Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

New BitForge cryptocurrency wallet flaws lets hackers steal crypto

bitcoin-blockchain

 Multiple zero-day vulnerabilities named 'BitForge' in the implementation of widely used cryptographic protocols like GG-18, GG-20, and Lindell 17 affected popular cryptocurrency wallet providers, including Coinbase, ZenGo, Binance, and many more.

Continue reading
  3904 Hits

AI Swipes Data By Listening to Keyboard Keystrokes with 95% Accuracy

GFz7Cb2gFsTPdcus5KvAaJ-1200-80.jpg

A team of researchers from Cornell, specifically Joshua Harrison, Ehsan Toreini and Maryam Mehrnezhad, have published a paper detailing their work in training AI to interpret keyboard input from audio alone. By recording keystrokes to train the model, they were able to predict what was typed on the keyboard with up to 95% accuracy. This accuracy only dropped to 93% when using Zoom to train the system. 

Continue reading
  3192 Hits

FBI warns of scammers posing as NFT devs to steal your crypto

FBI_headpic

The FBI warned today of fraudsters posing as Non-Fungible Token (NFT) developers to prey upon NFT enthusiasts and steal their cryptocurrency and NFT assets. 

Continue reading
  2927 Hits

New Microsoft Azure AD CTS feature can be abused for lateral movement

microsoft-azure-headpic

Microsoft's new Azure Active Directory Cross-Tenant Synchronization (CTS) feature, introduced in June 2023, has created a new potential attack surface that might allow threat actors to more easily spread laterally to other Azure tenants. Microsoft tenants are client organizations or sub-organizations in Azure Active Directory that are configured wi...

Continue reading
  3756 Hits

FBI, CISA, and NSA reveal top exploited vulnerabilities of 2022

Globe_map

In collaboration with CISA, the NSA, and the FBI, Five Eyes cybersecurity authorities have issued today a list of the 12 most exploited vulnerabilities throughout 2022.

Continue reading
  3105 Hits

Russian hackers target govt orgs in Microsoft Teams phishing attacks

Russia__bear

 Microsoft says a hacking group tracked as APT29 and linked to Russia's Foreign Intelligence Service (SVR) targeted dozens of organizations worldwide, including government agencies, in Microsoft Teams phishing attacks.

Continue reading
  2946 Hits

Over 640 Citrix servers backdoored with web shells in ongoing attacks

citrix

Hundreds of Citrix Netscaler ADC and Gateway servers have already been breached and backdoored in a series of attacks targeting a critical remote code execution (RCE) vulnerability tracked as CVE-2023-3519. 

Continue reading
  3692 Hits

Amazon's AWS SSM agent can be used as post-exploitation RAT malware

hacker-looking-at-screens

Researchers have discovered a new post-exploitation technique in Amazon Web Services (AWS) that allows hackers to use the platform's System Manager (SSM) agent as an undetectable Remote Access Trojan (RAT). 

Continue reading
  3389 Hits

Hackers exploited Salesforce zero-day in Facebook phishing attack

salesforce

Hackers exploited a zero-day vulnerability in Salesforce's email services and SMTP servers to launch a sophisticated phishing campaign targeting valuable Facebook accounts.

Continue reading
  3325 Hits

Retail chain Hot Topic discloses wave of credential-stuffing attacks

data-theft

American apparel retailer Hot Topic is notifying customers about multiple cyberattacks between February 7 and June 21 that resulted in exposing sensitive information to hackers. 

Continue reading
  4097 Hits

Cybercriminals train AI chatbots for phishing, malware attacks

ai-cybersecurity-hacker

In the wake of WormGPT, a ChatGPT clone trained on malware-focused data, a new generative artificial intelligence hacking tool called FraudGPT has emerged, and at least another one is under development that is allegedly based on Google's AI experiment, Bard. 

Continue reading
  3051 Hits

Hackers steal Signal, WhatsApp user data with fake Android chat app

Android_malware

Hackers are using a fake Android app named 'SafeChat' to infect devices with spyware malware that steals call logs, texts, and GPS locations from phones. 

Continue reading
  3424 Hits

WordPress Ninja Forms plugin flaw lets hackers steal submitted data

ninja-b_20230728-001805_1

Popular WordPress form-building plugin Ninja Forms contains three vulnerabilities that could allow attackers to achieve privilege escalation and steal user data.

Continue reading
  2927 Hits

Lazarus hackers linked to $60 million Alphapo cryptocurrency heist

cryptocurrency-assorted

Blockchain analysts blame the North Korean Lazarus hacking group for a recent attack on payment processing platform Alphapo where the attackers stole almost $60 million in crypto. 

Continue reading
  3179 Hits

SEC now requires companies to disclose cyberattacks in 4 days

USA_SEC

 The U.S. Securities and Exchange Commission has adopted new rules requiring publicly traded companies to disclose cyberattacks within four business days after determining they're material incidents.

Continue reading
  2904 Hits

Microsoft still unsure how hackers stole Azure AD signing key

Microsoft

Microsoft says it still doesn't know how Chinese hackers stole an inactive Microsoft account (MSA) consumer signing key used to breach the Exchange Online and Azure AD accounts of two dozen organizations, including government agencies. 

Continue reading
  3074 Hits

WordPress AIOS plugin used by 1M sites logged plaintext passwords

WordPress-headpi_20230716-190455_1

The All-In-One Security (AIOS) WordPress security plugin, used by over a million WordPress sites, was found to be logging plaintext passwords from user login attempts to the site's database, putting account security at risk. 

Continue reading
  3043 Hits

Microsoft: Chinese hackers breached US govt Exchange email accounts

man-in-hood-typing

A Chinese hacking group has breached the email accounts of more than two dozen organizations worldwide, including U.S. and Western European government agencies, according to Microsoft. 

Continue reading
  3471 Hits

Charming Kitten hackers use new ‘NokNok’ malware for macOS

Iranian-hacker

Security researchers observed a new campaign they attribute to the Charming Kitten APT group where hackers used new NokNok malware that targets macOS systems. 

Continue reading
  7945 Hits

Cisco warns of bug that lets attackers break traffic encryption

Cisco

Cisco warned customers today of a high-severity vulnerability impacting some data center switch models and allowing attackers to tamper with encrypted traffic. 

Continue reading
  2994 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024