Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

    The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet

    Read More BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware DeliveryContinue

  • Blog

    Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

    Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

    Read More Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerContinue

  • Blog

    Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII

    A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser.

    Read More Vatican’s Official Prayer App Leaks 700K+ Global Users’ PIIContinue

  • Blog

    Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

    Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant’s identity and access other tenants’ data, credentials, and cloud workloads.

    Read More Default Azure Automation Setting Enables Cross-Tenant Identity TakeoverContinue

  • Blog

    ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

    Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of…

    Read More ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkContinue

  • Blog

    Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

    A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITYSYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing’s image tier, not on one bad…

    Read More Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s ServersContinue

  • Blog

    Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

    AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we’ve collectively landed is…

    Read More Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can DoContinue

  • Blog

    Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

    Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection. The agent then worked through the ministry’s network on its own, checking hosts for ways to…

    Read More Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance MinistryContinue

  • Blog

    Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

    The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential

    Read More Golden Chickens Resurfaces With Four New Malware Families and Modular ImplantsContinue

  • Blog

    NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

    Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators…

    Read More NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private ChatsContinue

Page navigation

1 2 3 … 537 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us