Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

    Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server’s software and can briefly…

    Read More New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential ComputingContinue

  • Blog

    Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

    A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. “Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,” Acronis Threat Research Unit…

    Read More Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six CountriesContinue

  • Blog

    Anthropic CEO: Time to Shift From Improving to Controlling AI

    Dario Amodei says it’s time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?

    Read More Anthropic CEO: Time to Shift From Improving to Controlling AIContinue

  • Blog

    ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed…

    Read More ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and RootkitsContinue

  • Blog

    AI Changed the Exposure Problem. Validation Needs to Change With It.

    There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a…

    Read More AI Changed the Exposure Problem. Validation Needs to Change With It.Continue

  • Blog

    Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store –…

    Read More Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 UsersContinue

  • Blog

    Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

    Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as…

    Read More Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate DataContinue

  • Blog

    CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows – CVE-2026-42016 (CVSS score: 8.1) – An incorrect authorization

    Read More CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVContinue

  • Blog

    When the Whole Company Adopts AI: What It Does to Your SOC

    Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and…

    Read More When the Whole Company Adopts AI: What It Does to Your SOCContinue

  • Blog

    OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

    The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated…

    Read More OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc ServersContinue

Page navigation

1 2 3 … 590 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us