The Information Highway

The Information Highway

all things technology risk and cybersecurity

D.C. Board of Elections confirms voter data stolen in site hack

DC_Board_of_Elections

The District of Columbia Board of Elections (DCBOE) is currently probing a data leak involving an unknown number of voter records following breach claims from a threat actor known as RansomedVC. 

Continue reading
  891 Hits

Genetics firm 23andMe says user data stolen in credential stuffing attack

dna

23andMe has confirmed that it is aware of user data from its platform circulating on hacker forums and attributes the leak to a credential-stuffing attack. 

Continue reading
  937 Hits

China-linked cyberspies backdoor semiconductor firms with Cobalt Strike

motherboard-cpu-bios

Hackers engaging in cyber espionage have targeted Chinese-speaking semiconductor companies with TSMC-themed lures that infect them with Cobalt Strike beacons. 

Continue reading
  866 Hits

NSA and CISA reveal top 10 cybersecurity misconfigurations

Hacker

The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) revealed today the top ten most common cybersecurity misconfigurations discovered by their red and blue teams in the networks of large organizations. 

Continue reading
  850 Hits

Lyca Mobile investigates customer data leak after cyberattack

lyca-white

Lyca Mobile has released a statement about an unexpected disruption on its network caused by a cyberattack that may have also compromised customer data. 

Continue reading
  925 Hits

Apple emergency update fixes new zero-day used to hack iPhones

Apple

Apple released new emergency security updates on Wednesday to patch two new zero-day vulnerabilities known to be exploited in attacks. 

Continue reading
  865 Hits

Microsoft: Hackers target Azure cloud VMs via breached SQL servers

MSSQL

Hackers have been observed trying to breach cloud environments through Microsoft SQL Servers vulnerable to SQL injection. 

Continue reading
  1038 Hits

Sony confirms data breach impacting thousands in the U.S.

SONY

Sony Interactive Entertainment (Sony) has notified current and former employees and their family members about a cybersecurity breach that exposed personal information. 

Continue reading
  833 Hits

New Microsoft Azure AD CTS feature can be abused for lateral movement

microsoft-azure-headpic

Microsoft's new Azure Active Directory Cross-Tenant Synchronization (CTS) feature, introduced in June 2023, has created a new potential attack surface that might allow threat actors to more easily spread laterally to other Azure tenants. 

Continue reading
  999 Hits

Cloudflare DDoS protections ironically bypassed using Cloudflare

cloudflare-ddos

Cloudflare's Firewall and DDoS prevention can be bypassed through a specific attack process that leverages logic flaws in cross-tenant security controls. 

Continue reading
  964 Hits

Exploit released for Microsoft SharePoint Server auth bypass flaw

SharePoint

Proof-of-concept exploit code has surfaced on GitHub for a critical authentication bypass vulnerability in Microsoft SharePoint Server, allowing privilege escalation. 

Continue reading
  1043 Hits

Microsoft breach led to theft of 60,000 US State Dept emails

Hacker_world_map

Chinese hackers stole tens of thousands of emails from U.S. State Department accounts after breaching Microsoft's cloud-based Exchange email platform in May. 

Continue reading
  1063 Hits

Bing Chat responses infiltrated by ads pushing malware

bing-chat-header-blue

Malicious advertisements are now being injected into Microsoft's AI-powered Bing Chat responses, promoting fake download sites that distribute malware. 

Continue reading
  1031 Hits

Cisco Catalyst SD-WAN Manager flaw allows remote server access

Cisco__headpic

Cisco is warning of five new Catalyst SD-WAN Manager products vulnerabilities with the most critical allowing unauthenticated remote access to the server. 

Continue reading
  888 Hits

Google fixes fifth actively exploited Chrome zero-day of 2023

Google_Chrome

Google has patched the fifth Chrome zero-day vulnerability exploited in attacks since the start of the year in emergency security updates released today. 

Continue reading
  884 Hits

New ZeroFont phishing tricks Outlook into showing fake AV-scans

Outlook_headpic_red

Hackers are utilizing a new trick of using zero-point fonts in emails to make malicious emails appear as safely scanned by security tools in Microsoft Outlook. 

Continue reading
  996 Hits

SickKids impacted by BORN Ontario data breach that hit 3.4 million

sickkids

The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were impacted by the recent breach at BORN Ontario. 

Continue reading
  833 Hits

Fake celebrity photo leak videos flood TikTok with Temu referral codes

temu-tiktok-header

TikTok is flooded with videos promoting fake nude celebrity photo leaks used to push referral rewards for the Temu online megastore.

Continue reading
  953 Hits

National Student Clearinghouse data breach impacts 890 schools

Hacker-books

U.S. educational nonprofit National Student Clearinghouse has disclosed a data breach affecting 890 schools using its services across the United States. 

Continue reading
  992 Hits

TransUnion denies it was hacked, links leaked data to 3rd party

TransUnion

Credit reporting firm TransUnion has denied claims of a security breach after a threat actor known as USDoD leaked data allegedly stolen from the company's network.  The Chicago-based company's over 10,000 employees provide their services to millions of consumers and more than 65,000 businesses from 30 countries. "Immediately upon discovering ...

Continue reading
  873 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023