The Information Highway

The Information Highway

all things technology risk and cybersecurity

MCNA Dental data breach impacts 8.9 million people after ransomware attack

MCNA Dental data breach impacts 8.9 million people after ransomware attack
Managed Care of North America (MCNA) Dental has published a data breach notification on its website, informing almost 9 million patients that their personal data were compromised.
Continue reading
  1277 Hits

Lazarus hackers target Windows IIS web servers for initial access

Lazarus hackers target Windows IIS web servers for initial access
The notorious North Korean state-backed hackers, known as the Lazarus Group, are now targeting vulnerable Windows Internet Information Services (IIS) web servers to gain initial access to corporate networks.
Continue reading
  1323 Hits

Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains

Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains
A new 'File Archivers in the Browser' phishing kit abuses ZIP domains by displaying fake WinRAR or Windows File Explorer windows in the browser to convince users to launch malicious files.
Continue reading
  1306 Hits

CISA warns govt agencies of recently patched Barracuda zero-day

CISA warns govt agencies of recently patched Barracuda zero-day
CISA warned of a recently patched zero-day vulnerability exploited last week to hack into Barracuda Email Security Gateway (ESG) appliances.
Continue reading
  1201 Hits

QBot malware abuses Windows WordPad EXE to infect devices

QBot malware abuses Windows WordPad EXE to infect devices
The QBot malware operation has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program to infect computers, using the legitimate program to evade detection by security software.
Continue reading
  1219 Hits

Hot Pixels attack checks CPU temp, power changes to steal data

Hot Pixels attack checks CPU temp, power changes to steal data
A team of researchers at Georgia Tech, the University of Michigan, and Ruhr University Bochum have developed a novel attack called "Hot Pixels," which can retrieve pixels from the content displayed in the target's browser and infer the navigation history.
Continue reading
  1307 Hits

IT employee impersonates ransomware gang to extort employer

IT employee impersonates ransomware gang to extort employer
A 28-year-old United Kingdom man from Fleetwood, Hertfordshire, has been convicted of unauthorized computer access with criminal intent and blackmailing his employer.
Continue reading
  1279 Hits

Cuba ransomware claims cyberattack on Philadelphia Inquirer

Cuba ransomware claims cyberattack on Philadelphia Inquirer
The Cuba ransomware gang has claimed responsibility for this month's cyberattack on The Philadelphia Inquirer, which temporarily disrupted the newspaper's distribution and disrupted some business operations.
Continue reading
  1272 Hits

New ZIP domains spark debate among cybersecurity experts

New ZIP domains spark debate among cybersecurity experts
Cybersecurity researchers and IT admins have raised concerns over Google's new ZIP and MOV Internet domains, warning that threat actors could use them for phishing attacks and malware delivery.
Continue reading
  1267 Hits

Hackers use Azure Serial Console for stealthy access to VMs

Hackers use Azure Serial Console for stealthy access to VMs
A financially motivated cybergang tracked by Mandiant as 'UNC3944' is using phishing and SIM swapping attacks to hijack Microsoft Azure admin accounts and gain access to virtual machines.
Continue reading
  1272 Hits

Ransomware gang steals data of 5.8 million PharMerica patients

Ransomware gang steals data of 5.8 million PharMerica patients
Pharmacy services provider PharMerica has disclosed a massive data breach impacting over 5.8 million patients, exposing their medical data to hackers.
Continue reading
  1280 Hits

Hackers use public exploit to attack vulnerable WordPress sites

Hackers use public exploit to attack vulnerable WordPress sites
Hackers are actively exploiting a recently fixed vulnerability in the WordPress Advanced Custom Fields plugin roughly 24 hours after a proof-of-concept (PoC) exploit was made public.
Continue reading
  1200 Hits

Capita warns customers they should assume data was stolen

Capita warns customers they should assume data was stolen
Business process outsourcing firm Capita is warning customers to assume that their data was stolen in a cyberattack that affected its systems in early April.
Continue reading
  1380 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024