CyberHub Podcast Recap: Patch Tuesday and Major Security Incidents
Good morning, Security Gang!
Today’s episode of the CyberHub Podcast is packed with critical updates and actionable insights. Here’s a breakdown of the latest cybersecurity news and what you need to do to stay protected.
RADIUS Protocol Vulnerability
Researchers have discovered a 30-year-old design flaw in the RADIUS protocol, which is widely used in network access control. The flaw, known as "Blast Radius," can allow attackers to bypass multi-factor authentication (MFA) and gain unauthorized access to networks.
Action Items:
Upgrade all RADIUS servers immediately to mitigate this vulnerability.
Conduct a thorough review of your network access controls to identify potential risks.
Evolve Bank and Trust Data Breach
Evolve Bank and Trust notified 7.6 million Americans of a data breach following a LockBit ransomware attack. The breach exposed personal and financial information.
Action Items:
Enroll in the offered credit monitoring and identity protection services by October 31.
Monitor financial accounts for any suspicious activity and report anomalies immediately.
Arabian Travel Agency Data Breach
A significant data breach at the Arabian Travel Agency compromised sensitive information of over 1.2 million individuals, including Air India customers and UAE visa applicants.
Fujitsu Data Breach
Fujitsu confirmed a data breach impacting sensitive information after malware spread to 49 computers within their network.
Patch Tuesday Updates
Microsoft released patches for 143 security flaws, including two critical vulnerabilities under active exploitation.
Action Items:
Prioritize patching systems affected by CVE-2024-38080 and CVE-2024-38112.
Regularly update all software to the latest versions to mitigate vulnerabilities.
Adobe Security Updates
Adobe released critical patches for Premiere Pro, InDesign, and Bridge, addressing several high-severity vulnerabilities.
Action Items:
Apply Adobe’s latest patches to affected software immediately.
Regularly check for updates and apply them as soon as they become available.
ICS Vulnerabilities
Siemens and Schneider Electric released patches for multiple vulnerabilities in their industrial control systems, including critical flaws that could allow privilege escalation and code execution.
Action Items:
Apply the latest security updates from Siemens and Schneider Electric.
Conduct a security audit of all industrial control systems to ensure they are protected.
OpenSSH Vulnerability
A new OpenSSH vulnerability (CVE-2024-6409) has been identified, affecting Red Hat Enterprise Linux 9.
Action Items:
Update to the latest versions of OpenSSH to mitigate the risk.
Regularly review security advisories for any additional patches.
Iranian Cyber Espionage
Iranian-linked cyber actors are using custom Android spyware, "Guard Zoo," to conduct espionage across the Middle East.
Upcoming Events
AI in Cybersecurity: Join us for a conversation with Steve Orrin, CTO at Intel Federal, discussing the practical implementation and impact of AI in cybersecurity. Tune in on YouTube and LinkedIn at 11 a.m. Eastern.
Stay cyber safe, everyone!
✅ Story Links:
https://thecyberexpress.com/arabian-travel-agency-data-breach-exposed-info/
https://thehackernews.com/2024/07/microsofts-july-update-patches-143.html
https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-cisa-issue-advisories/
https://thehackernews.com/2024/07/new-openssh-vulnerability-discovered.html
🔔 Subscribe now for the latest insights from industry leaders, in-depth analyses, and real-world strategies to secure your digital world. https://www.youtube.com/@TheCyberHubPodcast/?sub_confirmation=1
✅ Important Links to Follow:
👉Website: https://www.cyberhubpodcast.com
👉Substack:
👉Listen here: https://linktr.ee/cyberhubpodcast
✅ Stay Connected With Us.
👉Rumble: https://rumble.com/c/c-1353861
👉Facebook: https://www.facebook.com/CyberHubpodcast/
👉LinkedIn: https://www.linkedin.com/company/cyberhubpodcast/
👉Twitter (X): https://twitter.com/cyberhubpodcast
👉Instagram: https://www.instagram.com/cyberhubpodcast
✅ For Business Inquiries: info@cyberhubpodcast.com
=============================
✅ About The CyberHub Podcast.
The Hub of the Infosec Community.
Our mission is to provide substantive and quality content that’s more than headlines or sales pitches. We want to be a valuable source to assist those cybersecurity practitioners in their mission to keep their organizations secure.
Share this post