Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The…

    Read More Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesContinue

  • Blog

    ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

    Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert…

    Read More ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesContinue

  • Blog

    Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

    Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with The Hacker News ahead…

    Read More Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesContinue

  • Blog

    Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

    The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or…

    Read More Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeContinue

  • Blog

    China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

    An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the…

    Read More China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare AttacksContinue

  • Blog

    How Synthetic Identity Fraud is Coming for Machine Identities

    Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn’t exist. Since no…

    Read More How Synthetic Identity Fraud is Coming for Machine IdentitiesContinue

  • Blog

    Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

    Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,

    Read More Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersContinue

  • Blog

    Agentic AI Challenges Progress in Confidential Computing

    Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.

    Read More Agentic AI Challenges Progress in Confidential ComputingContinue

  • Blog

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is…

    Read More Google Adds Selfie Video Recovery for Users Locked Out of Their AccountsContinue

  • Blog

    Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

    RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation. The…

    Read More Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsContinue

Page navigation

1 2 3 … 535 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us