The Information Highway

The Information Highway

all things technology risk and cybersecurity

Cisco discloses new IOS XE zero-day exploited to deploy malware implant

Cisco

Cisco disclosed a new high-severity zero-day (CVE-2023-20273) today, actively exploited to deploy malicious implants on IOS XE devices compromised using the CVE-2023-20198 zero-day unveiled earlier this week. 

Continue reading
  704 Hits

Okta says its support system was breached using stolen credentials

Okta

Okta says attackers accessed files containing cookies and session tokens uploaded by customers to its support management system after breaching it using stolen credentials. 

Continue reading
  544 Hits

Critical RCE flaws found in SolarWinds access audit solution

connector

Security researchers found three critical remote code execution vulnerabilities in the SolarWinds Access Rights Manager (ARM) product that remote attackers could use to run code with SYSTEM privileges. 

Continue reading
  566 Hits

Fake Corsair job offers on LinkedIn push DarkGate malware

hacker-holding-linkedin

A threat actor is using fake LinkedIn posts and direct messages about a Facebook Ads specialist position at hardware maker Corsair to lure people into downloading info-stealing malware like DarkGate and RedLine. 

Continue reading
  463 Hits

Over 40,000 Cisco IOS XE devices infected with backdoor using zero-day

Cisco-headpic

More than 40,000 Cisco devices running the IOS XE operating system have been compromised after hackers exploited a recently disclosed maximum severity vulnerability tracked as CVE-2023-20198. 

Continue reading
  477 Hits

BlackCat ransomware uses new ‘Munchkin’ Linux VM in stealthy attacks

robot-cat-datacenter

The BlackCat/ALPHV ransomware operation has begun to use a new tool named 'Munchkin' that utilizes virtual machines to deploy encryptors on network devices stealthily. 

Continue reading
  438 Hits

Fake KeePass site uses Google Ads and Punycode to push malware

malware-header

A Google Ads campaign was found pushing a fake KeePass download site that used Punycode to appear as the official domain of the KeePass password manager to distribute malware. 

Continue reading
  623 Hits

India targets Microsoft, Amazon tech support scammers in nationwide crackdown

Hacker_phone_scam

India's Central Bureau of Investigation (CBI) raided 76 locations in a nationwide crackdown on cybercrime operations behind tech support scams and cryptocurrency fraud. 

Continue reading
  473 Hits

Casio discloses data breach impacting customers in 149 countries

Casio

Japanese electronics manufacturer Casio disclosed a data breach impacting customers from 149 countries after hackers gained to the servers of its ClassPad education platform. 

Continue reading
  461 Hits

Hacker leaks millions of new 23andMe genetic data profiles

23andme-dna-burnin_20231021-202036_1

A hacker has leaked an additional 4.1 million stolen 23andMe genetic data profiles for people in Great Britain and Germany on a hacking forum. 

Continue reading
  450 Hits

MATA malware framework exploits EDR in attacks on defense firms

hacker-looking-at-screens

An updated version of the MATA backdoor framework was spotted in attacks between August 2022 and May 2023, targeting oil and gas firms and the defense industry in Eastern Europe. 

Continue reading
  494 Hits

Qubitstrike attacks rootkit Jupyter Linux servers to steal credentials

linux-security-headpic

Hackers are scanning for internet-exposed Jupyter Notebooks to breach servers and deploy a cocktail of malware consisting of a Linux rootkit, crypto miners, and password-stealing scripts. 

Continue reading
  476 Hits

DarkGate malware spreads through compromised Skype accounts

Hacker_gate

Between July and September, DarkGate malware attacks have used compromised Skype accounts to infect targets through messages containing VBA loader script attachments. 

Continue reading
  484 Hits

Apple fixes iOS Kernel zero-day vulnerability on older iPhones

apple_triangle

Apple has published security updates for older iPhones and iPads to backport patches released one week ago, addressing two zero-day vulnerabilities exploited in attacks. 

Continue reading
  522 Hits

Shadow PC warns of data breach as hacker tries to sell gamers' info

shadow

Shadow PC, a provider of high-end cloud computing services, is warning customers of a data breach that exposed customers' private information, as a threat actor claims to be selling the stolen data for over 500,000 customers. 

Continue reading
  483 Hits

New WordPress backdoor creates rogue admin to hijack websites

0_WordPres_20231014-202126_1

A new malware has been posing as a legitimate caching plugin to target WordPress sites, allowing threat actors to create an administrator account and control the site's activity. 

Continue reading
  503 Hits

Microsoft Defender now auto-isolates compromised accounts

Microsoft-Defender_for_Endpoint

Microsoft Defender for Endpoint now uses automatic attack disruption to isolate compromised user accounts and block lateral movement in hands-on-keyboard attacks with the help of a new 'contain user' capability in public preview. 

Continue reading
  492 Hits

Microsoft: State hackers exploiting Confluence zero-day since September

Atlassian_headpic

Microsoft says a Chinese-backed threat group tracked as 'Storm-0062' (aka DarkShadow or Oro0lxy) has been exploiting a critical privilege escalation zero-day in the Atlassian Confluence Data Center and Server since September 14, 2023. 

Continue reading
  480 Hits

LinkedIn Smart Links attacks return to target Microsoft accounts

hacker-holding-linkedin

Hackers are once again abusing LinkedIn Smart Links in phishing attacks to bypass protection measures and evade detection in attempts to steal Microsoft account credentials. 

Continue reading
  481 Hits

Microsoft warns of incorrect BitLocker encryption errors

Window_20231014-193248_1

Microsoft warned customers this week of incorrect BitLocker drive encryption errors being shown in some managed Windows environments. 

Continue reading
  648 Hits