Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

    An attacker used stolen passwords of staff at France’s tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France’s national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday:…

    Read More French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven WeeksContinue

  • Blog

    Russia’s Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

    Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was…

    Read More Russia’s Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver BackdoorContinue

  • Blog

    Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

    Automated certificates for everyone, built for today, and hardened for the era of quantum computing.

    Read More Cloudflare Announces Public Certificate Authority for the Post-Quantum WebContinue

  • Blog

    New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

    A group of academics from VUSec and Scuola Superiore Sant’Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR). “The key insight is…

    Read More New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing DefensesContinue

  • Blog

    ‘NeedyMantis’ Provides Long-Term Access to Compromised Networks

    Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.

    Read More ‘NeedyMantis’ Provides Long-Term Access to Compromised NetworksContinue

  • Blog

    Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

    The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers’ networks.

    Read More Dual NetScaler Zero-Days Trigger Chaos for Citrix CustomersContinue

  • Blog

    Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

    Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. “During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the…

    Read More Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary ShutdownContinue

  • Blog

    101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

    Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. “The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent,” OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko…

    Read More 101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without ConsentContinue

  • Blog

    Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

    Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. “It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,” the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual…

    Read More Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters InvestigationContinue

  • Blog

    Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

    A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK’s maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the…

    Read More Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth CredentialsContinue

Page navigation

1 2 3 … 607 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us