Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

Microsoft warns it lost some customer's security logs for a month

microsoft-red-header

Microsoft is warning enterprise customers that, for almost a month, a bug caused critical logs to be partially lost, putting at risk companies that rely on this data to detect unauthorized activity.

Continue reading
  2478 Hits

EDRSilencer red team tool used in attacks to bypass security

hacker

A tool for red-team operations called EDRSilencer has been observed in malicious incidents attempting to identify security tools and mute their alerts to management consoles.

Continue reading
  2510 Hits

Over 200 malicious apps on Google Play downloaded millions of times

image_2

Google Play, the official store for Android, distributed over a period of one year more than 200 malicious applications, which cumulatively counted nearly eight million downloads.

Continue reading
  2370 Hits

Cisco investigates breach after stolen data for sale on hacking forum

Cisco

Cisco has confirmed that it is investigating recent claims that it suffered a breach after a threat actor began selling allegedly stolen data on a hacking forum.

Continue reading
  2221 Hits

CISA: Hackers abuse F5 BIG-IP cookies to map internal servers

F5_loogo

CISA is warning that threat actors have been observed abusing unencrypted persistent F5 BIG-IP cookies to identify and target other internal devices on the targeted network.

Continue reading
  2354 Hits

Casio confirms customer data stolen in a ransomware attack

Casio

Casio now confirms it suffered a ransomware attack earlier this month, warning that the personal and confidential data of employees, job candidates, and some customers was also stolen.

Continue reading
  2219 Hits

Akira and Fog ransomware now exploit critical Veeam RCE flaw

Veeam

Ransomware gangs now exploit a critical security vulnerability that lets attackers gain remote code execution (RCE) on vulnerable Veeam Backup & Replication (VBR) servers.

Continue reading
  2093 Hits

Fidelity Investments says data breach affects over 77,000 people

Fidelity-Investments

Fidelity Investments, a Boston-based multinational financial services company, disclosed that the personal information of over 77,000 customers was exposed after its systems were breached in August.

Continue reading
  2155 Hits

CISA says critical Fortinet RCE flaw now exploited in attacks

Fortinet

Today, CISA revealed that attackers actively exploit a critical FortiOS remote code execution (RCE) vulnerability in the wild.

Continue reading
  2100 Hits

Apache Avro SDK vulnerability

Threat-Advisory-Banner3

Threat update

A critical security flaw in the Apache Avro Java Software Development Kit (SDK), tracked as CVE-2024-47561, poses a significant threat to systems using this data serialization framework. A successful exploitation allows an attacker to execute arbitrary code on vulnerable instances. Continue reading this Cybersecurity Threat Advisory to learn how you can mitigate your risk.

Continue reading
  2115 Hits

Highline Public Schools confirms ransomware behind shutdown

Highline-Public-Schools

On Thursday, K-12 school district Highline Public Schools confirmed that a ransomware attack forced it to shut down all schools in early September. 

Continue reading
  2255 Hits

Outlast game development delayed after Red Barrels cyberattack

outlast-header

Canadian video game developer Red Barrels is warning that the development of its Outlast games will likely be delayed after the company suffered a cyberattack impacting its internal IT systems and data. 

Continue reading
  2779 Hits

Recently patched CUPS flaw can be used to amplify DDoS attacks

headpic

A recently disclosed vulnerability in the Common Unix Printing System (CUPS) open-source printing system can be exploited by threat actors to launch distributed denial-of-service (DDoS) attacks with a 600x amplification factor.

Continue reading
  2260 Hits

Exploited cryptojacking campaign impacting Docker

Threat-Advisory-Banner3

Threat update

 A new cryptojacking campaign exploiting the Docker Engine API has been discovered. The large-scale hacking campaign is targeting Docker Swarm, Kubernetes, and Secure Socket Shell (SSH) servers. Continue reading this Cybersecurity Threat Advisory to learn how to mitigate your risk from these vulnerabilities.

Continue reading
  2032 Hits

Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks

Wasp-sting

Adobe Commerce and Magento online stores are being targeted in "CosmicSting" attacks at an alarming rate, with threat actors hacking approximately 5% of all stores.

Continue reading
  2282 Hits

Critical RCE vulnerability in ZCS

Threat-Advisory-Banner3

Threat update

There is a critical remote code execution (RCE) vulnerability in Zimbra Collaboration Suite (ZCS) version 9.0, tracked as CVE-2024-45519. The vulnerability allows unauthenticated attackers to remotely execute arbitrary commands by exploiting weaknesses in Zimbra's SMTP PostJournal service. 

Continue reading
  2466 Hits

Fake browser updates spread updated WarmCookie malware

Cookies

 A new 'FakeUpdate' campaign targeting users in France leverages compromised websites to show fake browser and application updates that spread a new version of the WarmCookie backdoor.

Continue reading
  2751 Hits

CISA: Network switch RCE flaw impacts critical infrastructure

datacenter-switch

U.S. cybersecurity agency CISA is warning about two critical vulnerabilities that allow authentication bypass and remote code execution in Optigo Networks ONS-S8 Aggregation Switch products used in critical infrastructure.

Continue reading
  2448 Hits

Critical flaw in NVIDIA Container Toolkit allows full host takeover

0_NVIDIA_headpic

 A critical vulnerability in NVIDIA Container Toolkit impacts all AI applications in a cloud or on-premises environment that rely on it to access GPU resources.

Continue reading
  2676 Hits

Embargo ransomware escalates attacks to cloud environments

ransomware-2

Microsoft warns that ransomware threat actor Storm-0501 has recently switched tactics and now targets hybrid cloud environments, expanding its strategy to compromise all victim assets. 

Continue reading
  2056 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024