Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Attackers Combo Up Evasion Tactics for BEC Phishing

    “The TFF Trap” uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.

    Read More Attackers Combo Up Evasion Tactics for BEC PhishingContinue

  • Blog

    Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

    A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it…

    Read More Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignContinue

  • Blog

    HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

    A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic,…

    Read More HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050Continue

  • Blog

    Cybersecurity Keeps Events ‘Uneventful’

    From the World Cup to the United States’ 250th celebration, this year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.

    Read More Cybersecurity Keeps Events ‘Uneventful’Continue

  • Blog

    ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

    A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already…

    Read More ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreContinue

  • Blog

    Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

    At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and…

    Read More Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and UkraineContinue

  • Blog

    Mythos Didn’t Break Your Security Program. Your Exposure Window Could.

    The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain…

    Read More Mythos Didn’t Break Your Security Program. Your Exposure Window Could.Continue

  • Blog

    New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

    Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow…

    Read More New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During ExtractionContinue

  • Blog

    Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

    A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other…

    Read More Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCsContinue

  • Blog

    World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

    In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. “We identified unauthorized access to a limited set of internal datasets…

    Read More World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI AgentContinue

Page navigation

1 2 3 … 531 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us