The Information Highway

The Information Highway

all things technology risk and cybersecurity

News farm impersonates 60+ major outlets: BBC, CNN, CNBC, Guardian...

image

It's been discovered a content farm operating some 60+ domains named after popular media outlets, including the BBC, CNBC, CNN, Forbes, Huffington Post, Reuters, The Guardian, and Washington Post, among others.


Continue reading
  175 Hits

Golden Corral restaurant chain data breach impacts 183,000 people

Golden_Corral

The Golden Corral American restaurant chain disclosed a data breach after attackers behind an August cyberattack stole the personal information of over 180,000 people.

Continue reading
  275 Hits

CISA cautions against using hacked Ivanti VPN gateways even after factory resets

CISA-red-flare

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed today that attackers who hack Ivanti VPN appliances using one of multiple actively exploited vulnerabilities may be able to maintain root persistence even after performing factory resets.

Continue reading
  263 Hits

Malicious AI models on Hugging Face backdoor users’ machines

evil-hacker-ai

At least 100 instances of malicious AI ML models were found on the Hugging Face platform, some of which can execute code on the victim's machine, giving attackers a persistent backdoor.

Continue reading
  232 Hits

UnitedHealth confirms Optum hack behind US healthcare billing outage

healthcare-cyber

Healthcare giant UnitedHealth Group confirmed that its subsidiary Optum was forced to shut down IT systems and various services after a cyberattack by "nation-state" hackers on the Change Healthcare platform.

Continue reading
  296 Hits

U-Haul says hacker accessed customer records using stolen creds

UHau_20240225-192118_1
U-Haul has started informing customers that a hacker used stolen account credentials to access an internal system for dealers and team members to track customer reservations.
Continue reading
  244 Hits

New ScreenConnect RCE flaw exploited in ransomware attacks

LockBit_logo

The samples seen by Sophos in this week's attacks were a buhtiRansom LockBit variant dropped on 30 different customer networks and a second payload created using the leaked Lockbit builder (and dropped by a different threat actor).


Continue reading
  275 Hits

ALPHV ransomware claims loanDepot, Prudential Financial breaches

Hacker-headpic

The ALPHV/Blackcat ransomware gang has claimed responsibility for the recent network breaches of Fortune 500 company Prudential Financial and mortgage lender loanDepot.


Continue reading
  230 Hits

New ‘Gold Pickaxe’ Android, iOS malware steals your face for fraud

iphone

A new iOS and Android trojan named 'GoldPickaxe' employs a social engineering scheme to trick victims into scanning their faces and ID documents, which are believed to be used to generate deepfakes for unauthorized banking access.


Continue reading
  216 Hits

RansomHouse gang automates VMware ESXi attacks with new MrAgent tool

Linux_tux

 The RansomHouse ransomware operation has created a new tool named 'MrAgent' that automates the deployment of its data encrypter across multiple VMware ESXi hypervisors.


Continue reading
  307 Hits

New Fortinet RCE bug is actively exploited, CISA confirms

Fortinet2

CISA confirmed today that attackers are actively exploiting a critical remote code execution (RCE) bug patched by Fortinet on Thursday.


Continue reading
  481 Hits

New RustDoor macOS malware impersonates Visual Studio update

mystery-hacker

A new Rust-based macOS malware spreading as a Visual Studio update to provide backdoor access to compromised systems uses infrastructure linked to the infamous ALPHV/BlackCat ransomware gang.


Continue reading
  385 Hits

New Fortinet RCE flaw in SSL VPN likely exploited in attacks

Fortine_20240210-192609_1

Fortinet is warning that a new critical remote code execution vulnerability in FortiOS SSL VPN is potentially being exploited in attacks.


Continue reading
  362 Hits

Hyundai Motor Europe hit by Black Basta ransomware attack

hyundai-ioniq

Car maker Hyundai Motor Europe suffered a Black Basta ransomware attack, with the threat actors claiming to have stolen three terabytes of corporate data.


Continue reading
  359 Hits

Microsoft reveals how hackers breached its Exchange Online accounts

microsoft-red-header

Microsoft confirmed that the Russian Foreign Intelligence Service hacking group, which hacked into its executives' email accounts in November 2023, also breached other organizations as part of this malicious campaign.


Continue reading
  282 Hits

23andMe data breach: Hackers stole raw genotype data, health reports

23andMe

Genetic testing provider 23andMe confirmed that hackers stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27.


Continue reading
  312 Hits

Blackwood hackers hijack WPS Office update to install malware

China-hacker

A previously unknown advanced threat actor tracked as 'Blackwood' is using sophisticated malware called NSPX30 in cyberespionage attacks against companies and individuals.


Continue reading
  340 Hits

iPhone apps abuse iOS push notifications to collect user data

iphone

Numerous iOS apps are using background processes triggered by push notifications to collect user data about devices, potentially allowing the creation of fingerprinting profiles used for tracking.


Continue reading
  290 Hits

Over 5,300 GitLab servers exposed to zero-click account takeover attacks

GitLab

Over 5,300 internet-exposed GitLab instances are vulnerable to CVE-2023-7028, a zero-click account takeover flaw GitLab warned about earlier this month.


Continue reading
  301 Hits

Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024

Pwn2Own_Tokyo-headpic

Security researchers hacked a Tesla Modem and collected awards of $722,500 on the first day of Pwn2Own Automotive 2024 for three bug collisions and 24 unique zero-day exploits.


Continue reading
  319 Hits