The Information Highway

The Information Highway

all things technology risk and cybersecurity

Global infostealer malware operation targets crypto users, gamers

hacker-looking-at-screens

A massive infostealer malware operation encompassing thirty campaigns targeting a broad spectrum of demographics and system platforms has been uncovered, attributed to a cybercriminal group named "Marko Polo." 

Continue reading
  239 Hits

SolarWinds ARM vulnerabilities

Threat-Advisory-Banner3

Threat update

SolarWinds has issued patches to address two vulnerabilities in its Access Rights Manager (ARM) software. Out of the two, one is a critical vulnerability that can lead to remote code execution (RCE).



Continue reading
  272 Hits

Dell investigates data breach claims after hacker leaks employee info

Dell-headpic

Dell has confirmed that they are investigating recent claims that it suffered a data breach after a threat actor leaked the data for over 10,000 employees. 

Continue reading
  282 Hits

CISA warns of actively exploited Apache HugeGraph-Server bug

apache-header-image

The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting Apache HugeGraph-Server. 

Continue reading
  248 Hits

Ivanti warns of another critical CSA flaw exploited in attacks

ivanti-headpic

 Today, Ivanti warned that threat actors are exploiting another Cloud Services Appliance (CSA) security flaw in attacks targeting a limited number of customers.

Continue reading
  205 Hits

FTC exposes massive surveillance of kids, teens by social media giants

FTC

 A Federal Trade Commission (FTC) staff report has found that social media and video streaming companies have been engaging in widespread user surveillance, particularly of children and teens, with insufficient privacy protections and earning billions of dollars annually by monetizing their data.

Continue reading
  193 Hits

X hacking spree fuels "$HACKED" crypto token pump-and-dump

X-logo-flare

An X account hacking spree has fueled a successful pump-and-dump scheme for the $HACKED Solana token, with people rushing to buy the coin.

Continue reading
  189 Hits

Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware

Hospital

 Microsoft says a ransomware affiliate it tracks as Vanilla Tempest now targets U.S. healthcare organizations in INC ransomware attacks.

Continue reading
  260 Hits

GitLab releases fix for critical SAML authentication bypass flaw

GitLab

 GitLab has released security updates to address a critical SAML authentication bypass vulnerability impacting self-managed installations of the GitLab Community Edition (CE) and Enterprise Edition (EE).

Continue reading
  187 Hits

FBI tells public to ignore false claims of hacked voter data

CISA

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are alerting the public of false claims that the U.S. voter registration data has been compromised in cyberattacks.

Continue reading
  289 Hits

Malware locks browser in kiosk mode to steal Google credentials

kiosk

A malware campaign uses the unusual method of locking users in their browser's kiosk mode to annoy them into entering their Google credentials, which are then stolen by information-stealing malware.

Continue reading
  258 Hits

Port of Seattle hit by Rhysida ransomware in August attack

Port-of-Seattle

Port of Seattle, the United States government agency overseeing Seattle's seaport and airport, confirmed on Friday that the Rhysida ransomware operation was behind a cyberattack impacting its systems over the last three weeks.

Continue reading
  208 Hits

RansomHub claims Kawasaki cyberattack, threatens to leak stolen data

Kawasaki

Kawasaki Motors Europe has announced that its recovering from a cyberattack that caused service disruptions as the RansomHub ransomware gang threatens to leak stolen data.

Continue reading
  200 Hits

FBI: Reported cryptocurrency losses reached $5.6 billion in 2023

FBI_cryptocurrency

The FBI says that 2023 was a record year for cryptocurrency fraud, with total losses exceeding $5.6 billion, based on nearly 70,000 reports received through the Internet Crime Complaint Center (IC3).

Continue reading
  198 Hits

Fortinet confirms data breach after hacker claims to steal 440GB of files

Fortinet

Cybersecurity giant Fortinet has confirmed it suffered a data breach after a threat actor claimed to steal 440GB of files from the company's Microsoft SharePoint server.

Continue reading
  267 Hits

Fake password manager coding test used to hack Python developers

developer

Members of the North Korean hacker group Lazarus posing as recruiters are baiting Python developers with coding test project for password management products that include malware.

Continue reading
  265 Hits

Adobe fixes Acrobat Reader zero-day with public PoC exploit

adob_20240914-211645_1

A cybersecurity researcher is urging users to upgrade Adobe Acrobat Reader after a fix was released yesterday for a remote code execution zero-day with a public in-the-wild proof-of-concept exploit.

Continue reading
  284 Hits

Veeam Backup security flaws

Threat-Advisory-Banner3

Threat update

There were recently six vulnerabilities discovered in Veeam Backup and Replication. One of them is an unauthenticated remote code execution (RCE), while the other five include authenticated RCE, arbitrary file deletion, low-privileged multi-factor authentication (MFA) setting modification and MFA bypass, credential sniffing, and privilege escalation. Review the details in this Cybersecurity Threat Advisory to limit customers' impact.

Continue reading
  241 Hits

Ivanti fixes maximum severity RCE bug in Endpoint Management software

Ivanti

Ivanti has fixed a maximum severity vulnerability in its Endpoint Management software (EPM) that can let unauthenticated attackers gain remote code execution on the core server.

Continue reading
  213 Hits

Progress LoadMaster vulnerable to 10/10 severity RCE flaw

Progress_headpic

Progress Software has issued an emergency fix for a maximum (10/10) severity vulnerability impacting its LoadMaster and LoadMaster Multi-Tenant (MT) Hypervisor products that allows attackers to remotely execute commands on the device.

Continue reading
  217 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023