Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

LastPass warns of fake support centers trying to steal customer data

LastPass-headpic

LastPass is warning about an ongoing campaign where scammers are writing reviews for its Chrome extension to promote a fake customer support phone number. However, this phone number is part of a much larger campaign to trick callers into giving scammers remote access to their computers.

Continue reading
  2285 Hits

Synology hurries out patches for zero-days exploited at Pwn2Own

Synology

Synology, a Taiwanese network-attached storage (NAS) appliance maker, patched two critical zero-days exploited during last week's Pwn2Own hacking competition within days.

Continue reading
  2090 Hits

Sophos reveals 5-year battle with Chinese hackers attacking network devices

Chinese_hackers

Sophos disclosed today a series of reports dubbed "Pacific Rim" that detail how the cybersecurity company has been sparring with Chinese threat actors for over 5 years as they increasingly targeted networking devices worldwide, including those from Sophos.

Continue reading
  2303 Hits

VMware critical vulnerability

Threat-Advisory-Banner3

Threat update

VMware has recently released software updates to address a security flaw believed to have already been patched in vCenter Server. The vulnerability, known as CVE-2024-38812 with a CVSS score of 9.8, is a heap-overflow vulnerability. Continue reading this Cybersecurity Threat Advisory to mitigate your risk.

Continue reading
  2140 Hits

SonicWall VPN vulnerability

Threat-Advisory-Banner3

Threat update

Fog and Akira ransomware operators are exploiting a critical SonicWall SSL VPN vulnerability, CVE-2024-40766, to breach corporate networks.

Continue reading
  1950 Hits

Black Basta ransomware poses as IT support on Microsoft Teams to breach networks

Microsoft_Teams

The BlackBasta ransomware operation has moved its social engineering attacks to Microsoft Teams, posing as corporate help desks contacting employees to assist them with an ongoing spam attack.

Continue reading
  4899 Hits

Amazon seizes domains used in rogue Remote Desktop campaign to steal data

Microsoft-Russia

Amazon has seized domains used by the Russian APT29 hacking group in targeted attacks against government and military organizations to steal Windows credentials and data using malicious Remote Desktop Protocol connection files.

Continue reading
  2103 Hits

QNAP, Synology, Lexmark devices hacked on Pwn2Own Day 3

pwn2own-ireland

The third day of Pwn2Own Ireland 2024 continued to showcase the expertise of white hat hackers as they exposed 11 zero-day vulnerabilities, adding $124,750 to the total prize pool, which now stands at $874,875.

Continue reading
  2428 Hits

UnitedHealth says data of 100 million stolen in Change Healthcare breach

UnitedHealth_Group_UHG

UnitedHealth has confirmed for the first time that over 100 million people had their personal information and healthcare data stolen in the Change Healthcare ransomware attack, marking this as the largest healthcare data breach in recent years.

Continue reading
  2135 Hits

Henry Schein discloses data breach a year after ransomware attack

henry-schein

Henry Schein has finally disclosed a data breach following at least two back-to-back cyberattacks in 2023 by the BlackCat Ransomware gang, revealing that over 160,000 people had their personal information stolen.

Continue reading
  2297 Hits

Insurance admin Landmark says data breach impacts 800,000 people

data-breach-header

Insurance administrative services company Landmark Admin warns that a data breach impacts over 800,000 people from a May cyberattack.

Continue reading
  2297 Hits

Mandiant says new Fortinet flaw has been exploited since June

Fortinet

A new Fortinet FortiManager flaw dubbed "FortiJump" and tracked as CVE-2024-47575 has been exploited since June 2024 in zero-day attacks on over 50 servers, according to a new report by Mandiant.

Continue reading
  2771 Hits

Over 6,000 WordPress sites hacked to install plugins pushing infostealers

back-2

WordPress sites are being hacked to install malicious plugins that display fake software updates and errors to push information-stealing malware.

Continue reading
  2371 Hits

Microsoft creates fake Azure tenants to pull phishers into honeypots

Microsoft

Microsoft is using deceptive tactics against phishing actors by spawning realistic-looking honeypot tenants with access to Azure and lure cybercriminals in to collect intelligence about them.

Continue reading
  2531 Hits

Cisco takes DevHub portal offline after hacker publishes stolen data

Cisco

Cisco confirmed today that it took its public DevHub portal offline after a threat actor leaked "non-public" data, but it continues to state that there is no evidence that its systems were breached.

Continue reading
  2448 Hits

Tech giant Nidec confirms data breach following ransomware attack

nidec

Nidec Corporation is informing that hackers behind a ransomware attack is suffered earlier this year stole data and leaked it on the dark web.

Continue reading
  2396 Hits

Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass

motherboard-cpu-bios

The latest generations of Intel processors, including Xeon chips, and AMD's older microarchitectures on Linux are vulnerable to new speculative execution attacks that bypass existing 'Spectre' mitigations.

Continue reading
  2891 Hits

Critical Ivanti CSA flaw actively exploited

Threat-Advisory-Banner3

Threat update

Three Ivanti Cloud Service Appliance (CSA) vulnerabilities are being exploited and weaponized in the wild. Read this Cybersecurity Threat Advisory to learn how you can mitigate your risk of being targeted.

Continue reading
  2315 Hits

Windows Kernel vulnerability used in espionage campaign

Threat-Advisory-Banner3

Threat update

 Researchers have observed the well-known cyber espionage group OilRig exploiting a now-patched privilege escalation vulnerability (CVE-2024-30088) in the Windows Kernel to conduct espionage operations. Read this Cybersecurity Threat Advisory to learn more about the espionage campaign and how to avoid becoming a victim of the campaign.

Continue reading
  2491 Hits

Mozilla Firefox zero-day vulnerability

Threat-Advisory-Banner3

Threat update

A Mozilla Firefox critical zero-day vulnerability, CVE-2024-9680, has emerged. This vulnerability allows an attacker to have unauthorized access and potential remote code execution on the affected OS. Continue reading this Cybersecurity Threat Advisory for recommendations to remediate this threat.

Continue reading
  1954 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024