The Information Highway

The Information Highway

all things technology risk and cybersecurity

Ransomware gang targets Windows admins via PuTTy, WinSCP malvertising

windows-server-admin-logi_20240519-191426_1

A ransomware operation targets Windows system administrators by taking out Google ads to promote fake download sites for Putty and WinSCP.

Continue reading
  665 Hits

Microsoft to start enforcing Azure multi-factor authentication in July

Microsoft_passwordless

Starting in July, Microsoft will begin gradually enforcing multi-factor authentication (MFA) for all users signing into Azure to administer resources.

Continue reading
  524 Hits

WebTPA data breach impacts 2.4 million insurance policyholders

medical-data-header

The WebTPA Employer Services (WebTPA) data breach disclosed earlier this month is impacting close to 2.5 million individuals, the U.S. Department of Health and Human Services notes.

Continue reading
  546 Hits

Norway recommends replacing SSL VPN to prevent breaches

global-pew-pe_20240519-183959_1

The Norwegian National Cyber Security Centre (NCSC) recommends replacing SSLVPN/WebVPN solutions with alternatives due to the repeated exploitation of related vulnerabilities in edge network devices to breach corporate networks. 

Continue reading
  670 Hits

MediSecure e-script firm hit by ‘large-scale’ ransomware data breach

data-breach-header

Electronic prescription provider MediSecure in Australia has shut down its website and phone lines following a ransomware attack believed to originate from a third-party vendor.

Continue reading
  553 Hits

How to manage the security risks of generative AI tools

nudge-ai-tool_20240519-181355_1

Over the past year, we've witnessed an explosive growth spurt in consumer-focused AI productivity tools that has once again transformed the way we work. Once the realm of data science and engineering teams, generative AI was packaged and delivered to the masses in 2023.

Continue reading
  523 Hits

Critical flaws discovered in Cacti framework

Threat-Advisory-Banner3

Threat update

This Cybersecurity Threat Advisory breaks down multiple critical vulnerabilities in the Cacti framework, an open-source network monitoring and fault management tool. Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary code and compromise network infrastructure.

Continue reading
  584 Hits

Critical GitLab bug

Threat-Advisory-Banne2r

Threat update

 A critical vulnerability in GitLab, labeled CVE-2023-7028, is under active attack by threat actors to achieve account takeover, as reported by the Cybersecurity and Infrastructure Security Agency (CISA).

Continue reading
  553 Hits

Apple backports fix for RTKit iOS zero-day to older iPhones

Appl_20240514-030518_1

Apple has backported security patches released in March to older iPhones and iPads, fixing an iOS Kernel zero-day tagged as exploited in attacks.

Continue reading
  495 Hits

Hackers use DNS tunneling for network scanning, tracking victims

hacker-tunnel

Threat actors are using Domain Name System (DNS) tunneling to track when their targets open phishing emails and click on malicious links, and to scan networks for potential vulnerabilities.

Continue reading
  584 Hits

The Post Millennial hack leaked data impacting 26 million people

hand-sifting-data

Have I Been Pwned has added the information for 26,818,266 people whose data was leaked in a recent hack of The Post Millennial conservative news website.

Continue reading
  605 Hits

CISA: Black Basta ransomware breached over 500 orgs worldwide

CISA-red-flare

CISA and the FBI said today that Black Basta ransomware affiliates breached over 500 organizations between April 2022 and May 2024.

Continue reading
  539 Hits

Widely used modems in industrial IoT devices open to SMS attack

world-internet-network

Security flaws in Telit Cinterion cellular modems, widely used in sectors including industrial, healthcare, and telecommunications, could allow remote attackers to execute arbitrary code via SMS.

Continue reading
  596 Hits

Dell API abused to steal 49 million customer records in data breach

Dell-headpic

The threat actor behind the recent Dell data breach revealed they scraped information of 49 million customer records using an partner portal API they accessed as a fake company. 

Continue reading
  676 Hits

Ohio Lottery ransomware attack impacts over 538,000 individuals

Ohio-Lottery

The Ohio Lottery is sending data breach notification letters to over 538,000 individuals affected by a cyberattack that hit the organization's systems on Christmas Eve.

Continue reading
  431 Hits

Monday.com removes "Share Update" feature abused for phishing attacks

monday-cyber

Project management platform Monday.com has removed its "Share Update" feature after threat actors abused it in phishing attacks. 

Continue reading
  548 Hits

RCE vulnerabilities in HPE Aruba Networking devices

Threat-Advisory-Banne2r

Threat update

HPE Aruba Networking has disclosed that critical remote code execution (RCE) vulnerabilities are impacting multiple versions of ArubaOS. Out of the ten vulnerabilities found, four pose critical risks of unauthenticated buffer overflows in various services.

Continue reading
  475 Hits

City of Wichita shuts down IT network after ransomware attack

wichita

The City of Wichita, Kansas, disclosed it was forced to shut down portions of its network after suffering a weekend ransomware attack.

Continue reading
  486 Hits

R Programming Vulnerability

Threat-Advisory-Banne2r

Threat update

A critical security flaw known as CVE-2024-27322 with a CVSS score of 8.8, has been discovered within the R programming language. Attackers can craft malicious RDS files or R packages that embed arbitrary R code. 

Continue reading
  562 Hits

Android bug leaks DNS queries even when VPN kill switch is enabled

Android-lea_20240506-151316_1

A Mullvad VPN user has discovered that Android devices leak DNS queries when switching VPN servers even though the "Always-on VPN" feature was enabled with the "Block connections without VPN" option. 

Continue reading
  493 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023