Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore practical insights into cybersecurity risk, from identifying threats and vulnerabilities to understanding their potential business impact. Learn how effective risk management helps organizations protect critical assets, reduce exposure, strengthen resilience, and make smarter security decisions.

Subcategories from this category:

Threat Advisory

New RomCom malware variant 'SnipBot' spotted in data theft attacks

hacker

A new variant of the RomCom malware called SnipBot, has been used in attacks that pivot on the network to steal data from compromised systems.

Continue reading
  2289 Hits

Kia dealer portal flaw could let attackers hack millions of cars

KIA

A group of security researchers discovered critical flaws in Kia's dealer portal that could let hackers locate and steal millions of Kia cars made after 2013 using just the targeted vehicle's license plate. 

Continue reading
  2345 Hits

Global infostealer malware operation targets crypto users, gamers

hacker-looking-at-screens

A massive infostealer malware operation encompassing thirty campaigns targeting a broad spectrum of demographics and system platforms has been uncovered, attributed to a cybercriminal group named "Marko Polo." 

Continue reading
  2442 Hits

SolarWinds ARM vulnerabilities

Threat-Advisory-Banner3

Threat update

SolarWinds has issued patches to address two vulnerabilities in its Access Rights Manager (ARM) software. Out of the two, one is a critical vulnerability that can lead to remote code execution (RCE).



Continue reading
  2463 Hits

Dell investigates data breach claims after hacker leaks employee info

Dell-headpic

Dell has confirmed that they are investigating recent claims that it suffered a data breach after a threat actor leaked the data for over 10,000 employees. 

Continue reading
  2376 Hits

CISA warns of actively exploited Apache HugeGraph-Server bug

apache-header-image

The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting Apache HugeGraph-Server. 

Continue reading
  2470 Hits

Ivanti warns of another critical CSA flaw exploited in attacks

ivanti-headpic

 Today, Ivanti warned that threat actors are exploiting another Cloud Services Appliance (CSA) security flaw in attacks targeting a limited number of customers.

Continue reading
  2687 Hits

FTC exposes massive surveillance of kids, teens by social media giants

FTC

 A Federal Trade Commission (FTC) staff report has found that social media and video streaming companies have been engaging in widespread user surveillance, particularly of children and teens, with insufficient privacy protections and earning billions of dollars annually by monetizing their data.

Continue reading
  2244 Hits

X hacking spree fuels "$HACKED" crypto token pump-and-dump

X-logo-flare

An X account hacking spree has fueled a successful pump-and-dump scheme for the $HACKED Solana token, with people rushing to buy the coin.

Continue reading
  2141 Hits

Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware

Hospital

 Microsoft says a ransomware affiliate it tracks as Vanilla Tempest now targets U.S. healthcare organizations in INC ransomware attacks.

Continue reading
  2608 Hits

GitLab releases fix for critical SAML authentication bypass flaw

GitLab

 GitLab has released security updates to address a critical SAML authentication bypass vulnerability impacting self-managed installations of the GitLab Community Edition (CE) and Enterprise Edition (EE).

Continue reading
  2183 Hits

FBI tells public to ignore false claims of hacked voter data

CISA

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are alerting the public of false claims that the U.S. voter registration data has been compromised in cyberattacks.

Continue reading
  2447 Hits

Malware locks browser in kiosk mode to steal Google credentials

kiosk

A malware campaign uses the unusual method of locking users in their browser's kiosk mode to annoy them into entering their Google credentials, which are then stolen by information-stealing malware.

Continue reading
  2289 Hits

Port of Seattle hit by Rhysida ransomware in August attack

Port-of-Seattle

Port of Seattle, the United States government agency overseeing Seattle's seaport and airport, confirmed on Friday that the Rhysida ransomware operation was behind a cyberattack impacting its systems over the last three weeks.

Continue reading
  2219 Hits

RansomHub claims Kawasaki cyberattack, threatens to leak stolen data

Kawasaki

Kawasaki Motors Europe has announced that its recovering from a cyberattack that caused service disruptions as the RansomHub ransomware gang threatens to leak stolen data.

Continue reading
  2720 Hits

FBI: Reported cryptocurrency losses reached $5.6 billion in 2023

FBI_cryptocurrency

The FBI says that 2023 was a record year for cryptocurrency fraud, with total losses exceeding $5.6 billion, based on nearly 70,000 reports received through the Internet Crime Complaint Center (IC3).

Continue reading
  2261 Hits

Fortinet confirms data breach after hacker claims to steal 440GB of files

Fortinet

Cybersecurity giant Fortinet has confirmed it suffered a data breach after a threat actor claimed to steal 440GB of files from the company's Microsoft SharePoint server.

Continue reading
  2500 Hits

Fake password manager coding test used to hack Python developers

developer

Members of the North Korean hacker group Lazarus posing as recruiters are baiting Python developers with coding test project for password management products that include malware.

Continue reading
  2455 Hits

Adobe fixes Acrobat Reader zero-day with public PoC exploit

adob_20240914-211645_1

A cybersecurity researcher is urging users to upgrade Adobe Acrobat Reader after a fix was released yesterday for a remote code execution zero-day with a public in-the-wild proof-of-concept exploit.

Continue reading
  3658 Hits

Veeam Backup security flaws

Threat-Advisory-Banner3

Threat update

There were recently six vulnerabilities discovered in Veeam Backup and Replication. One of them is an unauthenticated remote code execution (RCE), while the other five include authenticated RCE, arbitrary file deletion, low-privileged multi-factor authentication (MFA) setting modification and MFA bypass, credential sniffing, and privilege escalation. Review the details in this Cybersecurity Threat Advisory to limit customers' impact.

Continue reading
  2573 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024