Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

    A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic’s own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto…

    Read More Claude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesContinue

  • Blog

    ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories

    It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and come back worse. Cheap hackers get better toys. AI starts breaking real systems. Great. Read the whole…

    Read More ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesContinue

  • Blog

    China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa

    A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts have been complemented by a “rapid operational tempo” and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT),…

    Read More China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South AfricaContinue

  • Blog

    FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

    Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed JSCoreRunner (aka FileRipple) in late August 2025. The cybercrime group behind the…

    Read More FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube AdsContinue

  • Blog

    Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

    Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework. “The sites are well-designed and often look like legitimate project portals at a glance, sometimes referencing

    Read More Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDSContinue

  • Blog

    Hackers Spied on a Stock Exchange Executive’s Outlook Mailbox for Five Months

    Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and OneDrive so the traffic blended into normal cloud activity. Symantec and Carbon Black’s Threat Hunter Team reported the campaign this…

    Read More Hackers Spied on a Stock Exchange Executive’s Outlook Mailbox for Five MonthsContinue

  • Blog

    CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-45247 (CVSS score: 9.8), is a case of deserialization of untrusted

    Read More CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV CatalogContinue

  • Blog

    DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

    The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting Americans. The “Disruption Week” operation began May 18, 2026, leading to the takedown of millions of social media, email, and internet access accounts used by…

    Read More DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in AssetsContinue

  • Blog

    Pakistan Spies on Afghan Finance Ministry With Xeno RAT

    Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan’s porous cybersecurity.

    Read More Pakistan Spies on Afghan Finance Ministry With Xeno RATContinue

  • Blog

    Attackers Use AI to Automate EDR Evasion Testing

    Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.

    Read More Attackers Use AI to Automate EDR Evasion TestingContinue

Page navigation

1 2 3 … 483 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us