Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

    Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.

    Read More Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear AgencyContinue

  • Blog

    Attackers Pounce on Critical Artifactory Flaw Following Disclosure

    CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems.

    Read More Attackers Pounce on Critical Artifactory Flaw Following DisclosureContinue

  • Blog

    Stronger Security Drives Ransomware Groups to Recruit From Within

    Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.

    Read More Stronger Security Drives Ransomware Groups to Recruit From WithinContinue

  • Blog

    Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

    The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

    Read More Critical Langflow Flaw Exploited as Attacks on AI Platform RiseContinue

  • Blog

    Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

    Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. “JFrog Artifactory contains an authentication weakness that, under default

    Read More Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureContinue

  • Blog

    Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

    Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as “specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.” The adversary

    Read More Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment SystemsContinue

  • Blog

    13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

    Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. “The injected code runs two operations against a site’s visitors: a mobile ad-fraud…

    Read More 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet SeedsContinue

  • Blog

    ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

    The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

    Read More ClickFix Campaign Compromises 31 Orgs, Abuses Polygon BlockchainContinue

  • Blog

    Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

    The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the

    Read More Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding TestsContinue

  • Blog

    Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

    The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix,…

    Read More Threat Actors Don’t Want Better Attacks. They Want Repeatable OnesContinue

Page navigation

1 2 3 … 578 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us