The Information Highway

The Information Highway

Read the latest technology news, your comprehensive source for the latest breakthroughs, trends, and innovations shaping the world of technology.

Critical GitLab bug

Threat-Advisory-Banne2r

Threat update

 A critical vulnerability in GitLab, labeled CVE-2023-7028, is under active attack by threat actors to achieve account takeover, as reported by the Cybersecurity and Infrastructure Security Agency (CISA).

Continue reading
  38 Hits

Apple backports fix for RTKit iOS zero-day to older iPhones

Appl_20240514-030518_1

Apple has backported security patches released in March to older iPhones and iPads, fixing an iOS Kernel zero-day tagged as exploited in attacks.

Continue reading
  66 Hits

City of Wichita shuts down IT network after ransomware attack

wichita

The City of Wichita, Kansas, disclosed it was forced to shut down portions of its network after suffering a weekend ransomware attack.

Continue reading
  74 Hits

Microsoft rolls out passkey auth for personal Microsoft accounts

microsoft

Microsoft announced that Windows users can now log into their Microsoft consumer accounts using a passkey, allowing users to authenticate using password-less methods such as Windows Hello, FIDO2 security keys, biometric data (facial scans or fingerprints), or device PINs.

Continue reading
  70 Hits

CISA urges software devs to weed out path traversal vulnerabilities

CISA

CISA and the FBI urged software companies today to review their products and eliminate path traversal security vulnerabilities before shipping.

Continue reading
  72 Hits

Killware: The emerging cyberthreat

2024-04-27-14_21_01-Killware_-The-emerging-cyberthreat-and-5-more-pages---InPrivate---Microsoft-E

 Given the surge of incidents within the past decade, many people are becoming familiar with ransomware and data breaches. However, a new type of cyberattack known as killware has emerged in recent years. It's now a major security issue for organizations. But what does the term "killware" actually mean? Let's take a look:

Continue reading
  81 Hits

FBI warns against using unlicensed crypto transfer services

FBI

The FBI has warned today that using unlicensed cryptocurrency transfer services can result in financial loss if law enforcement takes down these platforms.

Continue reading
  87 Hits

Windows 11 KB5036980 update goes live with Start Menu ads

Windows11_laptop

Microsoft has enabled Start menu ads in the optional KB5036980 preview cumulative update for Windows 11 22H2 and 23H2.

Continue reading
  134 Hits

UnitedHealth confirms it paid ransomware gang to stop data leak

United--Healthcare

The UnitedHealth Group has confirmed that it paid a ransom to cybercriminals to protect sensitive data stolen during the Optum ransomware attack in late February.

Continue reading
  116 Hits

Former AT&T customers get $6.3 million in data throttling refunds

AT-T

The Federal Trade Commission (FTC) is sending out $6,300,000 in partial refunds to 267,000 former AT&T Wireless customers as part of a data throttling settlement in 2019.

Continue reading
  177 Hits

CISA makes its "Malware Next-Gen" analysis system publicly available

CISA_headpic

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new version of "Malware Next-Gen," now allowing the public to submit malware samples for analysis by CISA.

Continue reading
  208 Hits

Over 92,000 exposed D-Link NAS devices have a backdoor account

map-dlink

A threat researcher has disclosed a new arbitrary command injection and hardcoded backdoor flaw in multiple end-of-life D-Link Network Attached Storage (NAS) device models.. 

Continue reading
  184 Hits

Recent Windows updates break Microsoft Connected Cache delivery

0_Windows-headpic

Microsoft says Windows 10 updates released since the start of the year are breaking Microsoft Connected Cache (MCC) node discovery on enterprise networks.

Continue reading
  202 Hits

Panera Bread week-long IT outage caused by ransomware attack

Panera

Panera Bread's recent week-long outage was caused by a ransomware attack, according to people familiar with the matter and emails. 

Continue reading
  137 Hits

Vultur banking malware for Android poses as McAfee Security app

android

Security researchers found a new version of the Vultur banking trojan for Android that includes more advanced remote control capabilities and an improved evasion mechanism.

Continue reading
  225 Hits

Retail chain Hot Topic hit by new credential stuffing attacks

HOT-TOPIC

American retailer Hot Topic disclosed that two waves of credential stuffing attacks in November exposed affected customers' personal information and partial payment data.

Continue reading
  226 Hits

CISA tags Microsoft SharePoint RCE bug as actively exploited

SharePoint

CISA warns that attackers are now exploiting a Microsoft SharePoint code injection vulnerability that can be chained with a critical privilege escalation flaw for pre-auth remote code execution attacks.

Continue reading
  1143 Hits

Microsoft releases emergency fix for Windows Server crashes

Windows_Serverblue

Microsoft has released emergency out-of-band (OOB) updates to fix a known issue causing Windows domain controllers to crash after installing the March 2024 Windows Server security updates.

Continue reading
  252 Hits

Microsoft confirms Windows Server issue behind domain controller crashes

Windows__Server


Microsoft confirmed that a memory leak introduced with the March 2024 Windows Server security updates is behind a widespread issue causing Windows domain controllers to crash. 

Continue reading
  270 Hits

McDonald's: Global outage was caused by "configuration change"

McDonalds

McDonald's has blamed a third-party service provider's configuration change, not a cyberattack, for the global outage that forced many of its fast-food restaurants to close.

Continue reading
  1035 Hits