The Information Highway

The Information Highway

all things technology risk and cybersecurity

Capital Health Hospitals hit by cyberattack causing IT outages

Capital_Health

Capital Health hospitals and physician offices across New Jersey are experiencing IT outages after a cyberattack hit the non-profit organization's network earlier this week. 

Continue reading
  983 Hits

LogoFAIL attack can install UEFI bootkits through bootup logos

logofail-red

Multiple security vulnerabilities collectively named LogoFAIL affect image-parsing components in the UEFI code from various vendors. Researchers warn that they could be exploited to hijack the execution flow of the booting process and to deliver bootkits. 

Continue reading
  891 Hits

Zyxel warns of multiple critical vulnerabilities in NAS devices

zyxel-header-image

Zyxel has addressed multiple security issues, including three critical ones that could allow an unauthenticated attacker to execute operating system commands on vulnerable network-attached storage (NAS) devices. 

Continue reading
  890 Hits

Dollar Tree hit by third-party data breach impacting 2 million people

dollar-tree

Discount store chain Dollar Tree was impacted by a third-party data breach affecting 1,977,486 people after the hack of service provider Zeroed-In Technologies. 

Continue reading
  1035 Hits

Hackers breach US water facility via exposed Unitronics PLCs

Water_treatment_US

CISA (Cybersecurity & Infrastructure Security Agency) is warning that threat actors breached a U.S. water facility by hacking into Unitronics programmable logic controllers (PLCs) exposed online. 

Continue reading
  950 Hits

New BLUFFS attack lets attackers hijack Bluetooth connections

Bluetooth_bluescreen_BSOD

 Researchers at Eurecom have developed six new attacks collectively named 'BLUFFS' that can break the secrecy of Bluetooth sessions, allowing for device impersonation and man-in-the-middle (MitM) attacks.

Continue reading
  803 Hits

Google Chrome emergency update fixes 6th zero-day exploited in 2023

Google_Chrome

Google has fixed the sixth Chrome zero-day vulnerability this year in an emergency security update released today to counter ongoing exploitation in attacks. 

Continue reading
  777 Hits

Qilin ransomware claims attack on automotive giant Yanfeng

0_dodge

The Qilin ransomware group has claimed responsibility for a cyber attack on Yanfeng Automotive Interiors (Yanfeng), one of the world's largest automotive parts suppliers. 

Continue reading
  976 Hits

Critical bug in ownCloud file sharing app exposes admin passwords

Cloud

Open source file sharing software ownCloud is warning of three critical-severity security vulnerabilities, including one that can expose administrator passwords and mail server credentials. 

Continue reading
  961 Hits

Cyberattack on IT provider CTS impacts dozens of UK law firms

CTS

A cyberattack on CTS, a leading managed service provider (MSP) for law firms and other organizations in the UK legal sector, is behind a major outage impacting numerous law firms and home buyers in the country since Wednesday. 

Continue reading
  977 Hits

Windows Hello auth bypassed on Microsoft, Dell, Lenovo laptops

Laptop_finger_print

Security researchers bypassed Windows Hello fingerprint authentication on Dell Inspiron, Lenovo ThinkPad, and Microsoft Surface Pro X laptops in attacks exploiting security flaws found in the embedded fingerprint sensors. 

Continue reading
  947 Hits

Welltok data breach exposes data of 8.5 million US patients

data-breach-header

Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. 

Continue reading
  1137 Hits

New botnet malware exploits two zero-days to infect NVRs and routers

Botnet

A new Mirai-based malware botnet named 'InfectedSlurs' has been exploiting two zero-day remote code execution (RCE) vulnerabilities to infect routers and video recorder (NVR) devices. 

Continue reading
  1059 Hits

Hacktivists breach U.S. nuclear research lab, steal employee data

INL

The Idaho National Laboratory (INL) confirms they suffered a cyberattack after 'SiegedSec' hacktivists leaked stolen human resources data online. 

Continue reading
  919 Hits

Microsoft launches Defender Bounty Program with $20,000 rewards

Microsoft_headpic

Microsoft has unveiled a new bug bounty program aimed at the Microsoft Defender security platform, with rewards between $500 and $20,000. 

Continue reading
  801 Hits

Auto parts giant AutoZone warns of MOVEit data breach

autozone

AutoZone is warning tens of thousands of its customers that it suffered a data breach as part of the Clop MOVEit file transfer attacks. 

Continue reading
  827 Hits

Citrix warns admins to kill NetScaler user sessions to block hackers

citrix-bleed

Citrix reminded admins today that they must take additional measures after patching their NetScaler appliances against the CVE-2023-4966 'Citrix Bleed' vulnerability to secure vulnerable devices against attacks. 

Continue reading
  788 Hits

DarkGate and Pikabot malware emerge as Qakbot’s successors

Hacker_red_map

A sophisticated phishing campaign pushing the DarkGate malware infections has recently added the PikaBot malware into the mix, making it the most advanced phishing campaign since the Qakbot operation was dismantled. 

Continue reading
  1061 Hits

Kinsing malware exploits Apache ActiveMQ RCE to plant rootkits

apache-header-image

The Kinsing malware operator is actively exploiting the CVE-2023-46604 critical vulnerability in the Apache ActiveMQ open-source message broker to compromise Linux systems. 

Continue reading
  1021 Hits

Lumma Stealer malware now uses trigonometry to evade detection

Hacker_headpic

The Lumma information-stealing malware is now using an interesting tactic to evade detection by security software - the measuring of mouse movements using trigonometry to determine if the malware is running on a real machine or an antivirus sandbox. 

Continue reading
  714 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023