Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. “Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences

    Read More PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command ExecutionContinue

  • Blog

    Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

    Read More Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion AttacksContinue

  • Blog

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that…

    Read More ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and MoreContinue

  • Blog

    Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

    If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How…

    Read More Your Cloud Security Checklist Doesn’t Work the Way You Think It DoesContinue

  • Blog

    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

    Read More Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected HostsContinue

  • Blog

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain…

    Read More Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit ReleasedContinue

  • Blog

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform,…

    Read More N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE FlawContinue

  • Blog

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. “The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a

    Read More JSCeal Malware Can Bypass Google Authentication Using Stolen Session CookiesContinue

  • Blog

    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count…

    Read More Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationContinue

  • Blog

    Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

    Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

    Read More Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto MinerContinue

Page navigation

1 2 3 … 583 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us