The Information Highway

The Information Highway

all things technology risk and cybersecurity

New RAMBO attack steals data using RAM in air-gapped computers

Airgapped

 A novel side-channel attack dubbed "RAMBO" (Radiation of Air-gapped Memory Bus for Offense) generates electromagnetic radiation from a device's RAM to send data from air-gapped computers.

Continue reading
  255 Hits

Car rental giant Avis discloses data breach impacting customers

AVIS

American car rental giant Avis notified customers that unknown attackers breached one of its business applications last month and stole some of their personal information.

Continue reading
  290 Hits

Microsoft Office 2024 to disable ActiveX controls by default

Microsoft_Office

 After Office 2024 launches in October, Microsoft will disable ActiveX controls by default in Word, Excel, PowerPoint, and Visio client apps.

Continue reading
  282 Hits

SpyAgent Android malware steals your crypto recovery phrases from images

android-eyes

A new Android malware named SpyAgent uses optical character recognition (OCR) technology to steal cryptocurrency wallet recovery phrases from screenshots stored on the mobile device.

Continue reading
  235 Hits

SonicWall SSLVPN access control flaw is now exploited in attacks

Sonicwall

SonicWall is warning that a recently fixed access control flaw tracked as CVE-2024-40766 in SonicOS is now "potentially" exploited in attacks, urging admins to apply patches as soon as possible.

Continue reading
  300 Hits

Apache fixes critical OFBiz remote code execution vulnerability

apache-header-image

Apache has fixed a critical security vulnerability in its open-source OFBiz (Open For Business) software, which could allow attackers to execute arbitrary code on vulnerable Linux and Windows servers.

Continue reading
  230 Hits

LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks

back-2

Yet, another critical severity vulnerability has been discovered in LiteSpeed Cache, a caching plugin for speeding up user browsing in over 6 million WordPress sites.

Continue reading
  226 Hits

Veeam warns of critical RCE flaw in Backup & Replication software

Veeam

Veeam has released security updates for several of its products as part of a single September 2024 security bulletin that addresses 18 high and critical severity flaws in Veeam Backup & Replication, Service Provider Console, and One.

Continue reading
  252 Hits

Hacker trap: Fake OnlyFans tool backstabs cybercriminals, steals passwords

onlyfans-header-image

Hackers are targeting other hackers with a fake OnlyFans tool that claims to help steal accounts but instead infects threat actors with the Lumma stealer information-stealing malware.

Continue reading
  218 Hits

Business services giant CBIZ discloses customer data breach

back

CBIZ Benefits & Insurance Services (CBIZ) has disclosed a data breach that involves unauthorized access of client information stored in specific databases.

Continue reading
  203 Hits

Linux version of new Cicada ransomware targets VMware ESXi servers

cicada

A new ransomware-as-a-service (RaaS) operation is impersonating the legitimate Cicada 3301 organization and has already listed 19 victims on its extortion portal, as it quickly attacked companies worldwide.

Continue reading
  276 Hits

New Voldemort malware abuses Google Sheets to store stolen data

evil_hacke_20240902-193133_1

 A new malware campaign is spreading a previously undocumented backdoor named "Voldemort" to organizations worldwide, impersonating tax agencies from the U.S., Europe, and Asia.

Continue reading
  316 Hits

Understanding the Difference Between Cybersecurity and Cybersecurity Risk

csr

In today's digital age, the terms "cybersecurity" and "cybersecurity risk" are often used interchangeably. However, they represent different concepts that are crucial for understanding how to protect information systems effectively. Let's delve into what these terms mean and how they relate to each other. 

Continue reading
  298 Hits

Halliburton cyberattack linked to RansomHub ransomware gang

Hallliburton

The RansomHub ransomware gang is behind the recent cyberattack on oil and gas services giant Halliburton, which disrupted the company's IT systems and business operations.

Continue reading
  251 Hits

Fake Palo Alto GlobalProtect used as lure to backdoor enterprises

malware-phishing-header

Threat actors target Middle Eastern organizations with malware disguised as the legitimate Palo Alto GlobalProtect Tool that can steal data and execute remote PowerShell commands to infiltrate internal networks further.

Continue reading
  251 Hits

PoorTry Windows driver evolves into a full-featured EDR wiper

hacker

The malicious PoorTry kernel-mode Windows driver used by multiple ransomware gangs to turn off Endpoint Detection and Response (EDR) solutions has evolved into an EDR wiper, deleting files crucial for the operation of security solutions and making restoration harder. 

Continue reading
  277 Hits

DICK'S shuts down email, locks employee accounts after cyberattack

DICK-S

DICK'S Sporting Goods, the largest chain of sporting goods retail stores in the United States, disclosed that confidential information was exposed in a cyberattack detected last Wednesday.

Continue reading
  209 Hits

Critical SonicOS Vulnerability

Threat-Advisory-Banner3

Threat update

A critical vulnerability has been identified in the SonicWall SonicOS management access. 

Continue reading
  238 Hits

Park’N Fly notifies 1 million customers of data breach

park-n-fly

Park'N Fly is warning that a data breach exposed the personal and account information of 1 million customers in Canada after hackers breached its network. 

Continue reading
  253 Hits

Microsoft Sway abused in massive QR code phishing campaign

Phishing

A massive QR code phishing campaign abused Microsoft Sway, a cloud-based tool for creating online presentations, to host landing pages to trick Microsoft 365 users into handing over their credentials. 

Continue reading
  252 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023