Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    EDR Evasion Stack Helps Process Injection Slip Past Defenses

    A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.

    Read More EDR Evasion Stack Helps Process Injection Slip Past DefensesContinue

  • Blog

    GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks

    Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.

    Read More GitLab Email Addresses Can Be Weaponized for Supply Chain AttacksContinue

  • Blog

    Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below – gocommunity-io/dockerd (222 downloads) kreuzwenker/

    Read More Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp RegistryContinue

  • Blog

    A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

    The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a…

    Read More A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as YouContinue

  • Blog

    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

    Read More MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH KeyContinue

  • Blog

    UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

    The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.

    Read More UAE, Saudi Arabia Face Onslaught of Increasingly Complex CyberattacksContinue

  • Blog

    Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

    Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.

    Read More Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing CampaignContinue

  • Blog

    This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker’s server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and…

    Read More This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next MoveContinue

  • Blog

    Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below – @memtensor/memos-cloud-openclaw-plugin versions

    Read More Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPIContinue

  • Blog

    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other…

    Read More New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server ControlContinue

Page navigation

1 2 3 … 600 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us