The Information Highway

The Information Highway

all things technology risk and cybersecurity

Data breach at healthcare tech firm impacts 4.5 million patients

healthcare

HealthEC LLC, a provider of health management solutions, suffered a data breach that impacts close to 4.5 million individuals who received care through one of the company's customers.


Continue reading
  697 Hits

Nearly 11 million SSH servers vulnerable to new Terrapin attacks

Turtle

Almost 11 million internet-exposed SSH servers are vulnerable to the Terrapin attack that threatens the integrity of some SSH connections.


Continue reading
  691 Hits

CISA warns of actively exploited bugs in Chrome and Excel parsing library

CISA_headpic

The U.S. Cybersecurity and Infrastructure Security Agency has added two vulnerabilities to the Known Exploited Vulnerabilities catalog, a recently patched flaw in Google Chrome and a bug affecting an open-source Perl library for reading information in an Excel file called Spreadsheet::ParseExcel.


Continue reading
  732 Hits

Online museum collections down after cyberattack on service provider

emuseum

Museum software solutions provider Gallery Systems has disclosed that its ongoing IT outages were caused by a ransomware attack last week.


Continue reading
  597 Hits

Xerox says subsidiary XBS U.S. breached after ransomware gang leaks data

back

The U.S. division of Xerox Business Solutions (XBS) has been compromised by hackers with a limited amount of personal information possibly exposed, according to a statement by the parent company, Xerox Corporation.


Continue reading
  653 Hits

Google Groups is ending support for Usenet to combat spam

Google_flare

Google has officially announced its ceasing support for Usenet groups on its Google Groups platform, a move partly attributed to the platform's increasing struggle with spam content. 

Continue reading
  736 Hits

The biggest cybersecurity and cyberattack stories of 2023

year-2023-header

2023 was a big year for cybersecurity, with significant cyberattacks, data breaches, new threat groups emerging, and, of course, zero-day vulnerabilities. 

Continue reading
  847 Hits

New Black Basta decryptor exploits ransomware flaw to recover files

cyber-key

Researchers have created a decryptor that exploits a flaw in Black Basta ransomware, allowing victims to recover their files for free. 

Continue reading
  750 Hits

Eagers Automotive halts trading in response to cyberattack

1

Eagers Automotive has announced it suffered a cyberattack and was forced to halt trading on the stock exchange as it evaluates the impact of the incident. 

Continue reading
  672 Hits

EasyPark discloses data breach that may impact millions of users

easypark

Parking app developer EasyPark has published a notice on its website warning of a data breach it discovered on December 10, 2023, which impacts an unknown number of its millions of users. 

Continue reading
  799 Hits

Microsoft disables MSIX protocol handler abused in malware attacks

Windows

Microsoft has again disabled the MSIX ms-appinstaller protocol handler after multiple financially motivated threat groups abused it to infect Windows users with malware. 

Continue reading
  745 Hits

Blockchain dev's wallet emptied in "job interview" using npm package

Hackers_crypt_20240101-183235_1

A blockchain developer shares his ordeal over the holidays when he was approached on LinkedIn by a "recruiter" for a web development job. 

Continue reading
  657 Hits

Ohio Lottery hit by cyberattack claimed by DragonForce ransomware

Ohio-Lottery

The Ohio Lottery was forced to shut down some key systems after a cyberattack affected an undisclosed number of internal applications on Christmas Eve. 

Continue reading
  742 Hits

Mortgage firm LoanCare warns 1.3 million people of data breach

loancare-header-bw

Mortgage servicing company LoanCare is warning 1,316,938 borrowers across the U.S. that their sensitive information was exposed in a data breach at its parent company, Fidelity National Financial. 

Continue reading
  692 Hits

New Xamalicious Android malware installed 330k times on Google Play

Android_malware

 A previously unknown Android backdoor named 'Xamalicious' has infected approximately 338,300 devices via malicious apps on Google Play, Android's official app store.

Continue reading
  692 Hits

iPhone Triangulation attack abused undocumented hardware feature

apple_triangl_20240101-180232_1

 The Operation Triangulation spyware attacks targeting iPhone devices since 2019 leveraged undocumented features in Apple chips to bypass hardware-based security protections.

Continue reading
  855 Hits

Barracuda fixes new ESG zero-day exploited by Chinese hackers

Barracuda_red

Network and email security firm Barracuda says it remotely patched all active Email Security Gateway (ESG) appliances on December 21 against a zero-day bug exploited by UNC4841 Chinese hackers. 

Continue reading
  742 Hits

GTA 5 source code reportedly leaked online a year after Rockstar hack

GTA_headpi_20240101-004448_1

The source code for Grand Theft Auto 5 was reportedly leaked on Christmas Eve, a little over a year after the Lapsus$ threat actors hacked Rockstar games and stole corporate data. 

Continue reading
  682 Hits

Google Chrome now scans for compromised passwords in the background

Chrome

Google says the Chrome Safety Check feature will work in the background to check if passwords saved in the web browser have been compromised. 

Continue reading
  812 Hits

Qbot malware returns in campaign targeting hospitality industry

Qbot--malware

The QakBot malware is once again being distributed in phishing campaigns after the botnet was disrupted by law enforcement over the summer. 

Continue reading
  810 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023