IT modernization. Reading the article this headline references truly reinforces my assertion that if you really want to make progress, abolish this regressive entity that penalizes productivity. In this writer’s opinion, income by individuals should not be taxed. However, while this onerous agency does exist, I am certainly all for modernizing their arcane systems. But the glacial pace and monstrous costs associated with this make me believe that it will never be accomplished. Some have been underway since 2009! That’s eleven years! The systems will be obsolete before they ever come online into use. The annual exercise of American consumers reporting what they think is correct and then waiting for the Infernal Revenue Service to either agree and issue a refund due to overpayment, or acknowledge receipt of payment due to underpayment, is absurd. They know what we make. Send us a notice with the refund or a bill. Or better yet, let us keep all of our money and tax commerce, not income.

Musings:

Welcome to Pumpkin Spice season. It is that time of year where we find that scent and flavor everywhere. Starbucks, Trader Joe’s, Dunkin’, McDonalds, and more have it in abundance. It wouldn’t surprise me to see Pumpkin Spice offerings by the likes of Microsoft, Google, and Cisco. The holdouts will be Apple with iCinnamon-Spiced offerings and of course Foritnet with their own proprietary FortiSpice. No matter what your preferred seasonal flavor and scent, threat actors are not taking a break. So, enjoy your beverage of choice and…

Visc. Jan Broucinek

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

Share this with: