The Information Highway

The Information Highway

all things technology risk and cybersecurity

Halliburton cyberattack linked to RansomHub ransomware gang

Hallliburton

The RansomHub ransomware gang is behind the recent cyberattack on oil and gas services giant Halliburton, which disrupted the company's IT systems and business operations.

Continue reading
  329 Hits

Fake Palo Alto GlobalProtect used as lure to backdoor enterprises

malware-phishing-header

Threat actors target Middle Eastern organizations with malware disguised as the legitimate Palo Alto GlobalProtect Tool that can steal data and execute remote PowerShell commands to infiltrate internal networks further.

Continue reading
  315 Hits

PoorTry Windows driver evolves into a full-featured EDR wiper

hacker

The malicious PoorTry kernel-mode Windows driver used by multiple ransomware gangs to turn off Endpoint Detection and Response (EDR) solutions has evolved into an EDR wiper, deleting files crucial for the operation of security solutions and making restoration harder. 

Continue reading
  335 Hits

DICK'S shuts down email, locks employee accounts after cyberattack

DICK-S

DICK'S Sporting Goods, the largest chain of sporting goods retail stores in the United States, disclosed that confidential information was exposed in a cyberattack detected last Wednesday.

Continue reading
  250 Hits

Critical SonicOS Vulnerability

Threat-Advisory-Banner3

Threat update

A critical vulnerability has been identified in the SonicWall SonicOS management access. 

Continue reading
  303 Hits

Park’N Fly notifies 1 million customers of data breach

park-n-fly

Park'N Fly is warning that a data breach exposed the personal and account information of 1 million customers in Canada after hackers breached its network. 

Continue reading
  319 Hits

Microsoft Sway abused in massive QR code phishing campaign

Phishing

A massive QR code phishing campaign abused Microsoft Sway, a cloud-based tool for creating online presentations, to host landing pages to trick Microsoft 365 users into handing over their credentials. 

Continue reading
  323 Hits

Google tags a tenth Chrome zero-day as exploited this year

Google_Chrome

Today, Google revealed that it patched the tenth zero-day exploited in the wild in 2024 by attackers or security researchers during hacking contests.

Continue reading
  323 Hits

Patelco notifies 726,000 customers of ransomware data breach

patelco

Patelco Credit Union warns customers it suffered a data breach after personal data was stolen in a RansomHub ransomware attack earlier this year.

Continue reading
  296 Hits

Seattle-Tacoma Airport IT systems down due to a cyberattack

sea-tac-airport

The Seattle-Tacoma International Airport has confirmed that a cyberattack is likely behind the ongoing IT systems outage that disrupted reservation check-in systems and delayed flights over the weekend. 

Continue reading
  330 Hits

Your Oracle NetSuite data may be exposed

Threat-Advisory-Banner3

Threat update

Researchers discovered that externally-facing Oracle NetSuite e-commerce sites may expose sensitive customer information when configured inaccurately.

Continue reading
  391 Hits

US oil giant Halliburton confirms cyberattack behind systems shutdown

Halliburton

Halliburton, one of the world's largest providers of services to the energy industry, has confirmed a cyberattack that forced it to shut down some of its systems earlier this week.

Continue reading
  331 Hits

Critical zero-day vulnerability in Apache OFBiz

Threat-Advisory-Banner3

Threat update

CVE-2024-38856 is a new Apache OFBiz ERP system critical zero-day vulnerability. If you are using this system, please continue reading to learn which steps you should take to mitigate your risk. 

Continue reading
  348 Hits

Understanding email threats: The foundation of email security

email-bec-2431571581-1300x783

In today's digital landscape, email remains a fundamental communication tool for businesses. However, its ubiquity makes it a prime target for cyber threats. Understanding these threats is the first step in fortifying your email security. In this blog post, we'll explore the technical intricacies of various email threats and how you can protect your business from these ever-evolving dangers. 

Continue reading
  345 Hits

How company size affects the email threats targeting your business

shutterstock_1727882452-1300x867

It takes less than a minute for someone to fall for a phishing scam. According to the 2024 Data Breach Investigations Report, the median time for a recipient to click on a malicious link after opening the email is 21 seconds, followed by 28 seconds to enter the requested data.

Continue reading
  427 Hits

VMware ESXi flaw exploited by ransomware group

Threat-Advisory-Banner3

Threat update

A VMware ESXi vulnerability, known as CVE-2024-37085, has been discovered and it is actively exploited by several ransomware groups. Review this Cybersecurity Threat Advisory to learn how to limit the impact of this flaw. 

Continue reading
  426 Hits

Fake IT support sites push malicious PowerShell scripts as Windows fixes

hacker-arms-raised-brighter

Fake IT support sites promote malicious PowerShell "fixes" for common Windows errors, like the 0x80070643 error, to infect devices with information-stealing malware.

Continue reading
  567 Hits

Juniper releases out-of-cycle fix for max severity auth bypass flaw

Juniper_headpic

Juniper Networks has released an emergency update to address a maximum severity vulnerability that leads to authentication bypass in Session Smart Router (SSR), Session Smart Conductor, and WAN Assurance Router products.

Continue reading
  460 Hits

Hackers exploit critical D-Link DIR-859 router flaw to steal passwords

D_Link_headpic

Hackers are exploiting a critical vulnerability that affects all D-Link DIR-859 WiFi routers to collect account information from the device, including passwords.

Continue reading
  504 Hits

Dairy giant Agropur says data breach exposed customer info

cows

Agropur, one of the largest dairy cooperatives in North America, is notifying customers of a data breach after some of its shared online directories were exposed.

Continue reading
  516 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023