The Information Highway

The Information Highway

Read the latest technology news, your comprehensive source for the latest breakthroughs, trends, and innovations shaping the world of technology.

Check-in terminals used by thousands of hotels leak guest info

ariane

Ariane Systems self check-in systems installed at thousands of hotels worldwide are vulnerable to a kiosk mode bypass flaw that could allow access to guests' personal information and the keys for other rooms.

Continue reading
  481 Hits

Arc browser’s Windows launch targeted by Google ads malvertising

arc

A new Google Ads malvertising campaign, coinciding with the launch of the Arc web browser for Windows, was tricking people into downloading trojanized installers that infect them with malware payloads. 

Continue reading
  467 Hits

Microsoft: Windows 24H2 will remove Cortana and WordPad apps

Windows__11

Microsoft says the Cortana, Tips, and WordPad applications will be automatically removed on systems upgraded to the upcoming Windows 11 24H2 release.

Continue reading
  451 Hits

Microsoft Copilot fixed worldwide after 24 hour outage

Microsoft_Copilo_20240526-191411_1

After over a 24-hour outage, Microsoft's Bing, Copilot, and Copilot in Windows services are back online worldwide, with no information released as to what caused the problem.

Continue reading
  475 Hits

Cencora data breach exposes US patient info from 11 drug companies

0_Cencora

Some of the largest drug companies in the world have disclosed data breaches due to a February 2024 cyberattack at Cencora, whom they partner with for pharmaceutical and business services.

Continue reading
  436 Hits

Apple wasn’t storing deleted iOS photos in iCloud after all

apple_triangle

Security researchers reverse-engineered Apple's recent iOS 17.5.1 update and found that a recent bug that restored images deleted months or even years ago was caused by an iOS bug and not an issue with iCloud.

Continue reading
  375 Hits

Microsoft to start killing off VBScript in second half of 2024

Microsoft

Microsoft announced today that it will start deprecating VBScript in the second half of 2024 by making it an on-demand feature until it's completely removed.

Continue reading
  432 Hits

CISA warns of hackers exploiting Chrome, EoL D-Link bugs

CISA

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added three security vulnerabilities to its 'Known Exploited Vulnerabilities' catalog, one impacting Google Chrome and two affecting some D-Link routers.

Continue reading
  553 Hits

Microsoft to start enforcing Azure multi-factor authentication in July

Microsoft_passwordless

Starting in July, Microsoft will begin gradually enforcing multi-factor authentication (MFA) for all users signing into Azure to administer resources.

Continue reading
  485 Hits

SEC: Financial orgs have 30 days to send data breach notifications

sec-red-flar_20240519-185154_1

The Securities and Exchange Commission (SEC) has adopted amendments to Regulation S-P that require certain financial institutions to disclose data breach incidents to impacted individuals within 30 days of discovery.

Continue reading
  460 Hits

WebTPA data breach impacts 2.4 million insurance policyholders

medical-data-header

The WebTPA Employer Services (WebTPA) data breach disclosed earlier this month is impacting close to 2.5 million individuals, the U.S. Department of Health and Human Services notes.

Continue reading
  486 Hits

Norway recommends replacing SSL VPN to prevent breaches

global-pew-pe_20240519-183959_1

The Norwegian National Cyber Security Centre (NCSC) recommends replacing SSLVPN/WebVPN solutions with alternatives due to the repeated exploitation of related vulnerabilities in edge network devices to breach corporate networks. 

Continue reading
  584 Hits

Microsoft: Windows Server 2019 updates fail with 0x800f0982 errors

Windows-Server

Microsoft has acknowledged a new known issue causing this month's KB5037765 security update for Windows Server 2019 to fail to install with 0x800f0982 errors.

Continue reading
  517 Hits

How to manage the security risks of generative AI tools

nudge-ai-tool_20240519-181355_1

Over the past year, we've witnessed an explosive growth spurt in consumer-focused AI productivity tools that has once again transformed the way we work. Once the realm of data science and engineering teams, generative AI was packaged and delivered to the masses in 2023.

Continue reading
  456 Hits

Critical GitLab bug

Threat-Advisory-Banne2r

Threat update

 A critical vulnerability in GitLab, labeled CVE-2023-7028, is under active attack by threat actors to achieve account takeover, as reported by the Cybersecurity and Infrastructure Security Agency (CISA).

Continue reading
  488 Hits

Apple backports fix for RTKit iOS zero-day to older iPhones

Appl_20240514-030518_1

Apple has backported security patches released in March to older iPhones and iPads, fixing an iOS Kernel zero-day tagged as exploited in attacks.

Continue reading
  445 Hits

City of Wichita shuts down IT network after ransomware attack

wichita

The City of Wichita, Kansas, disclosed it was forced to shut down portions of its network after suffering a weekend ransomware attack.

Continue reading
  433 Hits

Microsoft rolls out passkey auth for personal Microsoft accounts

microsoft

Microsoft announced that Windows users can now log into their Microsoft consumer accounts using a passkey, allowing users to authenticate using password-less methods such as Windows Hello, FIDO2 security keys, biometric data (facial scans or fingerprints), or device PINs.

Continue reading
  434 Hits

CISA urges software devs to weed out path traversal vulnerabilities

CISA

CISA and the FBI urged software companies today to review their products and eliminate path traversal security vulnerabilities before shipping.

Continue reading
  475 Hits

Killware: The emerging cyberthreat

2024-04-27-14_21_01-Killware_-The-emerging-cyberthreat-and-5-more-pages---InPrivate---Microsoft-E

 Given the surge of incidents within the past decade, many people are becoming familiar with ransomware and data breaches. However, a new type of cyberattack known as killware has emerged in recent years. It's now a major security issue for organizations. But what does the term "killware" actually mean? Let's take a look:

Continue reading
  448 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023