The Information Highway

The Information Highway

all things technology risk and cybersecurity

3CX warns customers to disable SQL database integrations

3CX

 VoIP communications company 3CX warned customers today to disable SQL database integrations due to potential risks associated with what it describes as a potential vulnerability.

Continue reading
  772 Hits

Ransomware gang behind threats to Fred Hutch cancer patients

fred-hutch-cancer-center

The Hunters International ransomware gang claimed to be behind a cyberattack on the Fred Hutchinson Cancer Center (Fred Hutch) that resulted in patients receiving personalized extortion threats. 

Continue reading
  734 Hits

Delta Dental of California data breach exposed info of 7 million people

dentist-holding-drill

Delta Dental of California and its affiliates are warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach. 

Continue reading
  822 Hits

Kraft Heinz investigates hack claims, says systems ‘operating normally’

heinz-ketchup-russian

Kraft Heinz has confirmed that their systems are operating normally and that there is no evidence they were breached after an extortion group listed them on a data leak site. 

Continue reading
  789 Hits

New NKAbuse malware abuses NKN blockchain for stealthy comms

hacker-globe

A new Go-based multi-platform malware identified as 'NKAbuse' is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat. 

Continue reading
  729 Hits

Ubiquiti users report having access to others’ UniFi routers, cameras

Ubiquiti

Since yesterday, users of Ubiquiti networking devices, ranging from routers to security cameras, have reported seeing other people's devices and notifications through the company's UniFi cloud services. 

Continue reading
  744 Hits

Nissan is investigating cyberattack and potential data breach

Nissan-1

Japanese car maker Nissan is investigating a cyberattack that targeted its systems in Australia and New Zealand, which may have let hackers access personal information. 

Continue reading
  699 Hits

Multiple NFT collections at risk by flaw in open-source library

Thirdweb

A vulnerability in an open-source library that is common across the Web3 space impacts the security of pre-built smart contracts, affecting multiple NFT collections, including Coinbase. 

Continue reading
  883 Hits

Hackers breach US govt agencies using Adobe ColdFusion exploit

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning about hackers actively exploiting a critical vulnerability in Adobe ColdFusion identified as CVE-2023-26360 to gain initial access to government servers. 

Continue reading
  801 Hits

SpyLoan Android malware on Google Play downloaded 12 million times

Android

More than a dozen malicious loan apps, which are generically named SpyLoan, have been downloaded more than 12 million times this year from Google Play but the count is much larger since they are also available on third-party stores and suspicious websites.

 

Continue reading
  776 Hits

Over 20,000 vulnerable Microsoft Exchange servers exposed to attacks

exchange-red-white

Tens of thousands of Microsoft Exchange email servers in Europe, the U.S., and Asia exposed on the public internet are vulnerable to remote code execution flaws. 

Continue reading
  953 Hits

US Health Dept urges hospitals to patch critical Citrix Bleed bug

Citrix_Bleed

The U.S. Department of Health and Human Services (HHS) warned hospitals this week to patch the critical 'Citrix Bleed' Netscaler vulnerability actively exploited in attacks. 

Continue reading
  802 Hits

Hackers use new Agent Raccoon malware to backdoor US targets

Raccoon-Stealer

A novel malware named 'Agent Raccoon' (or Agent Racoon) is being used in cyberattacks against organizations in the United States, the Middle East, and Africa.

Continue reading
  871 Hits

Capital Health Hospitals hit by cyberattack causing IT outages

Capital_Health

Capital Health hospitals and physician offices across New Jersey are experiencing IT outages after a cyberattack hit the non-profit organization's network earlier this week. 

Continue reading
  914 Hits

LogoFAIL attack can install UEFI bootkits through bootup logos

logofail-red

Multiple security vulnerabilities collectively named LogoFAIL affect image-parsing components in the UEFI code from various vendors. Researchers warn that they could be exploited to hijack the execution flow of the booting process and to deliver bootkits. 

Continue reading
  839 Hits

Zyxel warns of multiple critical vulnerabilities in NAS devices

zyxel-header-image

Zyxel has addressed multiple security issues, including three critical ones that could allow an unauthenticated attacker to execute operating system commands on vulnerable network-attached storage (NAS) devices. 

Continue reading
  810 Hits

Dollar Tree hit by third-party data breach impacting 2 million people

dollar-tree

Discount store chain Dollar Tree was impacted by a third-party data breach affecting 1,977,486 people after the hack of service provider Zeroed-In Technologies. 

Continue reading
  956 Hits

Hackers breach US water facility via exposed Unitronics PLCs

Water_treatment_US

CISA (Cybersecurity & Infrastructure Security Agency) is warning that threat actors breached a U.S. water facility by hacking into Unitronics programmable logic controllers (PLCs) exposed online. 

Continue reading
  878 Hits

New BLUFFS attack lets attackers hijack Bluetooth connections

Bluetooth_bluescreen_BSOD

 Researchers at Eurecom have developed six new attacks collectively named 'BLUFFS' that can break the secrecy of Bluetooth sessions, allowing for device impersonation and man-in-the-middle (MitM) attacks.

Continue reading
  747 Hits

Google Chrome emergency update fixes 6th zero-day exploited in 2023

Google_Chrome

Google has fixed the sixth Chrome zero-day vulnerability this year in an emergency security update released today to counter ongoing exploitation in attacks. 

Continue reading
  728 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023