Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

Cybersecurity Threat Advisory: TrustSink Turns Microsoft Entra ID's MFA Against You to Steal Passwords

Threat-Advisory-Banner3

Threat update

Researchers have demonstrated a new attack technique called TrustSink that abuses the multi-factor authentication (MFA) features in Microsoft Entra ID, the identity service behind Microsoft 365. An attacker who gains control of a high-level admin account can quietly add a fake MFA provider to the tenant. From then on, every time a user signs in, that fake provider captures their password in plain text while the login completes normally. Organizations that use Microsoft 365 should review their Entra ID authentication settings and lock down admin accounts now.

Continue reading
  20 Hits

Critical Cisco SD-WAN Flaw Under Active Attack: What Business Owners Need to Do Now

img-cisco-sdwan
Cisco has confirmed that attackers are actively exploiting a critical vulnerability in the software many businesses use to connect their offices together. The flaw, tracked as CVE-2026-76504 and rated 9.8 out of 10 on the CVSS severity scale, affects Cisco Catalyst SD-WAN Manager. It lets a remote attacker slip past a login check and gain administrator-level access to a protected management API. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already added it to its Known Exploited Vulnerabilities (KEV) catalog and gave federal agencies until October 3, 2026 to fix it.
Continue reading
  203 Hits

Zimbra Email Servers Hacked Before the Flaw Was Even Announced: What You Need to Know

img-zimbra
A fix for a critical Zimbra email server flaw was available for more than three weeks before the public was told about it, and attackers used that time. Microsoft Threat Intelligence reports that threat actors exploited CVE-2026-73570 (CVSS 8.9), an unauthenticated operating system command injection vulnerability in the Zimbra Collaboration Suite, for weeks before it was disclosed. The Shadowserver Foundation counted 274 compromised Zimbra servers in a single recent week.
Continue reading
  139 Hits

Critical Citrix NetScaler Zero-Days Are Under Active Attack: What Your Business Needs to Do This Week

server-room-closeup-critical-error

A pair of critical, unauthenticated zero-day vulnerabilities in Citrix NetScaler are being actively exploited right now and with roughly 23,000 internet-exposed devices worldwide, this is a "patch today, not next sprint" moment that shows exactly why continuous vulnerability management can't be a once-a-quarter checkbox for any growing business.

Continue reading
  215 Hits

Cybersecurity Threat Advisory: WordPress "Click2Shell" Flaw Turns One Admin Click into Full Site Takeover

Threat-Advisory-Banner3

Threat update

A newly disclosed vulnerability in WordPress Core, nicknamed Click2Shell, allows an attacker to take control of a WordPress website if a logged-in administrator simply opens a specially crafted link. No further clicks, prompts, or approvals are needed. WordPress fixed the issue in version 7.1.1 and backported the fix to every supported branch back to 4.7. Because proof-of-concept code is now public, any organization running WordPress should confirm its sites are updated today.

Continue reading
  194 Hits

An AI Agent Hacked a Security Nonprofit Through Its Helpdesk: Lessons from the DIVD Breach

img-zammad
A cybersecurity nonprofit whose entire mission is warning others about vulnerabilities has itself been breached, and it believes an AI agent did the hacking. On September 24, 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) announced that attackers had broken into its systems. Over the following week, DIVD revealed that the attacker exploited two previously unknown vulnerabilities in Zammad, a popular open-source helpdesk and ticketing system, and stole volunteer data. Zammad has not yet released official patches.
Continue reading
  168 Hits

Cybersecurity Threat Advisory: ZcopyReaper Linux Kernel Flaw Gives Local Users Root Access, and Exploit Code Is Public

Threat-Advisory-Banner3

Threat update

A newly detailed Linux kernel vulnerability, tracked as CVE-2026-43502 and nicknamed ZcopyReaper, allows an unprivileged local user to escalate to full root control by abusing a memory-handling error in the kernel's Reliable Datagram Sockets (RDS) component. The flaw has existed since Linux kernel 4.17, working exploit code has been published, and patched kernels are available from major distributions. Organizations running Linux servers, cloud workloads, or Linux-based appliances should confirm patch status now. 

Continue reading
  266 Hits

Cybersecurity Threat Advisory: KATARU Malware Is Turning Exposed IoT Devices into Long-Term DDoS Bots

Threat-Advisory-Banner3

Threat update

A newly documented malware family named KATARU is hijacking internet-facing Linux devices, including routers and other IoT equipment, by guessing weak or default Telnet passwords. Once inside, it takes root-level control, embeds itself so it survives reboots, and enlists the device in a Mirai-style botnet used for large-scale DDoS attacks. Any organization with connected devices that are exposed to the internet, unpatched, or protected by default credentials should review its exposure now.

Continue reading
  271 Hits

Cybersecurity Threat Advisory: ScreenConnect Security Alert: What Businesses Need to Know About CVE-2026-84869

Threat-Advisory-Banner3

Threat update

A newly disclosed security issue affecting ConnectWise ScreenConnect could allow files to be transferred and executed during an active remote-support session without the authorization or confirmation normally expected in certain circumstances. ConnectWise has released ScreenConnect 26.6.5 to address the vulnerability, identified as CVE-2026-84869, and recommends affected organizations update as soon as possible.  

Continue reading
  331 Hits

Cybersecurity Threat Advisory: AI-Powered Server Attacks

Threat-Advisory-Banner3

Threat update

Cybersecurity researchers have identified a threat actor that leverages artificial intelligence throughout the attack lifecycle to conduct search engine optimization (SEO) fraud, steal data, and maintain persistence in compromised environments.

Continue reading
  230 Hits

Cybersecurity Threat Advisory 31-26: SonicWall zero‑day RCE campaign

Threat-Advisory-Banner3

Threat update

Threat actors are actively targeting SonicWall SMA1000 appliances by exploiting two zero-day vulnerabilities affecting models 6210, 7210, and 8200v. 

Continue reading
  238 Hits

22,000 Exchange Servers Are Still Exposed to a Live Hijack Flaw; And the Clock Is Running Out

Microsoft_Exchange

A live, actively targetable flaw in on-premises Microsoft Exchange is sitting unpatched on roughly 22,000 servers worldwide and for many small and mid-size businesses, the safety net (extended security support) runs out next month, turning a patching task into a hard deadline.

Continue reading
  234 Hits

Urgent N-central Hotfix: What Businesses Need to Know About the September 2026 Security Update

N-able N-central Hotfix 2026.3
If your IT provider or internal technology team uses N-able N-central, there is a new security update you should know about.

N-able released N-central 2026.3 Hotfix 3 on September 5, 2026, to address two high-severity security vulnerabilities. The flaws could allow an unauthorized person to bypass authentication controls and potentially gain full access to the N-central platform.
Continue reading
  413 Hits

Cybersecurity Threat Advisory: SonicWall zero‑day RCE campaign

Threat-Advisory-Banner3

Threat update

 Threat actors are actively targeting SonicWall SMA1000 appliances by exploiting two zero-day vulnerabilities affecting models 6210, 7210, and 8200v. Review this Cybersecurity Threat Advisory to protect your systems and mitigate risk.

Continue reading
  266 Hits

Cybersecurity Threat Advisory: SynkLoader Teams phishing campaign

Threat-Advisory-Banner3

Threat update

Security researchers have identified a phishing campaign that uses Microsoft Teams messages impersonating IT support staff to distribute a newly discovered malware known as SynkLoader. Read this Cybersecurity Threat Advisory to understand the risks associated with SynkLoader, identify potential exposure, and learn the recommended steps to protect your users and systems.

Continue reading
  282 Hits

It Wasn't a “Hack” It Was a Mistake Anyone Could Make: What the Manchester Airports Breach Teaches SMBs About Vendor Risk

Airport-flight-checkin
A breach that exposed the data of 8.7 million people didn't require nation-state malware or a zero-day exploit, it exploited exposed login credentials sitting in plain view in website code, tied to a third-party marketing platform. That's not a sophisticated attack. That's a mistake almost any business could make, which is exactly why every small and mid-sized business should be paying attention.
Continue reading
  302 Hits

Cybersecurity Threat Advisory 29-26: Qilin exploits GlobalProtect flaw

Threat-Advisory-Banner3

Threat update

 An authentication bypass zero-day vulnerability, tracked as CVE-2026-20182 with a maximum CVSS score of 10.0, has been identified in Cisco Catalyst SD-WAN Controller and Manager. The vulnerability allows unauthenticated attackers to gain the highest level of administrative access to affected systems without valid credentials and is currently under active exploitation by UAT-8616, a persistent and sophisticated threat group previously linked to multiple zero-day campaigns targeting Cisco network edge technologies. Continue reading this Cybersecurity Threat Advisory to learn how to minimize your risk and protect your environment.

Continue reading
  379 Hits

Cybersecurity Threat Advisory 30-26: SonicWall SMA1000 exploits

Threat-Advisory-Banner3

Threat update

SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. 

Continue reading
  318 Hits

AI Phishing Attacks Are Changing Fast: What Businesses Need to Know in 2026

AI-phishingv2

AI phishing attacks are making familiar cyber scams faster, more convincing, and harder for employees to recognize. Recent 2026 threat intelligence shows attackers expanding beyond email into Microsoft Teams, voice calls, trusted cloud services, and highly personalized messages. For businesses, protecting Microsoft 365 identities and training employees to verify unusual requests has become increasingly important.

Continue reading
  679 Hits

QR codes bypass browser isolation for malicious C2 communication

Hacker-headpic

Mandiant has identified a novel method to bypass browser isolation technology and achieve command-and-control operations through QR codes.

Continue reading
  4757 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024