Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Read the latest technology news, your comprehensive source for the latest breakthroughs, trends, and innovations shaping the world of technology.

Progress LoadMaster vulnerable to 10/10 severity RCE flaw

Progress_headpic

Progress Software has issued an emergency fix for a maximum (10/10) severity vulnerability impacting its LoadMaster and LoadMaster Multi-Tenant (MT) Hypervisor products that allows attackers to remotely execute commands on the device.

Continue reading
  2310 Hits

New RAMBO attack steals data using RAM in air-gapped computers

Airgapped

 A novel side-channel attack dubbed "RAMBO" (Radiation of Air-gapped Memory Bus for Offense) generates electromagnetic radiation from a device's RAM to send data from air-gapped computers.

Continue reading
  2512 Hits

Microsoft Office 2024 to disable ActiveX controls by default

Microsoft_Office

 After Office 2024 launches in October, Microsoft will disable ActiveX controls by default in Word, Excel, PowerPoint, and Visio client apps.

Continue reading
  5272 Hits

SpyAgent Android malware steals your crypto recovery phrases from images

android-eyes

A new Android malware named SpyAgent uses optical character recognition (OCR) technology to steal cryptocurrency wallet recovery phrases from screenshots stored on the mobile device.

Continue reading
  2234 Hits

SonicWall SSLVPN access control flaw is now exploited in attacks

Sonicwall

SonicWall is warning that a recently fixed access control flaw tracked as CVE-2024-40766 in SonicOS is now "potentially" exploited in attacks, urging admins to apply patches as soon as possible.

Continue reading
  2461 Hits

Apache fixes critical OFBiz remote code execution vulnerability

apache-header-image

Apache has fixed a critical security vulnerability in its open-source OFBiz (Open For Business) software, which could allow attackers to execute arbitrary code on vulnerable Linux and Windows servers.

Continue reading
  2417 Hits

Microsoft removes revenge porn from Bing search using new tool

Microsoft_headpic

Microsoft announced today that it has partnered with StopNCII to proactively remove harmful intimate images and videos from Bing using digital hashes people create from their sensitive media.

Continue reading
  3556 Hits

LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks

back-2

Yet, another critical severity vulnerability has been discovered in LiteSpeed Cache, a caching plugin for speeding up user browsing in over 6 million WordPress sites.

Continue reading
  2208 Hits

Veeam warns of critical RCE flaw in Backup & Replication software

Veeam

Veeam has released security updates for several of its products as part of a single September 2024 security bulletin that addresses 18 high and critical severity flaws in Veeam Backup & Replication, Service Provider Console, and One.

Continue reading
  2530 Hits

Windows 10 KB5041582 update released with 5 changes and fixes

windows-blue-background

 Microsoft has released the August 2024 preview update for Windows 10, version 22H2, with fixes for issues causing system freezes and memory leaks.

Continue reading
  2313 Hits

PoorTry Windows driver evolves into a full-featured EDR wiper

hacker

The malicious PoorTry kernel-mode Windows driver used by multiple ransomware gangs to turn off Endpoint Detection and Response (EDR) solutions has evolved into an EDR wiper, deleting files crucial for the operation of security solutions and making restoration harder. 

Continue reading
  2386 Hits

Windows 11 KB5041587 update adds sharing to Android devices

Windows-11

 Microsoft has released the optional KB5041587 preview cumulative update for Windows 11 23H2 and 22H2, which adds sharing to Android devices and fixes multiple File Explorer issues.

Continue reading
  2766 Hits

Park’N Fly notifies 1 million customers of data breach

park-n-fly

Park'N Fly is warning that a data breach exposed the personal and account information of 1 million customers in Canada after hackers breached its network. 

Continue reading
  2391 Hits

Google tags a tenth Chrome zero-day as exploited this year

Google_Chrome

Today, Google revealed that it patched the tenth zero-day exploited in the wild in 2024 by attackers or security researchers during hacking contests.

Continue reading
  2328 Hits

Patelco notifies 726,000 customers of ransomware data breach

patelco

Patelco Credit Union warns customers it suffered a data breach after personal data was stolen in a RansomHub ransomware attack earlier this year.

Continue reading
  2362 Hits

Seattle-Tacoma Airport IT systems down due to a cyberattack

sea-tac-airport

The Seattle-Tacoma International Airport has confirmed that a cyberattack is likely behind the ongoing IT systems outage that disrupted reservation check-in systems and delayed flights over the weekend. 

Continue reading
  2286 Hits

US oil giant Halliburton confirms cyberattack behind systems shutdown

Halliburton

Halliburton, one of the world's largest providers of services to the energy industry, has confirmed a cyberattack that forced it to shut down some of its systems earlier this week.

Continue reading
  2571 Hits

Understanding email threats: The foundation of email security

email-bec-2431571581-1300x783

In today's digital landscape, email remains a fundamental communication tool for businesses. However, its ubiquity makes it a prime target for cyber threats. Understanding these threats is the first step in fortifying your email security. In this blog post, we'll explore the technical intricacies of various email threats and how you can protect your business from these ever-evolving dangers. 

Continue reading
  2567 Hits

How company size affects the email threats targeting your business

shutterstock_1727882452-1300x867

It takes less than a minute for someone to fall for a phishing scam. According to the 2024 Data Breach Investigations Report, the median time for a recipient to click on a malicious link after opening the email is 21 seconds, followed by 28 seconds to enter the requested data.

Continue reading
  2532 Hits

Juniper releases out-of-cycle fix for max severity auth bypass flaw

Juniper_headpic

Juniper Networks has released an emergency update to address a maximum severity vulnerability that leads to authentication bypass in Session Smart Router (SSR), Session Smart Conductor, and WAN Assurance Router products.

Continue reading
  2300 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024