Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    OpenAI Agent Escape Causes Wikimedia Service Outage

    Autonomous agents also tried to abuse other websites and services hosted by the foundation, using them as proxies for unauthorized activities.

    Read More OpenAI Agent Escape Causes Wikimedia Service OutageContinue

  • Blog

    Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

    Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google’s own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real…

    Read More Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google DomainsContinue

  • Blog

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages…

    Read More Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and StealerContinue

  • Blog

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company’s network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it…

    Read More SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 AppliancesContinue

  • Blog

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache’s multiprocess mode, where the cache runs as a standalone server that LLM workers reach over…

    Read More Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code RemotelyContinue

  • Blog

    PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

    Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including

    Read More PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetContinue

  • Blog

    The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

    The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data…

    Read More The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the WorkflowContinue

  • Blog

    FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. “The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

    Read More FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device CredentialsContinue

  • Blog

    Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

    Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

    Read More Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public DetailsContinue

  • Blog

    What Is Agentic Pentesting? What It Proves, and Where It Stops.

    If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy…

    Read More What Is Agentic Pentesting? What It Proves, and Where It Stops.Continue

Page navigation

1 2 3 … 615 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us