Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means

    In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have

    Read More Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That MeansContinue

  • Blog

    Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone

    The iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” the Citizen Lab said….

    Read More Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhoneContinue

  • Blog

    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. “FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding

    Read More Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike FalconContinue

  • Blog

    CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – CVE-2026-83548 (CVSS score: 10.0) – A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated

    Read More CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersContinue

  • Blog

    AI’s Vulnerability Surge May Be More Manageable Than First Feared

    New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

    Read More AI’s Vulnerability Surge May Be More Manageable Than First FearedContinue

  • Blog

    SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

    The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor’s edge devices.

    Read More SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCEContinue

  • Blog

    AI Gives Cybercriminals a Dangerous Time Advantage

    Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

    Read More AI Gives Cybercriminals a Dangerous Time AdvantageContinue

  • Blog

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. “The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that…

    Read More Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access ProgramsContinue

  • Blog

    Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users

    The “Spring Ring” operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

    Read More Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams UsersContinue

  • Blog

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. “The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft

    Read More Fake Software Installers Disable Windows Update and Weaken Microsoft DefenderContinue

Page navigation

Previous PagePrevious 1 … 15 16 17 18 19 … 596 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us