The Information Highway

The Information Highway

all things technology risk and cybersecurity

Mortgage firm LoanCare warns 1.3 million people of data breach

loancare-header-bw

Mortgage servicing company LoanCare is warning 1,316,938 borrowers across the U.S. that their sensitive information was exposed in a data breach at its parent company, Fidelity National Financial. 

Continue reading
  747 Hits

New Xamalicious Android malware installed 330k times on Google Play

Android_malware

 A previously unknown Android backdoor named 'Xamalicious' has infected approximately 338,300 devices via malicious apps on Google Play, Android's official app store.

Continue reading
  757 Hits

iPhone Triangulation attack abused undocumented hardware feature

apple_triangl_20240101-180232_1

 The Operation Triangulation spyware attacks targeting iPhone devices since 2019 leveraged undocumented features in Apple chips to bypass hardware-based security protections.

Continue reading
  916 Hits

Barracuda fixes new ESG zero-day exploited by Chinese hackers

Barracuda_red

Network and email security firm Barracuda says it remotely patched all active Email Security Gateway (ESG) appliances on December 21 against a zero-day bug exploited by UNC4841 Chinese hackers. 

Continue reading
  800 Hits

GTA 5 source code reportedly leaked online a year after Rockstar hack

GTA_headpi_20240101-004448_1

The source code for Grand Theft Auto 5 was reportedly leaked on Christmas Eve, a little over a year after the Lapsus$ threat actors hacked Rockstar games and stole corporate data. 

Continue reading
  758 Hits

Google Chrome now scans for compromised passwords in the background

Chrome

Google says the Chrome Safety Check feature will work in the background to check if passwords saved in the web browser have been compromised. 

Continue reading
  884 Hits

Qbot malware returns in campaign targeting hospitality industry

Qbot--malware

The QakBot malware is once again being distributed in phishing campaigns after the botnet was disrupted by law enforcement over the summer. 

Continue reading
  862 Hits

3CX warns customers to disable SQL database integrations

3CX

 VoIP communications company 3CX warned customers today to disable SQL database integrations due to potential risks associated with what it describes as a potential vulnerability.

Continue reading
  848 Hits

Ransomware gang behind threats to Fred Hutch cancer patients

fred-hutch-cancer-center

The Hunters International ransomware gang claimed to be behind a cyberattack on the Fred Hutchinson Cancer Center (Fred Hutch) that resulted in patients receiving personalized extortion threats. 

Continue reading
  787 Hits

Delta Dental of California data breach exposed info of 7 million people

dentist-holding-drill

Delta Dental of California and its affiliates are warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach. 

Continue reading
  910 Hits

Kraft Heinz investigates hack claims, says systems ‘operating normally’

heinz-ketchup-russian

Kraft Heinz has confirmed that their systems are operating normally and that there is no evidence they were breached after an extortion group listed them on a data leak site. 

Continue reading
  873 Hits

New NKAbuse malware abuses NKN blockchain for stealthy comms

hacker-globe

A new Go-based multi-platform malware identified as 'NKAbuse' is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat. 

Continue reading
  802 Hits

Ubiquiti users report having access to others’ UniFi routers, cameras

Ubiquiti

Since yesterday, users of Ubiquiti networking devices, ranging from routers to security cameras, have reported seeing other people's devices and notifications through the company's UniFi cloud services. 

Continue reading
  805 Hits

Nissan is investigating cyberattack and potential data breach

Nissan-1

Japanese car maker Nissan is investigating a cyberattack that targeted its systems in Australia and New Zealand, which may have let hackers access personal information. 

Continue reading
  742 Hits

Multiple NFT collections at risk by flaw in open-source library

Thirdweb

A vulnerability in an open-source library that is common across the Web3 space impacts the security of pre-built smart contracts, affecting multiple NFT collections, including Coinbase. 

Continue reading
  968 Hits

Hackers breach US govt agencies using Adobe ColdFusion exploit

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning about hackers actively exploiting a critical vulnerability in Adobe ColdFusion identified as CVE-2023-26360 to gain initial access to government servers. 

Continue reading
  856 Hits

SpyLoan Android malware on Google Play downloaded 12 million times

Android

More than a dozen malicious loan apps, which are generically named SpyLoan, have been downloaded more than 12 million times this year from Google Play but the count is much larger since they are also available on third-party stores and suspicious websites.

 

Continue reading
  838 Hits

Over 20,000 vulnerable Microsoft Exchange servers exposed to attacks

exchange-red-white

Tens of thousands of Microsoft Exchange email servers in Europe, the U.S., and Asia exposed on the public internet are vulnerable to remote code execution flaws. 

Continue reading
  1032 Hits

US Health Dept urges hospitals to patch critical Citrix Bleed bug

Citrix_Bleed

The U.S. Department of Health and Human Services (HHS) warned hospitals this week to patch the critical 'Citrix Bleed' Netscaler vulnerability actively exploited in attacks. 

Continue reading
  862 Hits

Hackers use new Agent Raccoon malware to backdoor US targets

Raccoon-Stealer

A novel malware named 'Agent Raccoon' (or Agent Racoon) is being used in cyberattacks against organizations in the United States, the Middle East, and Africa.

Continue reading
  957 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023