Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had…

    Read More Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant BackdoorsContinue

  • Blog

    China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

    A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything…

    Read More China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT BackdoorContinue

  • Blog

    PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

    PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. “These are Regular Maintenance Releases (MR)…

    Read More PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited FlawsContinue

  • Blog

    Indonesia Hit by Android Banking App-Cloning Campaign

    The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

    Read More Indonesia Hit by Android Banking App-Cloning CampaignContinue

  • Blog

    Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

    Threat actors are leveraging Microsoft’s Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.

    Read More Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate DataContinue

  • Blog

    ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right…

    Read More ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More StoriesContinue

  • Blog

    Nightmare-Eclipse Strikes Again with ‘ShieldCrash’ Windows Exploit

    The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.

    Read More Nightmare-Eclipse Strikes Again with ‘ShieldCrash’ Windows ExploitContinue

  • Blog

    Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven’t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications…

    Read More Google Play Early Access Abused to Push Thousands of Deceptive Android AppsContinue

  • Blog

    Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

    Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it has not described. One flaw affects Check Point’s Security Gateways, its firewall appliances. The other affects those…

    Read More Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCEContinue

  • Blog

    PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

    A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from “45.142.193[.]132,” an IP address that has been…

    Read More PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ InstancesContinue

Page navigation

1 2 3 … 588 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us