
Hello all,
Most of us in the United States celebrated Labor Day, and the unofficial end of Summer with a much-deserved day off from work. It was a welcome respite to enjoy the company of friends, family, and if you were so inclined, the eating of burgers and hotdogs. Even though much of the year has now passed, the cyber-landscape remains relatively the same, defenders are still doing their best and evil people are continuing to do their worst. So far, the holy grail of AI stopping attacks hasn’t quite come to fruition, but there are glimmers of hope on the horizon along with plenty of sad reports. So, let’s get to the news from this past week and read all about it.
As usual, my commentary is followed by a plethora of links to other items that are worth skimming to see if they interest you or pertain to your particular environment or of those you support.
Headline NEWS:
- Cisco has released a couple of updates that are rather important. One is for their Smart Licensing Utility to close a backdoor of an “undocumented” hard-coded admin account. A what!? Yeah, an admin account, and this isn’t the first time they’ve had to fix such an issue. It sounds like something a developer was working on was forgotten before it went to release. This software defect is as serious as it gets. If you’re using this apply the fix immediately!
- Microsoft Windows Proof of Concept (PoC) code has been made available for a Windows Kernel Privilege Escalation vulnerability. This particular defect was patched by Redmon in last month’s Patch Tuesday updates. If you haven’t applied the patches by now, it may be too late, but hey, better late than never. Do it now!
- Progress Software makers of LoadMaster just released an emergency fix for a remote code execution (RCE) defect. This one has a severity value of 10 out of 10. So, if you use Load Master, (even out of support versions) stop what you’re doing and apply the new add-on package immediately! Then after doing so, follow their security hardening guidelines.
- SonicWall warned last week about a critical access control defect in SonicOS that affects Gen 5 – 7 firewalls. Toward the latter part of this past week SonicWall reissued the alert and said that active exploitation of the vulnerability has been observed. Further, it was determined that SSLVPNs that use local credentials on Gen 5 and Gen 6 versions are severely impacted. Guidance is to update the firewall software, and then ensure that MFA is enabled on all SSLVPN accounts and then require password resets of all users. Additionally, as a part of this issue (which is best practice anyway) you should, “restrict firewall management access to trusted sources or disable WAN management access from the internet.” Do not wait to apply the patches and mitigations, rampant threat actor probing is underway, and exploitation is happening.
- Veeam Software has fixed 18 high and critical severity flaws in Veeam Backup & Replication, Service Provider Console, and Veeam One. The most serious is an RCE in Backup & Replication that can result in full compromise.
- WhatsUp Gold is a stalwart in the monitoring arena, having been around for decades informing admins and technicians of issues with their systems. Progress Software has released several patches recently to fix defects that can allow for RCE, and SQL injection and theft of information. Updates are available from the manufacturer, and have been for some time, yet over 1,200 of these unpatched systems are still visible on the internet. Come on people, patch this stuff! PoC already exists out there to exploit some of these identified defects.
- Zyxel has released patches for a large number of their firewalls. At least one flaw allows for an unauthenticated attacker to execute OS commands. Patch quickly.
In Ransomware, Malware, and Vulnerabilities News:
- The NSA, FBI, CISA, US Dept. Treasury, US State Department, CNMF, MIVD, VZ, BIS, KAPO, VDD, SBU, CERT-UA, CSIS, CSE, ASD’s ACSC, and NCSC-UK have issued a joint 36-page PDF document describing and decrying Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. It is a lot to digest, but worth reading with sound analysis and recommendations. Summary, Russia bad.
- Critical Infrastructure sustained 13 cyberattacks per second in 2023. That is a staggering headline. And it is not slowing down in 2024.
In Other News Events of Note and Interest:
- Microsoft PowerToys is getting more new features and capabilities. If you’ve not played with this versatile Redmon Army Knife, give it a go.
- The ‘Ban TikTok’ movement is losing momentum among Americans. We defenders are clearly losing in the mindspace security war. The public is so inundated by breaches and vulnerabilities that they’ve become inoculated to news and facts and simply don’t care anymore. “I just want my dancing cat videos…China can have my data”.
In Cyber Insurance News:
- Big names proposing cyber insurance backstop. With the ever-looming specter of a catastrophic event, reminiscent of CrowdStrike’s recent spectacular failure, insurers are increasingly pushing for government-backed help in the event of something that is truly apocalyptic in nature to insurers.
Musings:
Next week is Patch Tuesday from Microsoft and a large swath of cyber vendors worldwide. By now you should have vetted, tested, and applied the August releases from last month. If you haven’t, get to it since PoC’s have been out for a while for some of the most severe vulnerabilities. And there’s still the looming unpatched “downdate” flaw in Microsoft Windows. Hopefully, Big Redmon plugs that particular massive hole this coming week. Much care will be warranted on this one due to the immense complexity of this issue. Vet carefully as it will have wide-reaching impact inside of Microsoft’s operating systems. You don’t want the cure to be worse than the disease.

Keep the shields up.
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Cisco warns of backdoor “undocumented” admin account in Smart Licensing Utility
- PoC Exploit Released for 0-Day Windows Kernel Privilege Escalation Vulnerability
- Progress LoadMaster vulnerable to 10/10 severity RCE flaw
- SonicWall SSLVPN access control flaw is now exploited in attacks
- Veeam warns of critical RCE flaw in Backup & Replication software
- Critical Flaws in Progress Software WhatsUp Gold Expose Systems to Full Compromise
- Zyxel warns of critical OS command injection flaw in routers
Ransomware, Malware, and Vulnerabilities News
- NSA, FBI, CISA, and Allies Issue Advisory about Russian Military Cyber Actors
- CISA Flags ICS Bugs in Baxter, Mitsubishi Products
- Maryland attorney announces indictments against 6 Russian nationals in cyberattacks
- The FBI’s Unsettling Warning About Charging Phones At The Airport
- FBI: North Korean Actors Readying Aggressive Cyberattack Wave
- FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals
- Biden admin pushing ‘promise’ of AI for cyber defense
- White House Addresses BGP Vulnerabilities in New Internet Routing Security Roadmap
- Homeland security hopes to scuttle maritime cyber-threats with port infosec testbed
- Critical infrastructure sustained 13 cyber attacks per second in 2023
- Despite cyberattacks, water security standards remain a pipe dream
- File-sharing phishing attacks zero-in on the financial sector
- Apache OFBiz Unauthenticated RCE (Fixed)
- PoC Exploit Released for Linux Kernel Vulnerability that Allows Root Access
- Google releases Pixel update to get rid of surveillance vulnerability
- Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401
- City of Columbus hires law firm to help handle cybersecurity attack
- Columbus data breach: Experts say alleged lack of encryption a failing
- Global Phishing Scam Hits Canadian Pizza Chains for Credit Card Data
- Transport for London faces ‘ongoing cyber security incident’
- Transport for London cuts data feeds to travel apps amid cyber-attack
- Business services giant CBIZ discloses customer data breach
- Hacktivist Group Exploit WinRAR Vulnerability to Encrypt Windows & Linux
- Revival Hijack supply-chain attack threatens 22,000 PyPI packages
- Ransomware crisis deepens as attacks and payouts rise
- Ransomware demands exponentially increase, averaging $1.5 Million this year
- Ransomware attacks escalate as critical sectors struggle to keep up
- Cicada3301 Ransomware Targets Windows and Linux/ESXi Hosts
- Iran pays millions in ransom to end massive cyberattack on banks
- Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data
- Meet RansomHub, gang allegedly behind Halliburton cyberattack
- Halliburton confirms data was stolen in ongoing cyberattack
- Microchip Technology confirms data was stolen in cyberattack
- Car rental giant Avis discloses data breach impacting customers
- New ManticoraLoader Malware Attacking Citrix Users To Steal Data
- UniFi Network Application 8.4.59 out with improvements and fixes
- Debian 12.7 “Bookworm” Released with 55 Security Updates and 51 Bug Fixes
- California man loses life savings, owes more than $30,000 in taxes after scam
- Data breach victims skyrocket over 1,100%: How to protect yourself
- Are Cyber Attacks Increasing in 2024?
- 170 million strong data leak traced to US data broker
- New Haven, CT Public Schools’ IT director fired following $6M lost in cyberattack
- Android Users Urged to Install Latest Security Updates to Fix Actively Exploited Flaw
- Sextortionists are claiming to have installed Pegasus spyware on victim’s devices
- The underground world of black-market AI chatbots is thriving
- Vulnerabilities In Two WordPress Contact Form Plugins Affect +1.1 Million
- Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPress
- RAMBO Attack Steals Data From Air-gapped Systems
- New malicious MS Office macro clusters discovered
- YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel
- New Deloitte report addresses increasing danger of cyber threats in space, issues call to action
- OnlyFans Hack Gone Wrong – How Cyber Criminals Turn into Victims Overnight
- Red Teaming Tool Abused for Malware Deployment
Other News Events of Note and Interest
- Cool Tool: New Windows PowerToy launches, repositions apps to saved layouts
- Cool Tool: Microsoft PowerToys: Advanced Paste Tool Overview
- Upgrades to Ubuntu 24.04 LTS Paused Due to ‘Critical Bug’
- NIST Proposes New Cybersecurity and AI Guidelines for Federal Government Contractors
- Bluetooth 6.0 has officially launched – here’s what the upgraded standard can do
- Forget about gigabit network cards, a startup you never heard of wants to sell you a terabit SuperNIC
- The ‘Ban TikTok’ Movement Is Losing Momentum Among Americans
- What is the Shared Fate Model? And is it time to push for it?
- Building a Culture of Email Security Awareness
- The Internet Archive Loses Its Appeal of a Major Copyright Case
- AT&T Sues Broadcom Over VMware Contracts ‘Bullying’
- Inside CISA’s Unprecedented Election Security Mission
- Indicted pair of foreign nationals were behind swatting attack on CISA director
- FCC finally gets around to banning Kaspersky from telecoms kit
- Army set to require SBOMs for new software by early next year
- US and UK sign legally enforceable AI treaty
- California lawmakers approve legislation to ban deepfakes, protect workers and regulate AI
- Musk’s xAI Supercomputer Goes Online With 100,000 Nvidia GPUs
- Zen Browser is a no-Google zone that offers tiling nirvana
- Mozilla Firefox 130 Is Now Available for Download, Here’s What’s New
- Elastic’s return to open source
- Intel strikes back against Windows on Arm
- 3 reasons you should you be using VLANs on your home network
- Personhood Credentials: Everything to Know About the Proposed ID for the Internet
- This hidden Windows 11 setting lets you kill unresponsive apps much more quickly
- Copilot for Microsoft 365 might boost productivity if you survive the compliance minefield
- Microsoft exec says AI tools should learn to ask for help to curb the spread of misinformation
- The New Outlook for Windows Is Getting More Improvements
- How to disable grouping in Windows 11 Downloads folder
- Microsoft Office 2024 to disable ActiveX controls by default
- Microsoft explains in detail how to fix slow Windows 11/10 startup performance
- Microsoft Remote Desktop has a new name, and people hate it
- Microsoft will hold another streaming event devoted to OneDrive reveals on October 8
- Thanks to Microsoft’s WDDM 3.2, Windows 11 24H2 may get fewer graphics driver crashes
Cyber Insurance News
- Insurance groups urge state support for ‘uninsurable’ cyber risks
- Technology closing the cyber resilience gap for insurers
- Big names proposing cyber insurance backstop