The Information Highway

The Information Highway

all things technology risk and cybersecurity

Cisco Catalyst SD-WAN Manager flaw allows remote server access

Cisco__headpic

Cisco is warning of five new Catalyst SD-WAN Manager products vulnerabilities with the most critical allowing unauthenticated remote access to the server. 

Continue reading
  1147 Hits

Google fixes fifth actively exploited Chrome zero-day of 2023

Google_Chrome

Google has patched the fifth Chrome zero-day vulnerability exploited in attacks since the start of the year in emergency security updates released today. 

Continue reading
  1128 Hits

New ZeroFont phishing tricks Outlook into showing fake AV-scans

Outlook_headpic_red

Hackers are utilizing a new trick of using zero-point fonts in emails to make malicious emails appear as safely scanned by security tools in Microsoft Outlook. 

Continue reading
  1279 Hits

SickKids impacted by BORN Ontario data breach that hit 3.4 million

sickkids

The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were impacted by the recent breach at BORN Ontario. 

Continue reading
  1073 Hits

Fake celebrity photo leak videos flood TikTok with Temu referral codes

temu-tiktok-header

TikTok is flooded with videos promoting fake nude celebrity photo leaks used to push referral rewards for the Temu online megastore.

Continue reading
  1267 Hits

National Student Clearinghouse data breach impacts 890 schools

Hacker-books

U.S. educational nonprofit National Student Clearinghouse has disclosed a data breach affecting 890 schools using its services across the United States. 

Continue reading
  1330 Hits

TransUnion denies it was hacked, links leaked data to 3rd party

TransUnion

Credit reporting firm TransUnion has denied claims of a security breach after a threat actor known as USDoD leaked data allegedly stolen from the company's network.  The Chicago-based company's over 10,000 employees provide their services to millions of consumers and more than 65,000 businesses from 30 countries. "Immediately upon discovering ...

Continue reading
  1117 Hits

BlackCat ransomware hits Azure Storage with Sphynx encryptor

BlackCat_Sphynx

The BlackCat (ALPHV) ransomware gang now uses stolen Microsoft accounts and the recently spotted Sphynx encryptor to encrypt targets' Azure cloud storage. 

Continue reading
  1454 Hits

CISA warns of critical Apache RocketMQ bug exploited in attacks

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added to its catalog of known exploited vulnerabilities (KEV) a critical–severity issue tracked as CVE-2023-33246 that affects Apache's RocketMQ distributed messaging and streaming platform. 

Continue reading
  1197 Hits

Apple zero-click iMessage exploit used to infect iPhones with spyware

apple-triangle

Citizen Lab says two zero-days fixed by Apple today in emergency security updates were actively abused as part of a zero-click exploit chain (dubbed BLASTPASS) to deploy NSO Group's Pegasus commercial spyware onto fully patched iPhones. 

Continue reading
  1147 Hits

Microsoft Teams phishing attack pushes DarkGate malware

Microsoft_Teams

A new phishing campaign is abusing Microsoft Teams messages to send malicious attachments that install the DarkGate Loader malware. 

Continue reading
  1793 Hits

Cisco warns of VPN zero-day exploited by ransomware gangs

Cisco_headpic

Cisco is warning of a CVE-2023-20269 zero-day vulnerability in its Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) that is actively exploited by ransomware operations to gain initial access to corporate networks. 

Continue reading
  1456 Hits

Apple discloses 2 new zero-days exploited to attack iPhones, Macs

Apple

Apple released emergency security updates to fix two new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 13 exploited zero-days patched since the start of the year. 

Continue reading
  1113 Hits

Windows cryptomining attacks target graphic designer's high-powered GPUs

graphics-card

Cybercriminals are leveraging a legitimate Windows tool called 'Advanced Installer' to infect the computers of graphic designers with cryptocurrency miners. 

Continue reading
  1109 Hits

Johnson & Johnson discloses IBM data breach impacting patients

server-rack

Johnson & Johnson Health Care Systems ("Janssen") has informed its CarePath customers that their sensitive information has been compromised in a third-party data breach involving IBM. 

Continue reading
  1168 Hits

Obsessed with privacy? Keep Tails on a USB drive and secure most any computer

screenshot-2023-08-29-18532_20230909-192716_1

If you're looking for protection against surveillance and censorship, this Tor-based operating system is worth a try. Here's how you get started. 

Continue reading
  1139 Hits

Chrome extensions can steal plaintext passwords from websites

Google___Chrome

A team of researchers from the University of Wisconsin-Madison has uploaded to the Chrome Web Store a proof-of-concept extension that can steal plaintext passwords from a website's source code 

Continue reading
  1132 Hits

NIST to Standardize Encryption Algorithms That Can Resist Attack by Quantum Computers

PQC_Algo_Pre-standardization-vid

Three new algorithms are expected to be ready for use in 2024. Others will follow.

Continue reading
  1186 Hits

Major U.S. energy org targeted in QR code phishing attack

phishing-hook

A phishing campaign was observed predominantly targeting a notable energy company in the US, employing QR codes to slip malicious emails into inboxes and bypass security.

Continue reading
  1323 Hits

LinkedIn accounts hacked in widespread hijacking campaign

hacker-holding-linkedin

LinkedIn is being targeted in a wave of account hacks resulting in many accounts being locked out for security reasons or ultimately hijacked by attackers. 

Continue reading
  1444 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024