Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

    Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway’s administrator credential. Anyone who holds it…

    Read More Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin KeyContinue

  • Blog

    Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

    Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an…

    Read More Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6Continue

  • Blog

    EU Cyber Resilience Act to Enforce New Reporting Requirements

    Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.

    Read More EU Cyber Resilience Act to Enforce New Reporting RequirementsContinue

  • Blog

    Orkes Conductor Evaluator Remote Code Execution

    What is the Vulnerability? Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments. In the last 24 hours, FortiGuard IPS blocked 1,290 attack attempts, representing a 132% increase in daily…

    Read More Orkes Conductor Evaluator Remote Code ExecutionContinue

  • Blog

    Mythos Vulnerability Firehose Hits a Human Bottleneck

    An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.

    Read More Mythos Vulnerability Firehose Hits a Human BottleneckContinue

  • Blog

    US Government Accuses Chinese AI Firms of Distilling Frontier Models

    US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX’s Grok to reduce development costs.

    Read More US Government Accuses Chinese AI Firms of Distilling Frontier ModelsContinue

  • Blog

    U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

    The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese…

    Read More U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in CryptoContinue

  • Blog

    Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

    Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

    Read More Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a WeekContinue

  • Blog

    Identity-Based AI Attack Threatens Security of Enterprise Data

    “Workflow identity hijacking” can bypass standard security controls and hijack an organization’s data by sending a basic request through an unauthenticated entry point.

    Read More Identity-Based AI Attack Threatens Security of Enterprise DataContinue

  • Blog

    Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

    Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens,…

    Read More Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFAContinue

Page navigation

1 2 3 … 587 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us