The Information Highway

The Information Highway

Read the latest technology news, your comprehensive source for the latest breakthroughs, trends, and innovations shaping the world of technology.

Hackers breach US govt agencies using Adobe ColdFusion exploit

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning about hackers actively exploiting a critical vulnerability in Adobe ColdFusion identified as CVE-2023-26360 to gain initial access to government servers. 

Continue reading
  801 Hits

SpyLoan Android malware on Google Play downloaded 12 million times

Android

More than a dozen malicious loan apps, which are generically named SpyLoan, have been downloaded more than 12 million times this year from Google Play but the count is much larger since they are also available on third-party stores and suspicious websites.

 

Continue reading
  774 Hits

Over 20,000 vulnerable Microsoft Exchange servers exposed to attacks

exchange-red-white

Tens of thousands of Microsoft Exchange email servers in Europe, the U.S., and Asia exposed on the public internet are vulnerable to remote code execution flaws. 

Continue reading
  951 Hits

US Health Dept urges hospitals to patch critical Citrix Bleed bug

Citrix_Bleed

The U.S. Department of Health and Human Services (HHS) warned hospitals this week to patch the critical 'Citrix Bleed' Netscaler vulnerability actively exploited in attacks. 

Continue reading
  802 Hits

Windows 10 KB5032278 update adds Copilot AI assistant, fixes 13 bugs

Windows-10-headpic

Microsoft has started rolling out its Copilot AI assistant to Windows 10 with the KB5032278 November 2023 non-security preview update for systems running Windows 10, version 22H2. 

Continue reading
  952 Hits

Apple fixes two new iOS zero-days in emergency updates

apple_triangle

Apple released emergency security updates to fix two zero-day vulnerabilities exploited in attacks and impacting iPhone, iPad, and Mac devices, reaching 20 zero-days patched since the start of the year. 

Continue reading
  1024 Hits

LogoFAIL attack can install UEFI bootkits through bootup logos

logofail-red

Multiple security vulnerabilities collectively named LogoFAIL affect image-parsing components in the UEFI code from various vendors. Researchers warn that they could be exploited to hijack the execution flow of the booting process and to deliver bootkits. 

Continue reading
  838 Hits

Microsoft starts testing new Windows 11 Energy Saver feature

Windows_11

Microsoft has started testing a new Windows 11 Energy Saver feature that helps customers extend their portable computers' battery life. 

Continue reading
  800 Hits

US seizes Sinbad crypto mixer used by North Korean Lazarus hackers

sinbad-seizure-message-header

The U.S. Department of the Treasury has sanctioned the Sinbad cryptocurrency mixing service for its use as a money-laundering tool by the North Korean Lazarus hacking group. 

Continue reading
  781 Hits

Google Chrome emergency update fixes 6th zero-day exploited in 2023

Google_Chrome

Google has fixed the sixth Chrome zero-day vulnerability this year in an emergency security update released today to counter ongoing exploitation in attacks. 

Continue reading
  727 Hits

Microsoft shares temp fix for Outlook crashes when sending emails

Outlook

Today, Microsoft shared a temporary fix for a known issue causing Outlook Desktop to crash when sending emails from Outlook.com accounts. 

Continue reading
  890 Hits

Windows Hello auth bypassed on Microsoft, Dell, Lenovo laptops

Laptop_finger_print

Security researchers bypassed Windows Hello fingerprint authentication on Dell Inspiron, Lenovo ThinkPad, and Microsoft Surface Pro X laptops in attacks exploiting security flaws found in the embedded fingerprint sensors. 

Continue reading
  852 Hits

Hacktivists breach U.S. nuclear research lab, steal employee data

INL

The Idaho National Laboratory (INL) confirms they suffered a cyberattack after 'SiegedSec' hacktivists leaked stolen human resources data online. 

Continue reading
  856 Hits

Microsoft launches Defender Bounty Program with $20,000 rewards

Microsoft_headpic

Microsoft has unveiled a new bug bounty program aimed at the Microsoft Defender security platform, with rewards between $500 and $20,000. 

Continue reading
  758 Hits

Auto parts giant AutoZone warns of MOVEit data breach

autozone

AutoZone is warning tens of thousands of its customers that it suffered a data breach as part of the Clop MOVEit file transfer attacks. 

Continue reading
  749 Hits

Citrix warns admins to kill NetScaler user sessions to block hackers

citrix-bleed

Citrix reminded admins today that they must take additional measures after patching their NetScaler appliances against the CVE-2023-4966 'Citrix Bleed' vulnerability to secure vulnerable devices against attacks. 

Continue reading
  730 Hits

Cybersecurity firm executive pleads guilty to hacking hospitals

healthcare-cyber

The former chief operating officer of a cybersecurity company has pleaded guilty to hacking two hospitals, part of the Gwinnett Medical Center (GMC), in June 2021 to boost his company's business. 

Continue reading
  947 Hits

Lumma Stealer malware now uses trigonometry to evade detection

Hacker_headpic

The Lumma information-stealing malware is now using an interesting tactic to evade detection by security software - the measuring of mouse movements using trigonometry to determine if the malware is running on a real machine or an antivirus sandbox. 

Continue reading
  664 Hits

Researchers extract RSA keys from SSH server signing errors

cyber-key

A team of academic researchers from universities in California and Massachusetts demonstrated that it's possible under certain conditions for passive network attackers to retrieve secret RSA keys from naturally occurring errors leading to failed SSH (secure shell) connection attempts. 

Continue reading
  824 Hits

Windows 10 to let admins control how optional updates are deployed

Windows-10

Microsoft announced a new policy that allows admins to control how optional updates are deployed on Windows 10 enterprise endpoints on their networks. 

Continue reading
  807 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023