Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug

    Microsoft has released out-of-band updates to address a security vulnerability in ASP.NET Core that could allow an attacker to escalate privileges. The vulnerability, tracked as CVE-2026-40372, carries a CVSS score of 9.1 out of 10.0. It’s rated Important in severity. An anonymous researcher has been credited with discovering and reporting the flaw. “Improper verification of…

    Read More Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation BugContinue

  • Blog

    Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles

    Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE that’s distributed via a theme related to India’s banking sector. “The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and supports remote shell access, file operations, and session management, indicating a continued espionage-focused capability set rather than

    Read More Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy CirclesContinue

  • Blog

    Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape

    A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-5752, is rated 9.3 on the CVSS scoring system. “Sandbox escape vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal,” according…

    Read More Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container EscapeContinue

  • Blog

    Ransomware Negotiator Pleads Guilty to BlackCat Scheme

    A cautionary tale illustrates why the person negotiating should never be involved with any part of the ransom payment process, experts noted.

    Read More Ransomware Negotiator Pleads Guilty to BlackCat SchemeContinue

  • Blog

    Exploits Turn Windows Defender into Attacker Tool

    Three proof-of-concept exploits are being used in active attacks against Microsoft’s built-in security platform; two are unpatched.

    Read More Exploits Turn Windows Defender into Attacker ToolContinue

  • Blog

    SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation

    Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy malware called SystemBC. According to new research published by Check Point, the command-and-control (C2 or C&C) server linked to SystemBC has led to the discovery of a botnet of more than 1,570 victims. “SystemBC establishes SOCKS5 network…

    Read More SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware OperationContinue

  • Blog

    22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP Converters

    Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex that could be exploited to hijack susceptible devices and tamper with data exchanged by them. The vulnerabilities have been collectively codenamed BRIDGE:BREAK by Forescout Research Vedere Labs, which identified nearly 20,000 Serial-to-Ethernet converters exposed

    Read More 22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP ConvertersContinue

  • Blog

    Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk

    The critical remote code execution flaw (CVE-2026-1731) in the remote monitoring and management tool can be exploited to spread ransomware and compromise supply chains.

    Read More Surge in Bomgar RMM Exploitation Demonstrates Supply Chain RiskContinue

  • Blog

    Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023

    A third individual who was employed as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Angelo Martino, 41, of Land O’Lakes, Florida, teamed up with the operators of the BlackCat ransomware starting in April 2023 to assist the e-crime gang in extracting higher amounts as ransoms. “Working as…

    Read More Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023Continue

  • Blog

    5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time

    Security teams often present MTTR as an internal KPI. Leadership sees it differently: every hour a threat dwells inside the environment is an hour of potential data exfiltration, service disruption, regulatory exposure, and brand damage.  The root cause of slow MTTR is almost never “not enough analysts.” It is almost always the same structural problem:…

    Read More 5 Places where Mature SOCs Keep MTTR Fast and Others Waste TimeContinue

Page navigation

1 2 3 … 445 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us