Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

    Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators…

    Read More NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private ChatsContinue

  • Blog

    Europe’s Multilingual Reality Exposes AI Security Gaps

    The AI security layer and guardrails for many AI products don’t evenly protect against jailbreaking and unsafe actions in every single language.

    Read More Europe’s Multilingual Reality Exposes AI Security GapsContinue

  • Blog

    Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

    Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote…

    Read More Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers SayContinue

  • Blog

    Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

    The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously…

    Read More Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 AttacksContinue

  • Blog

    Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

    A state-sponsored threat group, dubbed “Laundry Bear,” sends “half-click” phishing emails that require a victim only to open or preview the message.

    Read More Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine TargetsContinue

  • Blog

    Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The…

    Read More Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesContinue

  • Blog

    ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

    Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert…

    Read More ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesContinue

  • Blog

    Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

    Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with The Hacker News ahead…

    Read More Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesContinue

  • Blog

    Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

    The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or…

    Read More Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeContinue

  • Blog

    China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

    An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the…

    Read More China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare AttacksContinue

Page navigation

Previous PagePrevious 1 … 12 13 14 15 16 … 549 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us