Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

How to manage the security risks of generative AI tools

nudge-ai-tool_20240519-181355_1

Over the past year, we've witnessed an explosive growth spurt in consumer-focused AI productivity tools that has once again transformed the way we work. Once the realm of data science and engineering teams, generative AI was packaged and delivered to the masses in 2023.

Continue reading
  2842 Hits

Critical flaws discovered in Cacti framework

Threat-Advisory-Banner3

Threat update

This Cybersecurity Threat Advisory breaks down multiple critical vulnerabilities in the Cacti framework, an open-source network monitoring and fault management tool. Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary code and compromise network infrastructure.

Continue reading
  2722 Hits

Critical GitLab bug

Threat-Advisory-Banne2r

Threat update

 A critical vulnerability in GitLab, labeled CVE-2023-7028, is under active attack by threat actors to achieve account takeover, as reported by the Cybersecurity and Infrastructure Security Agency (CISA).

Continue reading
  2593 Hits

Apple backports fix for RTKit iOS zero-day to older iPhones

Appl_20240514-030518_1

Apple has backported security patches released in March to older iPhones and iPads, fixing an iOS Kernel zero-day tagged as exploited in attacks.

Continue reading
  2635 Hits

Hackers use DNS tunneling for network scanning, tracking victims

hacker-tunnel

Threat actors are using Domain Name System (DNS) tunneling to track when their targets open phishing emails and click on malicious links, and to scan networks for potential vulnerabilities.

Continue reading
  2761 Hits

The Post Millennial hack leaked data impacting 26 million people

hand-sifting-data

Have I Been Pwned has added the information for 26,818,266 people whose data was leaked in a recent hack of The Post Millennial conservative news website.

Continue reading
  3231 Hits

CISA: Black Basta ransomware breached over 500 orgs worldwide

CISA-red-flare

CISA and the FBI said today that Black Basta ransomware affiliates breached over 500 organizations between April 2022 and May 2024.

Continue reading
  2634 Hits

Widely used modems in industrial IoT devices open to SMS attack

world-internet-network

Security flaws in Telit Cinterion cellular modems, widely used in sectors including industrial, healthcare, and telecommunications, could allow remote attackers to execute arbitrary code via SMS.

Continue reading
  2915 Hits

Dell API abused to steal 49 million customer records in data breach

Dell-headpic

The threat actor behind the recent Dell data breach revealed they scraped information of 49 million customer records using an partner portal API they accessed as a fake company. 

Continue reading
  2761 Hits

Ohio Lottery ransomware attack impacts over 538,000 individuals

Ohio-Lottery

The Ohio Lottery is sending data breach notification letters to over 538,000 individuals affected by a cyberattack that hit the organization's systems on Christmas Eve.

Continue reading
  2472 Hits

Monday.com removes "Share Update" feature abused for phishing attacks

monday-cyber

Project management platform Monday.com has removed its "Share Update" feature after threat actors abused it in phishing attacks. 

Continue reading
  2745 Hits

RCE vulnerabilities in HPE Aruba Networking devices

Threat-Advisory-Banne2r

Threat update

HPE Aruba Networking has disclosed that critical remote code execution (RCE) vulnerabilities are impacting multiple versions of ArubaOS. Out of the ten vulnerabilities found, four pose critical risks of unauthenticated buffer overflows in various services.

Continue reading
  2525 Hits

City of Wichita shuts down IT network after ransomware attack

wichita

The City of Wichita, Kansas, disclosed it was forced to shut down portions of its network after suffering a weekend ransomware attack.

Continue reading
  2369 Hits

R Programming Vulnerability

Threat-Advisory-Banne2r

Threat update

A critical security flaw known as CVE-2024-27322 with a CVSS score of 8.8, has been discovered within the R programming language. Attackers can craft malicious RDS files or R packages that embed arbitrary R code. 

Continue reading
  2779 Hits

Android bug leaks DNS queries even when VPN kill switch is enabled

Android-lea_20240506-151316_1

A Mullvad VPN user has discovered that Android devices leak DNS queries when switching VPN servers even though the "Always-on VPN" feature was enabled with the "Block connections without VPN" option. 

Continue reading
  3256 Hits

CISA urges software devs to weed out path traversal vulnerabilities

CISA

CISA and the FBI urged software companies today to review their products and eliminate path traversal security vulnerabilities before shipping.

Continue reading
  3003 Hits

Microsoft warns of "Dirty Stream" attack impacting Android apps

Android

Microsoft has highlighted a novel attack dubbed "Dirty Stream," which could allow malicious Android apps to overwrite files in another application's home directory, potentially leading to arbitrary code execution and secrets theft.

Continue reading
  2821 Hits

Killware: The emerging cyberthreat

2024-04-27-14_21_01-Killware_-The-emerging-cyberthreat-and-5-more-pages---InPrivate---Microsoft-E

 Given the surge of incidents within the past decade, many people are becoming familiar with ransomware and data breaches. However, a new type of cyberattack known as killware has emerged in recent years. It's now a major security issue for organizations. But what does the term "killware" actually mean? Let's take a look:

Continue reading
  2703 Hits

Okta warns of "unprecedented" credential stuffing attacks on customers

Okta

Okta warns of an "unprecedented" spike in credential stuffing attacks targeting its identity and access management solutions, with some customer accounts breached in the attacks.

Continue reading
  2823 Hits

Kaiser Permanente: Data breach may impact 13.4 million patients

kaiser

Healthcare service provider Kaiser Permanente disclosed a data security incident that may impact 13.4 million people in the United States.

Continue reading
  2656 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024