The Information Highway

The Information Highway

all things technology risk and cybersecurity

Researchers extract RSA keys from SSH server signing errors

cyber-key

A team of academic researchers from universities in California and Massachusetts demonstrated that it's possible under certain conditions for passive network attackers to retrieve secret RSA keys from naturally occurring errors leading to failed SSH (secure shell) connection attempts. 

Continue reading
  1123 Hits

FCC adopts new rules to protect consumers from SIM-swapping attacks

Hacker_phones

The Federal Communications Commission (FCC) has revealed new rules to shield consumers from criminals who hijack their phone numbers in SIM swapping attacks and port-out fraud. 

Continue reading
  1046 Hits

Exploit for CrushFTP RCE chain released, patch now

hacker-looking-at-screens

A proof-of-concept exploit was publicly released for a critical remote code execution vulnerability in the CrushFTP enterprise suite, allowing unauthenticated attackers to access files on the server, execute code, and obtain plain-text passwords. 

Continue reading
  1066 Hits

Bloomberg Crypto X account snafu leads to Discord phishing attack

Bloomberg_Crypto_red

The official Twitter account for Bloomberg Crypto was used earlier today to redirect users to a deceptive website that stole Discord credentials in a phishing attack.  

Continue reading
  982 Hits

CISA warns of actively exploited Windows, Sophos, and Oracle bugs

CISA_headpic

The U.S. Cybersecurity & Infrastructure Security Agency has added to its catalog of known exploited vulnerabilities (KEV) three security issues that affect Microsoft devices, a Sophos product, and an enterprise solution from Oracle. 

Continue reading
  1073 Hits

Toyota confirms breach after Medusa ransomware threatens to leak data

toyota-logo-on-a-sign

Toyota Financial Services (TFS) has confirmed that it detected unauthorized access on some of its systems in Europe and Africa after Medusa ransomware claimed an attack on the company. 

Continue reading
  1078 Hits

Fortinet warns of critical command injection bug in FortiSIEM

Fortinet

Fortinet is alerting customers of a critical OS command injection vulnerability in FortiSIEM report server that could be exploited by remote, unauthenticated attackers to execute commands through specially crafted API requests. 

Continue reading
  1163 Hits

Toronto Public Library confirms data stolen in ransomware attack

toronto_public_library

The Toronto Public Library (TPL) confirmed that the personal information of employees, customers, volunteers, and donors was stolen from a compromised file server during an October ransomware attack. 

Continue reading
  1061 Hits

WP Fastest Cache plugin bug exposes 600K WordPress sites to attacks

WordPress-headpic

The WordPress plugin WP Fastest Cache is vulnerable to an SQL injection vulnerability that could allow unauthenticated attackers to read the contents of the site's database. 

Continue reading
  1063 Hits

LockBit ransomware exploits Citrix Bleed in attacks, 10K servers exposed

citrix-bleed

The Lockbit ransomware attacks use publicly available exploits for the Citrix Bleed vulnerability (CVE-2023-4966) to breach the systems of large organizations, steal data, and encrypt files. 

Continue reading
  990 Hits

VMware discloses critical VCD Appliance auth bypass with no patch

VMware_red

VMware disclosed a critical and unpatched authentication bypass vulnerability affecting Cloud Director appliance deployments. 

Continue reading
  1113 Hits

Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws

patch-tuesday-large

Today is Microsoft's November 2023 Patch Tuesday, which includes security updates for a total of 58 flaws and five zero-day vulnerabilities. 

Continue reading
  1359 Hits

McLaren Health Care says data breach impacted 2.2 million people

0_back

McLaren Health Care (McLaren) is notifying nearly 2.2 million people of a data breach that occurred between late July and August this year, exposing sensitive personal information. 

Continue reading
  1266 Hits

Cloudflare website downed by DDoS attack claimed by Anonymous Sudan

cloudflare

Cloudflare confirmed that the outage resulted from a DDoS attack that only affected the www.cloudflare.com website without impacting other products or services. The company didn't attribute the attack to a specific threat actor. 

Continue reading
  1178 Hits

World’s largest commercial bank ICBC confirms ransomware attack

ICBC

"On November 8, 2023, U.S. Eastern Time (November 9, 2023, Beijing Time), ICBC Financial Services (FS) experienced a ransomware attack that resulted in disruption to certain FS systems. Immediately upon discovering the incident, ICBC FS disconnected and isolated impacted systems to contain the incident," said the bank. 

Continue reading
  1023 Hits

Google ads push malicious CPU-Z app from fake Windows news site

CPU-Z

A threat actor has been abusing Google Ads to distribute a trojanized version of the CPU-Z tool to deliver the Redline info-stealing malware. 

Continue reading
  1095 Hits

OpenAI confirms DDoS attacks behind ongoing ChatGPT outages

OpenAI

OpenAI has been addressing "periodic outages" due to DDoS attacks targeting its API and ChatGPT services within the last 24 hours. 

Continue reading
  1152 Hits

ChatGPT down after major outage impacting OpenAI systems

ChatGPT

"Between 5:42AM - 7:16AM PT we saw errors impacting all services. We identified the problem and implemented a fix. We are now seeing normal responses from our services," the company said. 

Continue reading
  1162 Hits

Microsoft Authenticator now blocks suspicious MFA alerts by default

microsoft

Microsoft has introduced a new protective feature in the Authenticator app to block notifications that appear suspicious based on specific checks performed during the account login stage. 

Continue reading
  1195 Hits

Veeam warns of critical bugs in Veeam ONE monitoring platform

Veeam_headpic

Veeam released hotfixes today to address four vulnerabilities in the company's Veeam ONE IT infrastructure monitoring and analytics platform, two of them critical.

Continue reading
  1026 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024