Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

Cybersecurity Threat Advisory: ScreenConnect Security Alert: What Businesses Need to Know About CVE-2026-84869

Threat-Advisory-Banner3

Threat update

A newly disclosed security issue affecting ConnectWise ScreenConnect could allow files to be transferred and executed during an active remote-support session without the authorization or confirmation normally expected in certain circumstances. ConnectWise has released ScreenConnect 26.6.5 to address the vulnerability, identified as CVE-2026-84869, and recommends affected organizations update as soon as possible.  

Continue reading
  56 Hits

Cybersecurity Threat Advisory: AI-Powered Server Attacks

Threat-Advisory-Banner3

Threat update

Cybersecurity researchers have identified a threat actor that leverages artificial intelligence throughout the attack lifecycle to conduct search engine optimization (SEO) fraud, steal data, and maintain persistence in compromised environments.

Continue reading
  70 Hits

Cybersecurity Threat Advisory 31-26: SonicWall zero‑day RCE campaign

Threat-Advisory-Banner3

Threat update

Threat actors are actively targeting SonicWall SMA1000 appliances by exploiting two zero-day vulnerabilities affecting models 6210, 7210, and 8200v. 

Continue reading
  72 Hits

22,000 Exchange Servers Are Still Exposed to a Live Hijack Flaw; And the Clock Is Running Out

Microsoft_Exchange

A live, actively targetable flaw in on-premises Microsoft Exchange is sitting unpatched on roughly 22,000 servers worldwide and for many small and mid-size businesses, the safety net (extended security support) runs out next month, turning a patching task into a hard deadline.

Continue reading
  73 Hits

Urgent N-central Hotfix: What Businesses Need to Know About the September 2026 Security Update

N-able N-central Hotfix 2026.3
If your IT provider or internal technology team uses N-able N-central, there is a new security update you should know about.

N-able released N-central 2026.3 Hotfix 3 on September 5, 2026, to address two high-severity security vulnerabilities. The flaws could allow an unauthorized person to bypass authentication controls and potentially gain full access to the N-central platform.
Continue reading
  174 Hits

Cybersecurity Threat Advisory: SonicWall zero‑day RCE campaign

Threat-Advisory-Banner3

Threat update

 Threat actors are actively targeting SonicWall SMA1000 appliances by exploiting two zero-day vulnerabilities affecting models 6210, 7210, and 8200v. Review this Cybersecurity Threat Advisory to protect your systems and mitigate risk.

Continue reading
  127 Hits

Cybersecurity Threat Advisory: SynkLoader Teams phishing campaign

Threat-Advisory-Banner3

Threat update

Security researchers have identified a phishing campaign that uses Microsoft Teams messages impersonating IT support staff to distribute a newly discovered malware known as SynkLoader. Read this Cybersecurity Threat Advisory to understand the risks associated with SynkLoader, identify potential exposure, and learn the recommended steps to protect your users and systems.

Continue reading
  134 Hits

It Wasn't a “Hack” It Was a Mistake Anyone Could Make: What the Manchester Airports Breach Teaches SMBs About Vendor Risk

Airport-flight-checkin
A breach that exposed the data of 8.7 million people didn't require nation-state malware or a zero-day exploit, it exploited exposed login credentials sitting in plain view in website code, tied to a third-party marketing platform. That's not a sophisticated attack. That's a mistake almost any business could make, which is exactly why every small and mid-sized business should be paying attention.
Continue reading
  153 Hits

Cybersecurity Threat Advisory 29-26: Qilin exploits GlobalProtect flaw

Threat-Advisory-Banner3

Threat update

 An authentication bypass zero-day vulnerability, tracked as CVE-2026-20182 with a maximum CVSS score of 10.0, has been identified in Cisco Catalyst SD-WAN Controller and Manager. The vulnerability allows unauthenticated attackers to gain the highest level of administrative access to affected systems without valid credentials and is currently under active exploitation by UAT-8616, a persistent and sophisticated threat group previously linked to multiple zero-day campaigns targeting Cisco network edge technologies. Continue reading this Cybersecurity Threat Advisory to learn how to minimize your risk and protect your environment.

Continue reading
  206 Hits

Cybersecurity Threat Advisory 30-26: SonicWall SMA1000 exploits

Threat-Advisory-Banner3

Threat update

SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. 

Continue reading
  158 Hits

AI Phishing Attacks Are Changing Fast: What Businesses Need to Know in 2026

AI-phishingv2

AI phishing attacks are making familiar cyber scams faster, more convincing, and harder for employees to recognize. Recent 2026 threat intelligence shows attackers expanding beyond email into Microsoft Teams, voice calls, trusted cloud services, and highly personalized messages. For businesses, protecting Microsoft 365 identities and training employees to verify unusual requests has become increasingly important.

Continue reading
  333 Hits

QR codes bypass browser isolation for malicious C2 communication

Hacker-headpic

Mandiant has identified a novel method to bypass browser isolation technology and achieve command-and-control operations through QR codes.

Continue reading
  4579 Hits

FBI shares tips on how to tackle AI-powered fraud schemes

evil-hacker-ai

The FBI warns that scammers are increasingly using artificial intelligence to improve the quality and effectiveness of their online fraud schemes, ranging from romance and investment scams to job hiring schemes.

Continue reading
  4680 Hits

BT unit took servers offline after Black Basta ransomware breach

BT-Group

Multinational telecommunications giant BT Group (formerly British Telecom) has confirmed that its BT Conferencing business division shut down some of its servers following a Black Basta ransomware breach.

Continue reading
  4418 Hits

RomCom exploits vulnerabilities

Threat-Advisory-Banner3

Threat update

Recent reports have uncovered that a threat actor known as RomCom has been exploiting two zero-day vulnerabilities, one in Mozilla Firefox and another in Microsoft Windows, to deploy their proprietary backdoor malware. These vulnerabilities, CVE-2024-9680 and CVE-2024-49039, have been actively targeted in attacks across Europe and North America. Continue reading this Cybersecurity Threat Advisory to learn how to defend against RomCom. 

Continue reading
  2150 Hits

7-Zip vulnerability

Threat-Advisory-Banner3

Threat update

A security vulnerability in 7-Zip allows remote attackers to bypass defenses and execute malicious code via specially crafted archives. Read this Cybersecurity Threat Advisory to learn how to mitigate your risk from this new threat. 

Continue reading
  2028 Hits

Kemp LoadMaster and VMware vCenter vulnerabilities

Threat-Advisory-Banner3

Threat update

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical vulnerabilities in Progress Kemp LoadMaster (CVE-2024-1212) and VMware vCenter Server (CVE-2024-38812, CVE-2024-38813) to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities allow attackers to execute arbitrary commands, gain remote code execution (RCE), and escalate privileges. Continue reading this Cybersecurity Threat Advisory to reduce your risk of exploitation from these vulnerabilities. 

Continue reading
  2299 Hits

New malware loader – BabbleLoader

Threat-Advisory-Banner3

Threat update

BabbleLoader is a newly identified malware loader designed for delivering information-stealing payloads such as WhiteSnake and Meduza. It demonstrates sophisticated evasion techniques that challenge both traditional antivirus solutions and modern AI-driven detection systems. Read this Cybersecurity Threat Advisory to learn how to protect against this cutting-edge malware loader. 

Continue reading
  2314 Hits

Phishing campaign spreading Remcos RAT malware

Threat-Advisory-Banner3

Threat update

A new phishing campaign spreading a fileless variant of Remcos RAT malware has been discovered. Read below to learn how this could impact your organization.

Continue reading
  2574 Hits

Palo Alto PAN-OS RCE vulnerability

Threat-Advisory-Banner3

Threat update

A threat advisory was issued to Palo Alto customers notifying them of a vulnerability in the PAN-OS interface that can lead to remote code execution (RCE).

Continue reading
  2488 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024