Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    ‘Lorem Ipsum’ Malware Pivots to ClickFix Delivery

    New analysis shows the campaign, which uses compromised WordPress sites, may be linked to the ransomware and data extortion group Vice Society.

    Read More ‘Lorem Ipsum’ Malware Pivots to ClickFix DeliveryContinue

  • Blog

    New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

    Security researchers atĀ Zimperium’s zLabsĀ have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts lock-screen PINs, reads and sends SMS, rewrites the clipboard to redirect crypto payments, and switches off Google Play

    Read More New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet FundsContinue

  • Blog

    Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive

    Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms. Yet despite this abundance of information, many organizations continue to face a fundamental challenge: sifting through the noise to understand who is…

    Read More Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still ReactiveContinue

  • Blog

    Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

    Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that…

    Read More Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last WeekContinue

  • Blog

    China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

    Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. “The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS,” ESET said in a report shared with The Hacker News. “Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP,

    Read More China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based StealthContinue

  • Blog

    Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

    The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. “The attack email contained a message impersonating an MS account security alert,” the Genians Security Center (GSC) said. “It was designed to create concern over possible

    Read More Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT MalwareContinue

  • Blog

    Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

    Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. “A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,…

    Read More Cisco Releases Security Updates for Actively Exploited SD-WAN Manager FlawContinue

  • Blog

    CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case…

    Read More CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationContinue

  • Blog

    Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

    A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the unusual part: the attackers rewired the victims’ own Google Workspace…

    Read More Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense EmailsContinue

  • Blog

    North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

    Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes

    Read More North Korean Hackers Are Turning Developer Tools Into Malware Delivery ChannelsContinue

Page navigation

1 2 3 … 494 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us