The Information Highway

The Information Highway

all things technology risk and cybersecurity

Critical RCE vulnerability in ZCS

Threat-Advisory-Banner3

Threat update

There is a critical remote code execution (RCE) vulnerability in Zimbra Collaboration Suite (ZCS) version 9.0, tracked as CVE-2024-45519. The vulnerability allows unauthenticated attackers to remotely execute arbitrary commands by exploiting weaknesses in Zimbra's SMTP PostJournal service. 

Continue reading
  252 Hits

Fake browser updates spread updated WarmCookie malware

Cookies

 A new 'FakeUpdate' campaign targeting users in France leverages compromised websites to show fake browser and application updates that spread a new version of the WarmCookie backdoor.

Continue reading
  303 Hits

CISA: Network switch RCE flaw impacts critical infrastructure

datacenter-switch

U.S. cybersecurity agency CISA is warning about two critical vulnerabilities that allow authentication bypass and remote code execution in Optigo Networks ONS-S8 Aggregation Switch products used in critical infrastructure.

Continue reading
  286 Hits

Critical flaw in NVIDIA Container Toolkit allows full host takeover

0_NVIDIA_headpic

 A critical vulnerability in NVIDIA Container Toolkit impacts all AI applications in a cloud or on-premises environment that rely on it to access GPU resources.

Continue reading
  355 Hits

Embargo ransomware escalates attacks to cloud environments

ransomware-2

Microsoft warns that ransomware threat actor Storm-0501 has recently switched tactics and now targets hybrid cloud environments, expanding its strategy to compromise all victim assets. 

Continue reading
  228 Hits

New RomCom malware variant 'SnipBot' spotted in data theft attacks

hacker

A new variant of the RomCom malware called SnipBot, has been used in attacks that pivot on the network to steal data from compromised systems.

Continue reading
  296 Hits

Kia dealer portal flaw could let attackers hack millions of cars

KIA

A group of security researchers discovered critical flaws in Kia's dealer portal that could let hackers locate and steal millions of Kia cars made after 2013 using just the targeted vehicle's license plate. 

Continue reading
  276 Hits

Global infostealer malware operation targets crypto users, gamers

hacker-looking-at-screens

A massive infostealer malware operation encompassing thirty campaigns targeting a broad spectrum of demographics and system platforms has been uncovered, attributed to a cybercriminal group named "Marko Polo." 

Continue reading
  323 Hits

SolarWinds ARM vulnerabilities

Threat-Advisory-Banner3

Threat update

SolarWinds has issued patches to address two vulnerabilities in its Access Rights Manager (ARM) software. Out of the two, one is a critical vulnerability that can lead to remote code execution (RCE).



Continue reading
  363 Hits

Dell investigates data breach claims after hacker leaks employee info

Dell-headpic

Dell has confirmed that they are investigating recent claims that it suffered a data breach after a threat actor leaked the data for over 10,000 employees. 

Continue reading
  362 Hits

CISA warns of actively exploited Apache HugeGraph-Server bug

apache-header-image

The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting Apache HugeGraph-Server. 

Continue reading
  313 Hits

Ivanti warns of another critical CSA flaw exploited in attacks

ivanti-headpic

 Today, Ivanti warned that threat actors are exploiting another Cloud Services Appliance (CSA) security flaw in attacks targeting a limited number of customers.

Continue reading
  287 Hits

FTC exposes massive surveillance of kids, teens by social media giants

FTC

 A Federal Trade Commission (FTC) staff report has found that social media and video streaming companies have been engaging in widespread user surveillance, particularly of children and teens, with insufficient privacy protections and earning billions of dollars annually by monetizing their data.

Continue reading
  246 Hits

X hacking spree fuels "$HACKED" crypto token pump-and-dump

X-logo-flare

An X account hacking spree has fueled a successful pump-and-dump scheme for the $HACKED Solana token, with people rushing to buy the coin.

Continue reading
  251 Hits

Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware

Hospital

 Microsoft says a ransomware affiliate it tracks as Vanilla Tempest now targets U.S. healthcare organizations in INC ransomware attacks.

Continue reading
  367 Hits

GitLab releases fix for critical SAML authentication bypass flaw

GitLab

 GitLab has released security updates to address a critical SAML authentication bypass vulnerability impacting self-managed installations of the GitLab Community Edition (CE) and Enterprise Edition (EE).

Continue reading
  238 Hits

FBI tells public to ignore false claims of hacked voter data

CISA

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are alerting the public of false claims that the U.S. voter registration data has been compromised in cyberattacks.

Continue reading
  380 Hits

Malware locks browser in kiosk mode to steal Google credentials

kiosk

A malware campaign uses the unusual method of locking users in their browser's kiosk mode to annoy them into entering their Google credentials, which are then stolen by information-stealing malware.

Continue reading
  347 Hits

Port of Seattle hit by Rhysida ransomware in August attack

Port-of-Seattle

Port of Seattle, the United States government agency overseeing Seattle's seaport and airport, confirmed on Friday that the Rhysida ransomware operation was behind a cyberattack impacting its systems over the last three weeks.

Continue reading
  294 Hits

RansomHub claims Kawasaki cyberattack, threatens to leak stolen data

Kawasaki

Kawasaki Motors Europe has announced that its recovering from a cyberattack that caused service disruptions as the RansomHub ransomware gang threatens to leak stolen data.

Continue reading
  262 Hits

Top Breaches Of 2023

Customers Affected In T-Mobile Breach
Accounts Affected In MOVEit Breach
Customers Affected In MCNA Insurance Data Breach
Individuals Affected In PharMerica Data Breach
Users Affected In ChatGPT Major Data Breach
*Founder Shield End of Year 2023