The Information Highway

The Information Highway

all things technology risk and cybersecurity

Tech giant Nidec confirms data breach following ransomware attack

nidec

Nidec Corporation is informing that hackers behind a ransomware attack is suffered earlier this year stole data and leaked it on the dark web.

Continue reading
  215 Hits

Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass

motherboard-cpu-bios

The latest generations of Intel processors, including Xeon chips, and AMD's older microarchitectures on Linux are vulnerable to new speculative execution attacks that bypass existing 'Spectre' mitigations.

Continue reading
  265 Hits

Critical Ivanti CSA flaw actively exploited

Threat-Advisory-Banner3

Threat update

Three Ivanti Cloud Service Appliance (CSA) vulnerabilities are being exploited and weaponized in the wild. Read this Cybersecurity Threat Advisory to learn how you can mitigate your risk of being targeted.

Continue reading
  204 Hits

Windows Kernel vulnerability used in espionage campaign

Threat-Advisory-Banner3

Threat update

 Researchers have observed the well-known cyber espionage group OilRig exploiting a now-patched privilege escalation vulnerability (CVE-2024-30088) in the Windows Kernel to conduct espionage operations. Read this Cybersecurity Threat Advisory to learn more about the espionage campaign and how to avoid becoming a victim of the campaign.

Continue reading
  231 Hits

Mozilla Firefox zero-day vulnerability

Threat-Advisory-Banner3

Threat update

A Mozilla Firefox critical zero-day vulnerability, CVE-2024-9680, has emerged. This vulnerability allows an attacker to have unauthorized access and potential remote code execution on the affected OS. Continue reading this Cybersecurity Threat Advisory for recommendations to remediate this threat.

Continue reading
  178 Hits

Microsoft warns it lost some customer's security logs for a month

microsoft-red-header

Microsoft is warning enterprise customers that, for almost a month, a bug caused critical logs to be partially lost, putting at risk companies that rely on this data to detect unauthorized activity.

Continue reading
  223 Hits

EDRSilencer red team tool used in attacks to bypass security

hacker

A tool for red-team operations called EDRSilencer has been observed in malicious incidents attempting to identify security tools and mute their alerts to management consoles.

Continue reading
  271 Hits

Over 200 malicious apps on Google Play downloaded millions of times

image_2

Google Play, the official store for Android, distributed over a period of one year more than 200 malicious applications, which cumulatively counted nearly eight million downloads.

Continue reading
  231 Hits

Cisco investigates breach after stolen data for sale on hacking forum

Cisco

Cisco has confirmed that it is investigating recent claims that it suffered a breach after a threat actor began selling allegedly stolen data on a hacking forum.

Continue reading
  229 Hits

CISA: Hackers abuse F5 BIG-IP cookies to map internal servers

F5_loogo

CISA is warning that threat actors have been observed abusing unencrypted persistent F5 BIG-IP cookies to identify and target other internal devices on the targeted network.

Continue reading
  228 Hits

Casio confirms customer data stolen in a ransomware attack

Casio

Casio now confirms it suffered a ransomware attack earlier this month, warning that the personal and confidential data of employees, job candidates, and some customers was also stolen.

Continue reading
  186 Hits

Akira and Fog ransomware now exploit critical Veeam RCE flaw

Veeam

Ransomware gangs now exploit a critical security vulnerability that lets attackers gain remote code execution (RCE) on vulnerable Veeam Backup & Replication (VBR) servers.

Continue reading
  176 Hits

Fidelity Investments says data breach affects over 77,000 people

Fidelity-Investments

Fidelity Investments, a Boston-based multinational financial services company, disclosed that the personal information of over 77,000 customers was exposed after its systems were breached in August.

Continue reading
  186 Hits

CISA says critical Fortinet RCE flaw now exploited in attacks

Fortinet

Today, CISA revealed that attackers actively exploit a critical FortiOS remote code execution (RCE) vulnerability in the wild.

Continue reading
  201 Hits

Apache Avro SDK vulnerability

Threat-Advisory-Banner3

Threat update

A critical security flaw in the Apache Avro Java Software Development Kit (SDK), tracked as CVE-2024-47561, poses a significant threat to systems using this data serialization framework. A successful exploitation allows an attacker to execute arbitrary code on vulnerable instances. Continue reading this Cybersecurity Threat Advisory to learn how you can mitigate your risk.

Continue reading
  195 Hits

Highline Public Schools confirms ransomware behind shutdown

Highline-Public-Schools

On Thursday, K-12 school district Highline Public Schools confirmed that a ransomware attack forced it to shut down all schools in early September. 

Continue reading
  281 Hits

Outlast game development delayed after Red Barrels cyberattack

outlast-header

Canadian video game developer Red Barrels is warning that the development of its Outlast games will likely be delayed after the company suffered a cyberattack impacting its internal IT systems and data. 

Continue reading
  292 Hits

Recently patched CUPS flaw can be used to amplify DDoS attacks

headpic

A recently disclosed vulnerability in the Common Unix Printing System (CUPS) open-source printing system can be exploited by threat actors to launch distributed denial-of-service (DDoS) attacks with a 600x amplification factor.

Continue reading
  256 Hits

Exploited cryptojacking campaign impacting Docker

Threat-Advisory-Banner3

Threat update

 A new cryptojacking campaign exploiting the Docker Engine API has been discovered. The large-scale hacking campaign is targeting Docker Swarm, Kubernetes, and Secure Socket Shell (SSH) servers. Continue reading this Cybersecurity Threat Advisory to learn how to mitigate your risk from these vulnerabilities.

Continue reading
  201 Hits

Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks

Wasp-sting

Adobe Commerce and Magento online stores are being targeted in "CosmicSting" attacks at an alarming rate, with threat actors hacking approximately 5% of all stores.

Continue reading
  276 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023