Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

Ivanti fixes maximum severity RCE bug in Endpoint Management software

Ivanti

Ivanti has fixed a maximum severity vulnerability in its Endpoint Management software (EPM) that can let unauthenticated attackers gain remote code execution on the core server.

Continue reading
  2728 Hits

Progress LoadMaster vulnerable to 10/10 severity RCE flaw

Progress_headpic

Progress Software has issued an emergency fix for a maximum (10/10) severity vulnerability impacting its LoadMaster and LoadMaster Multi-Tenant (MT) Hypervisor products that allows attackers to remotely execute commands on the device.

Continue reading
  2336 Hits

New RAMBO attack steals data using RAM in air-gapped computers

Airgapped

 A novel side-channel attack dubbed "RAMBO" (Radiation of Air-gapped Memory Bus for Offense) generates electromagnetic radiation from a device's RAM to send data from air-gapped computers.

Continue reading
  2534 Hits

Car rental giant Avis discloses data breach impacting customers

AVIS

American car rental giant Avis notified customers that unknown attackers breached one of its business applications last month and stole some of their personal information.

Continue reading
  2661 Hits

Microsoft Office 2024 to disable ActiveX controls by default

Microsoft_Office

 After Office 2024 launches in October, Microsoft will disable ActiveX controls by default in Word, Excel, PowerPoint, and Visio client apps.

Continue reading
  5315 Hits

SpyAgent Android malware steals your crypto recovery phrases from images

android-eyes

A new Android malware named SpyAgent uses optical character recognition (OCR) technology to steal cryptocurrency wallet recovery phrases from screenshots stored on the mobile device.

Continue reading
  2259 Hits

SonicWall SSLVPN access control flaw is now exploited in attacks

Sonicwall

SonicWall is warning that a recently fixed access control flaw tracked as CVE-2024-40766 in SonicOS is now "potentially" exploited in attacks, urging admins to apply patches as soon as possible.

Continue reading
  2477 Hits

Apache fixes critical OFBiz remote code execution vulnerability

apache-header-image

Apache has fixed a critical security vulnerability in its open-source OFBiz (Open For Business) software, which could allow attackers to execute arbitrary code on vulnerable Linux and Windows servers.

Continue reading
  2435 Hits

LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks

back-2

Yet, another critical severity vulnerability has been discovered in LiteSpeed Cache, a caching plugin for speeding up user browsing in over 6 million WordPress sites.

Continue reading
  2223 Hits

Veeam warns of critical RCE flaw in Backup & Replication software

Veeam

Veeam has released security updates for several of its products as part of a single September 2024 security bulletin that addresses 18 high and critical severity flaws in Veeam Backup & Replication, Service Provider Console, and One.

Continue reading
  2551 Hits

Hacker trap: Fake OnlyFans tool backstabs cybercriminals, steals passwords

onlyfans-header-image

Hackers are targeting other hackers with a fake OnlyFans tool that claims to help steal accounts but instead infects threat actors with the Lumma stealer information-stealing malware.

Continue reading
  3778 Hits

Business services giant CBIZ discloses customer data breach

back

CBIZ Benefits & Insurance Services (CBIZ) has disclosed a data breach that involves unauthorized access of client information stored in specific databases.

Continue reading
  2137 Hits

Linux version of new Cicada ransomware targets VMware ESXi servers

cicada

A new ransomware-as-a-service (RaaS) operation is impersonating the legitimate Cicada 3301 organization and has already listed 19 victims on its extortion portal, as it quickly attacked companies worldwide.

Continue reading
  2775 Hits

New Voldemort malware abuses Google Sheets to store stolen data

evil_hacke_20240902-193133_1

 A new malware campaign is spreading a previously undocumented backdoor named "Voldemort" to organizations worldwide, impersonating tax agencies from the U.S., Europe, and Asia.

Continue reading
  2548 Hits

Understanding the Difference Between Cybersecurity and Cybersecurity Risk

csr

In today's digital age, the terms "cybersecurity" and "cybersecurity risk" are often used interchangeably. However, they represent different concepts that are crucial for understanding how to protect information systems effectively. Let's delve into what these terms mean and how they relate to each other. 

Continue reading
  2478 Hits

Halliburton cyberattack linked to RansomHub ransomware gang

Hallliburton

The RansomHub ransomware gang is behind the recent cyberattack on oil and gas services giant Halliburton, which disrupted the company's IT systems and business operations.

Continue reading
  2598 Hits

Fake Palo Alto GlobalProtect used as lure to backdoor enterprises

malware-phishing-header

Threat actors target Middle Eastern organizations with malware disguised as the legitimate Palo Alto GlobalProtect Tool that can steal data and execute remote PowerShell commands to infiltrate internal networks further.

Continue reading
  2369 Hits

PoorTry Windows driver evolves into a full-featured EDR wiper

hacker

The malicious PoorTry kernel-mode Windows driver used by multiple ransomware gangs to turn off Endpoint Detection and Response (EDR) solutions has evolved into an EDR wiper, deleting files crucial for the operation of security solutions and making restoration harder. 

Continue reading
  2403 Hits

DICK'S shuts down email, locks employee accounts after cyberattack

DICK-S

DICK'S Sporting Goods, the largest chain of sporting goods retail stores in the United States, disclosed that confidential information was exposed in a cyberattack detected last Wednesday.

Continue reading
  2160 Hits

Critical SonicOS Vulnerability

Threat-Advisory-Banner3

Threat update

A critical vulnerability has been identified in the SonicWall SonicOS management access. 

Continue reading
  2356 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024