Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

    Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing…

    Read More Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command ExecutionContinue

  • Blog

    China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. “The

    Read More China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEContinue

  • Blog

    ‘Sandworm’ Chains Cisco Vulnerabilities to Deploy Cyclops Blink

    The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

    Read More ‘Sandworm’ Chains Cisco Vulnerabilities to Deploy Cyclops BlinkContinue

  • Blog

    Maximum Severity GitLab Flaw Puts Supply Chains at Risk

    CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

    Read More Maximum Severity GitLab Flaw Puts Supply Chains at RiskContinue

  • Blog

    3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker’s…

    Read More 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber CredentialsContinue

  • Blog

    Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

    A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser….

    Read More Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML ExportsContinue

  • Blog

    New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

    Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server’s software and can briefly…

    Read More New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential ComputingContinue

  • Blog

    Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

    A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. “Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,” Acronis Threat Research Unit…

    Read More Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six CountriesContinue

  • Blog

    Anthropic CEO: Time to Shift From Improving to Controlling AI

    Dario Amodei says it’s time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?

    Read More Anthropic CEO: Time to Shift From Improving to Controlling AIContinue

  • Blog

    ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed…

    Read More ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and RootkitsContinue

Page navigation

1 2 3 … 590 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us