Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. “FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding

    Read More Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike FalconContinue

  • Blog

    CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – CVE-2026-83548 (CVSS score: 10.0) – A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated

    Read More CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersContinue

  • Blog

    AI’s Vulnerability Surge May Be More Manageable Than First Feared

    New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

    Read More AI’s Vulnerability Surge May Be More Manageable Than First FearedContinue

  • Blog

    SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

    The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor’s edge devices.

    Read More SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCEContinue

  • Blog

    AI Gives Cybercriminals a Dangerous Time Advantage

    Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

    Read More AI Gives Cybercriminals a Dangerous Time AdvantageContinue

  • Blog

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. “The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that…

    Read More Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access ProgramsContinue

  • Blog

    Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users

    The “Spring Ring” operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

    Read More Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams UsersContinue

  • Blog

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. “The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft

    Read More Fake Software Installers Disable Windows Update and Weaken Microsoft DefenderContinue

  • Blog

    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication. The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation…

    Read More Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker CodeContinue

  • Blog

    Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

    A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules

    Read More Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting PagesContinue

Page navigation

1 2 3 … 580 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us