Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

300,000+ Fortinet firewalls vulnerable to critical FortiOS RCE bug

Fortinet

Hundreds of thousands of FortiGate firewalls are vulnerable to a critical security issue identified as CVE-2023-27997, almost a month after Fortinet released an update that addresses the problem. 

Continue reading
  3080 Hits

Twitter's bot spam keeps getting worse — it's about porn this time

twitter-header

Forget crypto spam accounts, Twitter's got another problem which involves bots and accounts promoting adult content and infiltrating Direct Messages and interactions on the platform. And there doesn't seem to be an easy solution in sight. 

Continue reading
  3787 Hits

CISA issues DDoS warning after attacks hit multiple US orgs

0_CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today of ongoing distributed denial-of-service (DDoS) attacks after U.S. organizations across multiple industry sectors were hit. 

Continue reading
  3483 Hits

American Airlines, Southwest Airlines disclose data breaches affecting pilots

airplane

American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data breaches on Friday caused by the hack of Pilot Credentials, a third-party vendor that manages multiple airlines' pilot applications and recruitment portals.

Continue reading
  3076 Hits

Grafana warns of critical auth bypass due to Azure AD integration

header-grafan_20230625-032344_1

Grafana has released security fixes for multiple versions of its application, addressing a vulnerability that enables attackers to bypass authentication and take over any Grafana account that uses Azure Active Directory for authentication. 

Continue reading
  3094 Hits

LastPass users furious after being locked out due to MFA resets

Lastpass-headpic

LastPass password manager users have been experiencing significant login issues starting early May after being prompted to reset their authenticator apps. 

Continue reading
  2841 Hits

Microsoft Teams bug allows malware delivery from external accounts

Microsoft_Teams

Security researchers have found a simple way to deliver malware to an organization with Microsoft Teams, despite restrictions in the application for files from external sources. 

Continue reading
  3247 Hits

Over 100,000 ChatGPT Account Credentials Made Available on the Dark Web

ChatGPTCover

ChatGPT users should be wary that their personal data might've been leaked online, following the dump of more than 100,000 ChatGPT account credentials on the dark web. As reported by The Hacker News and according to Singapore-based cybersecurity company Group-IB, the credentials for users that logged into ChatGPT ranges from its launch (in June 2022) through May 2023, meaning that it's still an ongoing event. The U.S., France, Morocco, Indonesia, Pakistan, and Brazil seem to have contributed the most users towards the stolen credentials. 

Continue reading
  3120 Hits

CISA: LockBit ransomware extorted $91 million in 1,700 U.S. attacks

LockBi_20230615-213603_1

 U.S. and international cybersecurity authorities said in a joint LockBit ransomware advisory that the gang successfully extorted roughly $91 million following approximately 1,700 attacks against U.S. organizations since 2020.

Continue reading
  3118 Hits

Barracuda ESG zero-day attacks linked to suspected Chinese hackers

Barracud_20230615-215338_1

 A suspected pro-China hacker group tracked by Mandiant as UNC4841 has been linked to data-theft attacks on Barracuda ESG (Email Security Gateway) appliances using a now-patched zero-day vulnerability.

Continue reading
  3057 Hits

Russian hackers use PowerShell USB malware to drop backdoors

green-hacker-bright

The Russian state-sponsored hacking group Gamaredon (aka Armageddon or Shuckworm) continues to target critical organizations in Ukraine's military and security intelligence sectors, employing a refreshed toolset and new infection tactics. 

Continue reading
  3302 Hits

Microsoft: Windows Kernel CVE-2023-32019 fix is disabled by default

Windows-attac_20230616-032024_1

Microsoft has released an optional fix to address a Kernel information disclosure vulnerability affecting systems running multiple Windows versions, including the latest Windows 10, Windows Server, and Windows 11 releases. 

Continue reading
  3547 Hits

Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day

VMware

Initially detailed in September 2022, UNC3886 has been using malicious vSphere Installation Bundles (VIBs) – packages that are typically used to maintain systems and deploy updates – to install backdoors on ESXi hypervisors and gain command execution, file manipulation, and reverse shell capabilities.

Continue reading
  2899 Hits

Fortinet: New FortiOS RCE bug "may have been exploited" in attacks

Fortinet

Fortinet says a critical FortiOS SSL VPN vulnerability that was patched last week "may have been exploited" in attacks impacting government, manufacturing, and critical infrastructure organizations.

Continue reading
  2990 Hits

Flash loan attack on Jimbos Protocol steals over $7.5 million

Flash loan attack on Jimbos Protocol steals over $7.5 million

Jimbos Protocol, an Arbitrum-based DeFi project, has suffered a flash loan attack that resulted in the loss of more than of 4000 ETH tokens, currently valued at over $7,500,000.

Continue reading
  3001 Hits

MCNA Dental data breach impacts 8.9 million people after ransomware attack

MCNA Dental data breach impacts 8.9 million people after ransomware attack
Managed Care of North America (MCNA) Dental has published a data breach notification on its website, informing almost 9 million patients that their personal data were compromised.
Continue reading
  2991 Hits

Lazarus hackers target Windows IIS web servers for initial access

Lazarus hackers target Windows IIS web servers for initial access
The notorious North Korean state-backed hackers, known as the Lazarus Group, are now targeting vulnerable Windows Internet Information Services (IIS) web servers to gain initial access to corporate networks.
Continue reading
  3054 Hits

Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains

Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains
A new 'File Archivers in the Browser' phishing kit abuses ZIP domains by displaying fake WinRAR or Windows File Explorer windows in the browser to convince users to launch malicious files.
Continue reading
  2937 Hits

CISA warns govt agencies of recently patched Barracuda zero-day

CISA warns govt agencies of recently patched Barracuda zero-day
CISA warned of a recently patched zero-day vulnerability exploited last week to hack into Barracuda Email Security Gateway (ESG) appliances.
Continue reading
  2902 Hits

QBot malware abuses Windows WordPad EXE to infect devices

QBot malware abuses Windows WordPad EXE to infect devices
The QBot malware operation has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program to infect computers, using the legitimate program to evade detection by security software.
Continue reading
  2806 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024