The Information Highway

The Information Highway

all things technology risk and cybersecurity

Cisco Catalyst SD-WAN Manager flaw allows remote server access

Cisco__headpic

Cisco is warning of five new Catalyst SD-WAN Manager products vulnerabilities with the most critical allowing unauthenticated remote access to the server. 

Continue reading
  942 Hits

Google fixes fifth actively exploited Chrome zero-day of 2023

Google_Chrome

Google has patched the fifth Chrome zero-day vulnerability exploited in attacks since the start of the year in emergency security updates released today. 

Continue reading
  933 Hits

New ZeroFont phishing tricks Outlook into showing fake AV-scans

Outlook_headpic_red

Hackers are utilizing a new trick of using zero-point fonts in emails to make malicious emails appear as safely scanned by security tools in Microsoft Outlook. 

Continue reading
  1047 Hits

SickKids impacted by BORN Ontario data breach that hit 3.4 million

sickkids

The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were impacted by the recent breach at BORN Ontario. 

Continue reading
  884 Hits

Fake celebrity photo leak videos flood TikTok with Temu referral codes

temu-tiktok-header

TikTok is flooded with videos promoting fake nude celebrity photo leaks used to push referral rewards for the Temu online megastore.

Continue reading
  1035 Hits

National Student Clearinghouse data breach impacts 890 schools

Hacker-books

U.S. educational nonprofit National Student Clearinghouse has disclosed a data breach affecting 890 schools using its services across the United States. 

Continue reading
  1079 Hits

TransUnion denies it was hacked, links leaked data to 3rd party

TransUnion

Credit reporting firm TransUnion has denied claims of a security breach after a threat actor known as USDoD leaked data allegedly stolen from the company's network.  The Chicago-based company's over 10,000 employees provide their services to millions of consumers and more than 65,000 businesses from 30 countries. "Immediately upon discovering ...

Continue reading
  930 Hits

BlackCat ransomware hits Azure Storage with Sphynx encryptor

BlackCat_Sphynx

The BlackCat (ALPHV) ransomware gang now uses stolen Microsoft accounts and the recently spotted Sphynx encryptor to encrypt targets' Azure cloud storage. 

Continue reading
  1200 Hits

CISA warns of critical Apache RocketMQ bug exploited in attacks

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added to its catalog of known exploited vulnerabilities (KEV) a critical–severity issue tracked as CVE-2023-33246 that affects Apache's RocketMQ distributed messaging and streaming platform. 

Continue reading
  971 Hits

Apple zero-click iMessage exploit used to infect iPhones with spyware

apple-triangle

Citizen Lab says two zero-days fixed by Apple today in emergency security updates were actively abused as part of a zero-click exploit chain (dubbed BLASTPASS) to deploy NSO Group's Pegasus commercial spyware onto fully patched iPhones. 

Continue reading
  971 Hits

Microsoft Teams phishing attack pushes DarkGate malware

Microsoft_Teams

A new phishing campaign is abusing Microsoft Teams messages to send malicious attachments that install the DarkGate Loader malware. 

Continue reading
  1475 Hits

Cisco warns of VPN zero-day exploited by ransomware gangs

Cisco_headpic

Cisco is warning of a CVE-2023-20269 zero-day vulnerability in its Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) that is actively exploited by ransomware operations to gain initial access to corporate networks. 

Continue reading
  1166 Hits

Apple discloses 2 new zero-days exploited to attack iPhones, Macs

Apple

Apple released emergency security updates to fix two new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 13 exploited zero-days patched since the start of the year. 

Continue reading
  939 Hits

Windows cryptomining attacks target graphic designer's high-powered GPUs

graphics-card

Cybercriminals are leveraging a legitimate Windows tool called 'Advanced Installer' to infect the computers of graphic designers with cryptocurrency miners. 

Continue reading
  918 Hits

Johnson & Johnson discloses IBM data breach impacting patients

server-rack

Johnson & Johnson Health Care Systems ("Janssen") has informed its CarePath customers that their sensitive information has been compromised in a third-party data breach involving IBM. 

Continue reading
  976 Hits

Obsessed with privacy? Keep Tails on a USB drive and secure most any computer

screenshot-2023-08-29-18532_20230909-192716_1

If you're looking for protection against surveillance and censorship, this Tor-based operating system is worth a try. Here's how you get started. 

Continue reading
  936 Hits

Chrome extensions can steal plaintext passwords from websites

Google___Chrome

A team of researchers from the University of Wisconsin-Madison has uploaded to the Chrome Web Store a proof-of-concept extension that can steal plaintext passwords from a website's source code 

Continue reading
  937 Hits

NIST to Standardize Encryption Algorithms That Can Resist Attack by Quantum Computers

PQC_Algo_Pre-standardization-vid

Three new algorithms are expected to be ready for use in 2024. Others will follow.

Continue reading
  996 Hits

Major U.S. energy org targeted in QR code phishing attack

phishing-hook

A phishing campaign was observed predominantly targeting a notable energy company in the US, employing QR codes to slip malicious emails into inboxes and bypass security.

Continue reading
  1125 Hits

LinkedIn accounts hacked in widespread hijacking campaign

hacker-holding-linkedin

LinkedIn is being targeted in a wave of account hacks resulting in many accounts being locked out for security reasons or ultimately hijacked by attackers. 

Continue reading
  1210 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023