Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

    Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and

    Read More Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain AttacksContinue

  • Blog

    Apple’s MacOS Gap Lets Users Disable Security Tools

    Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.

    Read More Apple’s MacOS Gap Lets Users Disable Security ToolsContinue

  • Blog

    Dawn of the Apex Agentic Adversary

    We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, a fix was deployed. In…

    Read More Dawn of the Apex Agentic AdversaryContinue

  • Blog

    DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering

    The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entities linked to Prince Group. “These subsidiaries are alleged to have assisted individuals and organizations in transferring…

    Read More DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money LaunderingContinue

  • Blog

    Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

    Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote

    Read More Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to RootContinue

  • Blog

    Scope of Salesforce Attacks Expands as Icarus Leaks Data

    More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers’ Salesforce data.

    Read More Scope of Salesforce Attacks Expands as Icarus Leaks DataContinue

  • Blog

    ‘Cordyceps’: Mushrooming Malicious Pull Requests Threaten Developer Workflows

    The CI/CD workflow weakness affects Microsoft’s Azure Sentinel, Google’s AI Agent Development Kit, Apache’s Doris analytics database, Cloudflare’s Workers SDK, and Python Software Foundation’s Black.

    Read More ‘Cordyceps’: Mushrooming Malicious Pull Requests Threaten Developer WorkflowsContinue

  • Blog

    FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

    A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke

    Read More FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting OperationContinue

  • Blog

    Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

    Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user’s email address and…

    Read More Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 AgentsContinue

  • Blog

    Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration

    President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography. Key establishment must move by December 31, 2030; digital signatures by December 31, 2031. EO 14409 leaves national security systems on a separate track. The deadlines matter because of a threat that…

    Read More Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto MigrationContinue

Page navigation

1 2 3 … 501 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us