The Information Highway

The Information Highway

all things technology risk and cybersecurity

Microsoft still unsure how hackers stole Azure AD signing key

Microsoft

Microsoft says it still doesn't know how Chinese hackers stole an inactive Microsoft account (MSA) consumer signing key used to breach the Exchange Online and Azure AD accounts of two dozen organizations, including government agencies. 

Continue reading
  1091 Hits

WordPress AIOS plugin used by 1M sites logged plaintext passwords

WordPress-headpi_20230716-190455_1

The All-In-One Security (AIOS) WordPress security plugin, used by over a million WordPress sites, was found to be logging plaintext passwords from user login attempts to the site's database, putting account security at risk. 

Continue reading
  1057 Hits

Microsoft: Chinese hackers breached US govt Exchange email accounts

man-in-hood-typing

A Chinese hacking group has breached the email accounts of more than two dozen organizations worldwide, including U.S. and Western European government agencies, according to Microsoft. 

Continue reading
  1280 Hits

Charming Kitten hackers use new ‘NokNok’ malware for macOS

Iranian-hacker

Security researchers observed a new campaign they attribute to the Charming Kitten APT group where hackers used new NokNok malware that targets macOS systems. 

Continue reading
  5820 Hits

Cisco warns of bug that lets attackers break traffic encryption

Cisco

Cisco warned customers today of a high-severity vulnerability impacting some data center switch models and allowing attackers to tamper with encrypted traffic. 

Continue reading
  1013 Hits

300,000+ Fortinet firewalls vulnerable to critical FortiOS RCE bug

Fortinet

Hundreds of thousands of FortiGate firewalls are vulnerable to a critical security issue identified as CVE-2023-27997, almost a month after Fortinet released an update that addresses the problem. 

Continue reading
  1098 Hits

Twitter's bot spam keeps getting worse — it's about porn this time

twitter-header

Forget crypto spam accounts, Twitter's got another problem which involves bots and accounts promoting adult content and infiltrating Direct Messages and interactions on the platform. And there doesn't seem to be an easy solution in sight. 

Continue reading
  1092 Hits

CISA issues DDoS warning after attacks hit multiple US orgs

0_CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today of ongoing distributed denial-of-service (DDoS) attacks after U.S. organizations across multiple industry sectors were hit. 

Continue reading
  1171 Hits

American Airlines, Southwest Airlines disclose data breaches affecting pilots

airplane

American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data breaches on Friday caused by the hack of Pilot Credentials, a third-party vendor that manages multiple airlines' pilot applications and recruitment portals.

Continue reading
  1113 Hits

Grafana warns of critical auth bypass due to Azure AD integration

header-grafan_20230625-032344_1

Grafana has released security fixes for multiple versions of its application, addressing a vulnerability that enables attackers to bypass authentication and take over any Grafana account that uses Azure Active Directory for authentication. 

Continue reading
  1057 Hits

LastPass users furious after being locked out due to MFA resets

Lastpass-headpic

LastPass password manager users have been experiencing significant login issues starting early May after being prompted to reset their authenticator apps. 

Continue reading
  919 Hits

Microsoft Teams bug allows malware delivery from external accounts

Microsoft_Teams

Security researchers have found a simple way to deliver malware to an organization with Microsoft Teams, despite restrictions in the application for files from external sources. 

Continue reading
  1125 Hits

Over 100,000 ChatGPT Account Credentials Made Available on the Dark Web

ChatGPTCover

ChatGPT users should be wary that their personal data might've been leaked online, following the dump of more than 100,000 ChatGPT account credentials on the dark web. As reported by The Hacker News and according to Singapore-based cybersecurity company Group-IB, the credentials for users that logged into ChatGPT ranges from its launch (in June 2022) through May 2023, meaning that it's still an ongoing event. The U.S., France, Morocco, Indonesia, Pakistan, and Brazil seem to have contributed the most users towards the stolen credentials. 

Continue reading
  1098 Hits

CISA: LockBit ransomware extorted $91 million in 1,700 U.S. attacks

LockBi_20230615-213603_1

 U.S. and international cybersecurity authorities said in a joint LockBit ransomware advisory that the gang successfully extorted roughly $91 million following approximately 1,700 attacks against U.S. organizations since 2020.

Continue reading
  1095 Hits

Barracuda ESG zero-day attacks linked to suspected Chinese hackers

Barracud_20230615-215338_1

 A suspected pro-China hacker group tracked by Mandiant as UNC4841 has been linked to data-theft attacks on Barracuda ESG (Email Security Gateway) appliances using a now-patched zero-day vulnerability.

Continue reading
  1130 Hits

Russian hackers use PowerShell USB malware to drop backdoors

green-hacker-bright

The Russian state-sponsored hacking group Gamaredon (aka Armageddon or Shuckworm) continues to target critical organizations in Ukraine's military and security intelligence sectors, employing a refreshed toolset and new infection tactics. 

Continue reading
  1139 Hits

Microsoft: Windows Kernel CVE-2023-32019 fix is disabled by default

Windows-attac_20230616-032024_1

Microsoft has released an optional fix to address a Kernel information disclosure vulnerability affecting systems running multiple Windows versions, including the latest Windows 10, Windows Server, and Windows 11 releases. 

Continue reading
  1228 Hits

Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day

VMware

Initially detailed in September 2022, UNC3886 has been using malicious vSphere Installation Bundles (VIBs) – packages that are typically used to maintain systems and deploy updates – to install backdoors on ESXi hypervisors and gain command execution, file manipulation, and reverse shell capabilities.

Continue reading
  1074 Hits

Fortinet: New FortiOS RCE bug "may have been exploited" in attacks

Fortinet

Fortinet says a critical FortiOS SSL VPN vulnerability that was patched last week "may have been exploited" in attacks impacting government, manufacturing, and critical infrastructure organizations.

Continue reading
  1068 Hits

Flash loan attack on Jimbos Protocol steals over $7.5 million

Flash loan attack on Jimbos Protocol steals over $7.5 million

Jimbos Protocol, an Arbitrum-based DeFi project, has suffered a flash loan attack that resulted in the loss of more than of 4000 ETH tokens, currently valued at over $7,500,000.

Continue reading
  1178 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023