Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation

    A recently disclosed high-severity security flaw in Apache ActiveMQ Classic has come under active exploitation in the wild, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA). To that end, the agency has added the vulnerability, tracked as CVE-2026-34197 (CVSS score: 8.8), to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian

    Read More Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active ExploitationContinue

  • Blog

    North Korea Uses ClickFix to Target macOS Users’ Data

    Sapphire Sleet uses fake job offers and phony Zoom updates to deliver ClickFix attacks that steal credentials and sensitive data from Macs.

    Read More North Korea Uses ClickFix to Target macOS Users’ DataContinue

  • Blog

    ‘Harmless’ Global Adware Transforms Into an AV Killer

    A benign looking update Dragon Boss pushed out in March 2025 established persistence via scheduled tasks and arranged for future payloads to be excluded from Windows Defender.

    Read More ‘Harmless’ Global Adware Transforms Into an AV KillerContinue

  • Blog

    Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic

    Cybersecurity researchers have warned of an active malicious campaign that’s targeting the workforce in the Czech Republic with a previously undocumented botnet dubbed PowMix since at least December 2025. “PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade the network signature detections,” Cisco Talos

    Read More Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 TrafficContinue

  • Blog

    Two-Factor Authentication Breaks Free from the Desktop

    Threat actors know how to bypass security systems outside of traditional IT environments. Implementing 2FA could provide a needed extra security barrier in the physical world.

    Read More Two-Factor Authentication Breaks Free from the DesktopContinue

  • Blog

    Microsoft’s Original Windows Secure Boot Certificate Is Expiring

    The Secure Boot refresh is one of the largest coordinated security maintenance efforts across the Windows ecosystem, Microsoft said. Update those PCs soon.

    Read More Microsoft’s Original Windows Secure Boot Certificate Is ExpiringContinue

  • Blog

    ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories

    You know that feeling when you open your feed on a Thursday morning and it’s just… a lot? Yeah. This week delivered. We’ve got hackers getting creative in ways that are almost impressive if you ignore the whole “crime” part, ancient vulnerabilities somehow still ruining people’s days, and enough supply chain drama to fill a season of television…

    Read More ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More StoriesContinue

  • Blog

    [Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment

    In 2024, compromised service accounts and forgotten API keys were behind 68% of cloud breaches. Not phishing. Not weak passwords. Unmanaged non-human identities that nobody was watching. For every employee in your org, there are 40 to 50 automated credentials: service accounts, API tokens, AI agent connections, andOAuth grants. When projects end or employees leave, most

    Read More [Webinar] Find and Eliminate Orphaned Non-Human Identities in Your EnvironmentContinue

  • Blog

    Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution

    Cisco has announced patches to address four critical security flaws impacting Identity Services and Webex Services that could result in arbitrary code execution and allow an attacker to impersonate any user within the service. The details of the vulnerabilities are below – CVE-2026-20184 (CVSS score: 9.8) – An improper certificate validation in the integration of single sign-on…

    Read More Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code ExecutionContinue

  • Blog

    Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

    A “novel” social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurrency sectors. Dubbed REF6598 by Elastic Security Labs, the activity has been found to leverage

    Read More Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto AttacksContinue

Page navigation

1 2 3 … 442 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us