The Information Highway

The Information Highway

all things technology risk and cybersecurity

Roku warns 576,000 accounts hacked in new credential stuffing attacks

Roku

Roku warns that 576,000 accounts were hacked in new credential stuffing attacks after disclosing another incident that compromised 15,000 accounts in early March.

Continue reading
  673 Hits

Palo Alto Networks warns of PAN-OS firewall zero-day used in attacks

Palo_Alto_Networks

Today, Palo Alto Networks warns that an unpatched critical command injection vulnerability in its PAN-OS firewall is being actively exploited in attacks.

Continue reading
  877 Hits

LastPass: Hackers targeted employee in failed deepfake CEO call

LastPass-headpi_20240413-224058_1

LastPass revealed this week that threat actors targeted one of its employees in a voice phishing attack, using deepfake audio to impersonate Karim Toubba, the company's Chief Executive Officer.

Continue reading
  681 Hits

Palo Alto Networks zero-day exploited since March to backdoor firewalls

Hacker_datacenter_servers

Suspected state-sponsored hackers have been exploiting a zero-day vulnerability in Palo Alto Networks firewalls tracked as CVE-2024-3400 since March 26, using the compromised devices to breach internal networks, steal data and credentials.

Continue reading
  654 Hits

Critical flaws in Ivanti

Threat-Advisory-Banner

Threat update

Recent flaws found in Ivanti Connect Secure and Policy Secure Gateways can lead to remote code execution (RCE) attacks. Review this Cybersecurity Threat Advisory to learn additional details and recommendations to keep your organization secure. 

Continue reading
  683 Hits

D-Link NAS vulnerabilities

Threat-Advisory-Banner

Threat update

Two vulnerabilities were found in legacy D-Link products that have reached end-of-life (EoL) status. The vulnerabilities can cause command injection and backdoor account to these devices. This Cybersecurity Threat Advisory discusses the impact of the threat, as well as recommendations to mitigate risks these vulnerabilities may cause.

Continue reading
  606 Hits

XZ Utils supply chain vulnerability

Threat-Advisory-Banner

Threat update

A supply chain vulnerability was found in XZ Utils that creates a backdoor into OpenSSH and can lead to remote code execution (RCE). Read this Cybersecurity Threat Advisory to learn about this supply chain vulnerability and how to reduce your risks. 

Continue reading
  670 Hits

Over 92,000 exposed D-Link NAS devices have a backdoor account

map-dlink

A threat researcher has disclosed a new arbitrary command injection and hardcoded backdoor flaw in multiple end-of-life D-Link Network Attached Storage (NAS) device models.. 

Continue reading
  741 Hits

Fake Facebook MidJourney AI page promoted malware to 1.2 million people

ai-robot-hacker-disiintegratin

Hackers are using Facebook advertisements and hijacked pages to promote fake Artificial Intelligence services, such as MidJourney, OpenAI's SORA and ChatGPT-5, and DALL-E, to infect unsuspecting users with password-stealing malware.

Continue reading
  800 Hits

Acuity confirms hackers stole non-sensitive govt data from GitHub repos

data-theft

Acuity, a federal contractor that works with U.S. government agencies, has confirmed that hackers breached its GitHub repositories and stole documents containing old and non-sensitive data.

Continue reading
  618 Hits

Panera Bread week-long IT outage caused by ransomware attack

Panera

Panera Bread's recent week-long outage was caused by a ransomware attack, according to people familiar with the matter and emails. 

Continue reading
  617 Hits

Visa warns of new JSOutProx malware variant targeting financial orgs

malware-phishing-header

Visa is warning about a spike in detections for a new version of the JsOutProx malware targeting financial institutions and their customers.

Continue reading
  701 Hits

US cancer center data breach exposes info of 827,000 patients

city-of-hope-center

Cancer treatment and research center City of Hope is warning that a data breach exposed the sensitive information of over 820,000 patients. 

Continue reading
  687 Hits

TA558 phishing campaign

Threat-Advisory-Banner

Threat update

 The threat actor TA558 is conducting a phishing campaign targeting various sectors in Latin America, intending to deploy the remote access tool known as Venom RAT. LBT Technology Group encourages organizations to follow the recommendations detailed in this Cybersecurity Threat Advisory to mitigate the potential risk of this campaign.

Continue reading
  791 Hits

GitHub supply chain attack

Threat-Advisory-Banner

Threat update

Malicious actors have launched a software supply chain attack targeting developers on the GitHub platform. LBT Technology Group, LLC. recommends taking proactive measures detailed in this Cybersecurity Threat Advisory to mitigate the risk. 

Continue reading
  637 Hits

AWS 'FlowFixation' vulnerabiltiy

Threat-Advisory-Banner

Threat update

The AWS "FlowFixation" vulnerability, while patched in September 2023, may still pose account hijacking risks within its Amazon Managed Workflows Apache Airflow (MWAA) service. Read this Cybersecurity Threat Advisory to learn the impact and security measures to mitigate risks associated with this vulnerability. 

Continue reading
  637 Hits

New vulnerability in Apple M-chip

Threat-Advisory-Banner

Threat update

A new security exploit, GoFetch, was found in Apple's M-chip architecture. It takes advantage of data memory-dependent prefetchers (DMPs) and could use the device as a new attack vector. Continue reading to learn how you can mitigate the risks associated with this threat.
Continue reading
  667 Hits

AT&T confirms data for 73 million customers leaked on hacker forum

ATT

AT&T has finally confirmed it is impacted by a data breach affecting 73 million current and former customers after initially denying the leaked data originated from them.

Continue reading
Tags:
  895 Hits

Vultur banking malware for Android poses as McAfee Security app

android

Security researchers found a new version of the Vultur banking trojan for Android that includes more advanced remote control capabilities and an improved evasion mechanism.

Continue reading
  808 Hits

Retail chain Hot Topic hit by new credential stuffing attacks

HOT-TOPIC

American retailer Hot Topic disclosed that two waves of credential stuffing attacks in November exposed affected customers' personal information and partial payment data.

Continue reading
  719 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023