The Information Highway

The Information Highway

all things technology risk and cybersecurity

CISA issues DDoS warning after attacks hit multiple US orgs

0_CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today of ongoing distributed denial-of-service (DDoS) attacks after U.S. organizations across multiple industry sectors were hit. 

Continue reading
  1094 Hits

American Airlines, Southwest Airlines disclose data breaches affecting pilots

airplane

American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data breaches on Friday caused by the hack of Pilot Credentials, a third-party vendor that manages multiple airlines' pilot applications and recruitment portals.

Continue reading
  1063 Hits

Grafana warns of critical auth bypass due to Azure AD integration

header-grafan_20230625-032344_1

Grafana has released security fixes for multiple versions of its application, addressing a vulnerability that enables attackers to bypass authentication and take over any Grafana account that uses Azure Active Directory for authentication. 

Continue reading
  970 Hits

LastPass users furious after being locked out due to MFA resets

Lastpass-headpic

LastPass password manager users have been experiencing significant login issues starting early May after being prompted to reset their authenticator apps. 

Continue reading
  863 Hits

Microsoft Teams bug allows malware delivery from external accounts

Microsoft_Teams

Security researchers have found a simple way to deliver malware to an organization with Microsoft Teams, despite restrictions in the application for files from external sources. 

Continue reading
  1050 Hits

Over 100,000 ChatGPT Account Credentials Made Available on the Dark Web

ChatGPTCover

ChatGPT users should be wary that their personal data might've been leaked online, following the dump of more than 100,000 ChatGPT account credentials on the dark web. As reported by The Hacker News and according to Singapore-based cybersecurity company Group-IB, the credentials for users that logged into ChatGPT ranges from its launch (in June 2022) through May 2023, meaning that it's still an ongoing event. The U.S., France, Morocco, Indonesia, Pakistan, and Brazil seem to have contributed the most users towards the stolen credentials. 

Continue reading
  1033 Hits

CISA: LockBit ransomware extorted $91 million in 1,700 U.S. attacks

LockBi_20230615-213603_1

 U.S. and international cybersecurity authorities said in a joint LockBit ransomware advisory that the gang successfully extorted roughly $91 million following approximately 1,700 attacks against U.S. organizations since 2020.

Continue reading
  1038 Hits

Barracuda ESG zero-day attacks linked to suspected Chinese hackers

Barracud_20230615-215338_1

 A suspected pro-China hacker group tracked by Mandiant as UNC4841 has been linked to data-theft attacks on Barracuda ESG (Email Security Gateway) appliances using a now-patched zero-day vulnerability.

Continue reading
  1073 Hits

Russian hackers use PowerShell USB malware to drop backdoors

green-hacker-bright

The Russian state-sponsored hacking group Gamaredon (aka Armageddon or Shuckworm) continues to target critical organizations in Ukraine's military and security intelligence sectors, employing a refreshed toolset and new infection tactics. 

Continue reading
  1046 Hits

Microsoft: Windows Kernel CVE-2023-32019 fix is disabled by default

Windows-attac_20230616-032024_1

Microsoft has released an optional fix to address a Kernel information disclosure vulnerability affecting systems running multiple Windows versions, including the latest Windows 10, Windows Server, and Windows 11 releases. 

Continue reading
  1145 Hits

Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day

VMware

Initially detailed in September 2022, UNC3886 has been using malicious vSphere Installation Bundles (VIBs) – packages that are typically used to maintain systems and deploy updates – to install backdoors on ESXi hypervisors and gain command execution, file manipulation, and reverse shell capabilities.

Continue reading
  1022 Hits

Fortinet: New FortiOS RCE bug "may have been exploited" in attacks

Fortinet

Fortinet says a critical FortiOS SSL VPN vulnerability that was patched last week "may have been exploited" in attacks impacting government, manufacturing, and critical infrastructure organizations.

Continue reading
  1011 Hits

Flash loan attack on Jimbos Protocol steals over $7.5 million

Flash loan attack on Jimbos Protocol steals over $7.5 million

Jimbos Protocol, an Arbitrum-based DeFi project, has suffered a flash loan attack that resulted in the loss of more than of 4000 ETH tokens, currently valued at over $7,500,000.

Continue reading
  1123 Hits

MCNA Dental data breach impacts 8.9 million people after ransomware attack

MCNA Dental data breach impacts 8.9 million people after ransomware attack
Managed Care of North America (MCNA) Dental has published a data breach notification on its website, informing almost 9 million patients that their personal data were compromised.
Continue reading
  1036 Hits

Lazarus hackers target Windows IIS web servers for initial access

Lazarus hackers target Windows IIS web servers for initial access
The notorious North Korean state-backed hackers, known as the Lazarus Group, are now targeting vulnerable Windows Internet Information Services (IIS) web servers to gain initial access to corporate networks.
Continue reading
  1038 Hits

Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains

Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains
A new 'File Archivers in the Browser' phishing kit abuses ZIP domains by displaying fake WinRAR or Windows File Explorer windows in the browser to convince users to launch malicious files.
Continue reading
  1084 Hits

CISA warns govt agencies of recently patched Barracuda zero-day

CISA warns govt agencies of recently patched Barracuda zero-day
CISA warned of a recently patched zero-day vulnerability exploited last week to hack into Barracuda Email Security Gateway (ESG) appliances.
Continue reading
  954 Hits

QBot malware abuses Windows WordPad EXE to infect devices

QBot malware abuses Windows WordPad EXE to infect devices
The QBot malware operation has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program to infect computers, using the legitimate program to evade detection by security software.
Continue reading
  985 Hits

Hot Pixels attack checks CPU temp, power changes to steal data

Hot Pixels attack checks CPU temp, power changes to steal data
A team of researchers at Georgia Tech, the University of Michigan, and Ruhr University Bochum have developed a novel attack called "Hot Pixels," which can retrieve pixels from the content displayed in the target's browser and infer the navigation history.
Continue reading
  1022 Hits

IT employee impersonates ransomware gang to extort employer

IT employee impersonates ransomware gang to extort employer
A 28-year-old United Kingdom man from Fleetwood, Hertfordshire, has been convicted of unauthorized computer access with criminal intent and blackmailing his employer.
Continue reading
  1047 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023