Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Read the latest technology news, your comprehensive source for the latest breakthroughs, trends, and innovations shaping the world of technology.

Urgent N-central Hotfix: What Businesses Need to Know About the September 2026 Security Update

N-able N-central Hotfix 2026.3
If your IT provider or internal technology team uses N-able N-central, there is a new security update you should know about.

N-able released N-central 2026.3 Hotfix 3 on September 5, 2026, to address two high-severity security vulnerabilities. The flaws could allow an unauthorized person to bypass authentication controls and potentially gain full access to the N-central platform.
Continue reading
  36 Hits

It Wasn't a “Hack” It Was a Mistake Anyone Could Make: What the Manchester Airports Breach Teaches SMBs About Vendor Risk

Airport-flight-checkin
A breach that exposed the data of 8.7 million people didn't require nation-state malware or a zero-day exploit, it exploited exposed login credentials sitting in plain view in website code, tied to a third-party marketing platform. That's not a sophisticated attack. That's a mistake almost any business could make, which is exactly why every small and mid-sized business should be paying attention.
Continue reading
  53 Hits

CIRCIA Is Almost Here

SOC Security Operations Center
After more than four years of waiting, the federal government's most far-reaching cybersecurity reporting law is finally close to taking real, enforceable shape. The Cybersecurity and Infrastructure Security Agency (CISA) has told stakeholders it intends to publish the long-delayed final rule for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) in September 2026 — and once that happens, the clock starts ticking toward mandatory reporting for hundreds of thousands of U.S. businesses.
Continue reading
  186 Hits

AI Coding Tools Got Hacked Into Hacking: What It Means for Your Business

AI_cyber_attack_Main
Hackers didn't need to write new malware, they just told a trusted AI coding assistant it was "running a test," and it happily helped them break into ten companies. If a $9-billion AI tool can be talked into attacking its own users, what's stopping the AI plugins already running inside your business?
Continue reading
  115 Hits

Cybersecurity Threat Advisory 30-26: SonicWall SMA1000 exploits

Threat-Advisory-Banner3

Threat update

SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. 

Continue reading
  94 Hits

CMMC Level 2 Is on Hold: What Defense Contractors Need to Know

Government-Manufacturing

If you've been preparing your company for a CMMC Level 2 certification assessment, you may have heard some confusing news: the federal government has put CMMC Phase II on hold.

That part is true.

What isn't true is that CMMC has disappeared.

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II, which had been scheduled to begin November 10, 2026. At the same time, officials launched a 60-day review of the program. Phase I self-assessment requirements remain in place.

Continue reading
  130 Hits

AI Phishing Attacks Are Changing Fast: What Businesses Need to Know in 2026

AI-phishingv2

AI phishing attacks are making familiar cyber scams faster, more convincing, and harder for employees to recognize. Recent 2026 threat intelligence shows attackers expanding beyond email into Microsoft Teams, voice calls, trusted cloud services, and highly personalized messages. For businesses, protecting Microsoft 365 identities and training employees to verify unusual requests has become increasingly important.

Continue reading
  200 Hits

QR codes bypass browser isolation for malicious C2 communication

Hacker-headpic

Mandiant has identified a novel method to bypass browser isolation technology and achieve command-and-control operations through QR codes.

Continue reading
  4502 Hits

Microsoft expands Recall preview to Intel and AMD Copilot+ PCs

windows-11-recall

Microsoft is now testing its AI-powered Recall feature on AMD and Intel-powered Copilot+ PCs enrolled in the Windows 11 Insider program.

Continue reading
  4662 Hits

Microsoft says having a TPM is "non-negotiable" for Windows 11

Windows-11-headpic

Microsoft made it abundantly clear this week that Windows 10 users won't be able to upgrade to Windows 11 unless their systems come with TPM 2.0 support, stating it's a "non-negotiable" requirement.

Continue reading
  4642 Hits

FBI shares tips on how to tackle AI-powered fraud schemes

evil-hacker-ai

The FBI warns that scammers are increasingly using artificial intelligence to improve the quality and effectiveness of their online fraud schemes, ranging from romance and investment scams to job hiring schemes.

Continue reading
  4602 Hits

Microsoft says recent Windows 11 updates break SSH connections

Windows_11_headpic

Microsoft has confirmed that last month's Windows security updates are breaking SSH connections on some Windows 11 22H2 and 23H2 systems.

Continue reading
  5171 Hits

Critical Veeam RCE bug now used in Frag ransomware attacks

Veeam

After being used in Akira and Fog ransomware attacks, a critical Veeam Backup & Replication (VBR) security flaw was also recently exploited to deploy Frag ransomware.

Continue reading
  2354 Hits

D-Link won’t fix critical flaw affecting 60,000 older NAS devices

D-Link-headpic

More than 60,000 D-Link network-attached storage devices that have reached end-of-life are vulnerable to a command injection vulnerability with a publicly available exploit.

Continue reading
  4608 Hits

Unpatched Mazda Connect bugs let hackers install persistent malware

headpi_20241109-194606_1

Attackers could exploit several vulnerabilities in the Mazda Connect infotainment unit, present in multiple car models including Mazda 3 (2014-2021), to execute arbitrary code with root permission. 

Continue reading
  4967 Hits

Palo Alto Networks warns of potential PAN-OS RCE vulnerability

Palo-Alto-Networks

 Today, cybersecurity company Palo Alto Networks warned customers to restrict access to their next-generation firewalls because of a potential remote code execution vulnerability in the PAN-OS management interface.

Continue reading
  4429 Hits

Google's mysterious 'search.app' links leave Android users concerned

Google_headpi_20241109-201732_1

Google has left Android users puzzled after the most recent update to the Google mobile app causes links shared from the app to now be prepended with a mysterious "search.app" domain.

Continue reading
  4180 Hits

Canada orders TikTok to shut down over national risk concerns

TikTok

The Canadian government has ordered the dissolution of TikTok Technology Canada following a multi-step review that provided information and evidence of the social media company posing a national risk. 

Continue reading
  1645 Hits

Malicious PyPI Package 'Fabrice' Found Stealing AWS Keys from Thousands of Developers

aw_20241109-185929_1

Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) that has racked up thousands of downloads for over three years while stealthily exfiltrating developers' Amazon Web Services (AWS) credentials.

Continue reading
  2216 Hits

HPE warns of critical RCE flaws in Aruba Networking access points

HPE

Hewlett Packard Enterprise (HPE) released updates for Instant AOS-8 and AOS-10 software to address two critical vulnerabilities in Aruba Networking Access Points.. 

Continue reading
  4331 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024