Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

Active exploitation of Microsoft vulnerabilities

Threat-Advisory-Banner3

Threat update

 This Cybersecurity Threat Advisory highlights a new attack technique exploiting vulnerabilities in Microsoft Management Console (MMC). By creating malicious management saved console (MSC) files that appear legitimate, attackers can bypass traditional security measures and exploit the targeted MMC. LBT Technology Group recommends taking immediate action to mitigate this significant security risk.

Continue reading
  2287 Hits

Facebook PrestaShop module exploited to steal credit cards

credit-cards

Hackers are exploiting a flaw in a premium Facebook module for PrestaShop named pkfacebook to deploy a card skimmer on vulnerable e-commerce sites and steal people's payment credit card details.

Continue reading
  2634 Hits

Ratel RAT targets outdated Android phones in ransomware attacks

Android

An open-source Android malware named 'Ratel RAT' is widely deployed by multiple cybercriminals to attack outdated devices, some aiming to lock them down with a ransomware module that demands payment on Telegram.

Continue reading
  2794 Hits

Los Angeles Unified confirms student data stolen in Snowflake account hack

LAUSD_headpic

The Los Angeles Unified School District has confirmed a data breach after threat actors stole student and employee data by breaching the company's Snowflake account.

Continue reading
  2390 Hits

Change Healthcare lists the medical data stolen in ransomware attack

UnitedHealth_Group_UH_20240623-203656_1

UnitedHealth has confirmed for the first time what types of medical and patient data were stolen in the massive Change Healthcare ransomware attack, stating that data breach notifications will be mailed in July.

Continue reading
  2662 Hits

CDK warns: threat actors are calling customers, posing as support

cdk-global-red-tint

CDK Global has cautioned customers about unscrupulous actors calling them and posing as CDK agents or affiliates to gain unauthorized systems access.

Continue reading
  2403 Hits

Phoenix UEFI vulnerability impacts hundreds of Intel PC models

cpu-motherboard

A newly discovered vulnerability in Phoenix SecureCore UEFI firmware tracked as CVE-2024-0762 impacts devices running numerous Intel CPUs, with Lenovo already releasing new firmware updates to resolve the flaw.

Continue reading
  2542 Hits

UNC3886 hackers use Linux rootkits to hide on VMware ESXi VMs

VMware_headpic

A suspected Chinese threat actor tracked as UNC3886 uses publicly available open-source rootkits named 'Reptile' and 'Medusa' to remain hidden on VMware ESXi virtual machines, allowing them to conduct credential theft, command execution, and lateral movement.

Continue reading
  2431 Hits

T-Mobile denies it was hacked, links leaked data to vendor breach

T-Mobile

T-Mobile has denied it was breached or that source code was stolen after a threat actor claimed to be selling stolen data from the telecommunications company.


Continue reading
  2752 Hits

New Linux malware is controlled through emojis sent from Discord

emoji-hacker

A newly discovered Linux malware dubbed 'DISGOMOJI' uses the novel approach of utilizing emojis to execute commands on infected devices in attacks on government agencies in India.

Continue reading
  2502 Hits

ASUS warns of critical remote authentication bypass on 7 routers

asus

ASUS has released a new firmware update that addresses a vulnerability impacting seven router models that allow remote attackers to log in to devices.

Continue reading
  2625 Hits

Keytronic confirms data breach after ransomware gang leaks stolen files

keytronic-header

PCBA manufacturing giant Keytronic is warning it suffered a data breach after the Black Basta ransomware gang leaked 530GB of the company's stolen data two weeks ago.

Continue reading
  2527 Hits

CISA warns of Windows bug exploited in ransomware attacks

Windows

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Windows vulnerability abused in ransomware attacks as a zero-day to its catalog of actively exploited security bugs.

Continue reading
  2768 Hits

New Microsoft Outlook client vulnerability

Threat-Advisory-Banner3

Threat update

A recent Microsoft Outlook client zero-click remote code execution (RCE) vulnerability, CVE-2024-30103, has a CVSS score of 8.8. 

Continue reading
  2939 Hits

Insurance giant Globe Life investigating web portal breach

Globe_Life

 American financial services holding company Globe Life says attackers may have accessed consumer and policyholder data after breaching one of its web portals.

Continue reading
  2534 Hits

New typosquatting attack targeting Google users

Threat-Advisory-Banner3

Threat update

Google users have been targeted with a typosquatted attack when searching Advanced IP Scanner. When searching for this free network scanner for Windows, users are served with an exploited version of Advanced IP Scanner that injects a CobaltStrike Beacon into the parent process's address space. 

Continue reading
  2522 Hits

Critical VBEM vulnerability

Threat-Advisory-Banner3

Threat update

 A Veeam Backup Enterprise Manager (VBEM) security vulnerability, CVE-2024-29849, can pose serious risks for organizations. Users are advised to update their VBEM to the latest version immediately.

Continue reading
  2720 Hits

New York Times source code stolen using exposed GitHub token

new-york-times

 Internal source code and data belonging to The New York Times was leaked on the 4chan message board after being stolen from the company's GitHub repositories in January 2024, The Times confirmed.

Continue reading
  3067 Hits

LastPass says 12-hour outage caused by bad Chrome extension update

LastPass-headpic

LastPass says its almost 12-hour outage yesterday was caused by a bad update to its Google Chrome extension.

Continue reading
  3074 Hits

Christie's starts notifying clients of RansomHub data breach

Christie-s

British auction house Christie's is notifying individuals whose data was stolen by the RansomHub ransomware gang in a recent network breach.

Continue reading
  2469 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024