The Information Highway

The Information Highway

all things technology risk and cybersecurity

Microsoft reveals how hackers breached its Exchange Online accounts

microsoft-red-header

Microsoft confirmed that the Russian Foreign Intelligence Service hacking group, which hacked into its executives' email accounts in November 2023, also breached other organizations as part of this malicious campaign.


Continue reading
  1000 Hits

23andMe data breach: Hackers stole raw genotype data, health reports

23andMe

Genetic testing provider 23andMe confirmed that hackers stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27.


Continue reading
  889 Hits

Blackwood hackers hijack WPS Office update to install malware

China-hacker

A previously unknown advanced threat actor tracked as 'Blackwood' is using sophisticated malware called NSPX30 in cyberespionage attacks against companies and individuals.


Continue reading
  1217 Hits

iPhone apps abuse iOS push notifications to collect user data

iphone

Numerous iOS apps are using background processes triggered by push notifications to collect user data about devices, potentially allowing the creation of fingerprinting profiles used for tracking.


Continue reading
  1014 Hits

Over 5,300 GitLab servers exposed to zero-click account takeover attacks

GitLab

Over 5,300 internet-exposed GitLab instances are vulnerable to CVE-2023-7028, a zero-click account takeover flaw GitLab warned about earlier this month.


Continue reading
  915 Hits

Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024

Pwn2Own_Tokyo-headpic

Security researchers hacked a Tesla Modem and collected awards of $722,500 on the first day of Pwn2Own Automotive 2024 for three bug collisions and 24 unique zero-day exploits.


Continue reading
  1019 Hits

Bitwarden adds passkey support to log into web password vaults

Bitwarden

The open-source Bitwarden password manager has announced that all users can now log into their web vaults using a passkey instead of the standard username and password pairs.


Continue reading
  1082 Hits

Data breach at healthcare tech firm impacts 4.5 million patients

healthcare

HealthEC LLC, a provider of health management solutions, suffered a data breach that impacts close to 4.5 million individuals who received care through one of the company's customers.


Continue reading
  973 Hits

Nearly 11 million SSH servers vulnerable to new Terrapin attacks

Turtle

Almost 11 million internet-exposed SSH servers are vulnerable to the Terrapin attack that threatens the integrity of some SSH connections.


Continue reading
  919 Hits

CISA warns of actively exploited bugs in Chrome and Excel parsing library

CISA_headpic

The U.S. Cybersecurity and Infrastructure Security Agency has added two vulnerabilities to the Known Exploited Vulnerabilities catalog, a recently patched flaw in Google Chrome and a bug affecting an open-source Perl library for reading information in an Excel file called Spreadsheet::ParseExcel.


Continue reading
  1059 Hits

Online museum collections down after cyberattack on service provider

emuseum

Museum software solutions provider Gallery Systems has disclosed that its ongoing IT outages were caused by a ransomware attack last week.


Continue reading
  819 Hits

Xerox says subsidiary XBS U.S. breached after ransomware gang leaks data

back

The U.S. division of Xerox Business Solutions (XBS) has been compromised by hackers with a limited amount of personal information possibly exposed, according to a statement by the parent company, Xerox Corporation.


Continue reading
  983 Hits

Google Groups is ending support for Usenet to combat spam

Google_flare

Google has officially announced its ceasing support for Usenet groups on its Google Groups platform, a move partly attributed to the platform's increasing struggle with spam content. 

Continue reading
  978 Hits

The biggest cybersecurity and cyberattack stories of 2023

year-2023-header

2023 was a big year for cybersecurity, with significant cyberattacks, data breaches, new threat groups emerging, and, of course, zero-day vulnerabilities. 

Continue reading
  1232 Hits

New Black Basta decryptor exploits ransomware flaw to recover files

cyber-key

Researchers have created a decryptor that exploits a flaw in Black Basta ransomware, allowing victims to recover their files for free. 

Continue reading
  1046 Hits

Eagers Automotive halts trading in response to cyberattack

1

Eagers Automotive has announced it suffered a cyberattack and was forced to halt trading on the stock exchange as it evaluates the impact of the incident. 

Continue reading
  938 Hits

EasyPark discloses data breach that may impact millions of users

easypark

Parking app developer EasyPark has published a notice on its website warning of a data breach it discovered on December 10, 2023, which impacts an unknown number of its millions of users. 

Continue reading
  1180 Hits

Microsoft disables MSIX protocol handler abused in malware attacks

Windows

Microsoft has again disabled the MSIX ms-appinstaller protocol handler after multiple financially motivated threat groups abused it to infect Windows users with malware. 

Continue reading
  990 Hits

Blockchain dev's wallet emptied in "job interview" using npm package

Hackers_crypt_20240101-183235_1

A blockchain developer shares his ordeal over the holidays when he was approached on LinkedIn by a "recruiter" for a web development job. 

Continue reading
  895 Hits

Ohio Lottery hit by cyberattack claimed by DragonForce ransomware

Ohio-Lottery

The Ohio Lottery was forced to shut down some key systems after a cyberattack affected an undisclosed number of internal applications on Christmas Eve. 

Continue reading
  1035 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024