Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

    A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which…

    Read More Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia CampaignContinue

  • Blog

    Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

    A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer’s cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked as CVE-2026-12957 (CVSS 8.5), the bug sat in how Amazon’s AI coding assistant handled Model…

    Read More Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP ConfigsContinue

  • Blog

    New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

    A flaw in the Linux kernel’s traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed “pedit COW,” is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working exploit appeared within a day of the CVE assignment on June 16. Red Hat rates the flaw as

    Read More New Linux pedit COW Exploit Enables Root Access by Poisoning Cached BinariesContinue

  • Blog

    CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is

    Read More CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueContinue

  • Blog

    New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

    DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a cloned network packet and gain root. The patch landed in

    Read More New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned PacketsContinue

  • Blog

    Guardian Agents: The Next Layer of Identity Governance

    AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn’t designed for autonomous actors, and the gap between what enterprises are deploying and what their governance programs actually cover is widening fast. This guide breaks

    Read More Guardian Agents: The Next Layer of Identity GovernanceContinue

  • Blog

    Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

    Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. “The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow…

    Read More Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain AttackContinue

  • Blog

    Name That Toon Contest

    Post Content

    Read More Name That Toon ContestContinue

  • Blog

    Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

    An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says. The company has not attributed the activity to a known threat actor, and the operators’ end goal is still unclear. The lure…

    Read More Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js ImplantContinue

  • Blog

    Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff

    Russian authorities used Cellebrite’s UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and services to Russia and Belarus. The finding, published June 25 by the Citizen Lab, rests on two things that rarely line up: traces…

    Read More Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales CutoffContinue

Page navigation

1 2 3 … 504 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us