Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities

    Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented tradecraft. The campaigns have been codenamed Gopher Strike and Sheet Attack by Zscaler ThreatLabz, which identified them in September 2025. “While these campaigns share some similarities with the Pakistan-linked Advanced Persistent Threat (APT)

    Read More Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government EntitiesContinue

  • Blog

    WorldLeaks Extortion Group Claims It Stole 1.4TB of Nike Data

    The sportswear brand is investigating an alleged breach of its network that exposed some 188,347 files of highly sensitive corporate data.

    Read More WorldLeaks Extortion Group Claims It Stole 1.4TB of Nike DataContinue

  • Blog

    ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services

    Cybersecurity researchers have disclosed details of a new campaign that combines ClickFix-style fake CAPTCHAs with a signed Microsoft Application Virtualization (App-V) script to distribute an information stealer called Amatera. “Instead of launching PowerShell directly, the attacker uses this script to control how execution begins and to avoid more common, easily recognized execution paths,”

    Read More ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web ServicesContinue

  • Blog

    Beauty in Destruction: Exploring Malware’s Impact Through Art

    Artistic initiatives turn cybersecurity into immersive exhibits at the Museum of Malware Art, transforming digital threats into thought-provoking experiences.

    Read More Beauty in Destruction: Exploring Malware’s Impact Through ArtContinue

  • Blog

    Hand CVE Over to the Private Sector

    How MITRE has mismanaged the world’s vulnerability database for decades and wasted millions along the way.

    Read More Hand CVE Over to the Private SectorContinue

  • Blog

    CTEM in Practice: Prioritization, Validation, and Outcomes That Matter

    Cybersecurity teams increasingly want to move beyond looking at threats and vulnerabilities in isolation. It’s not only about what could go wrong (vulnerabilities) or who might attack (threats), but where they intersect in your actual environment to create real, exploitable exposure. Which exposures truly matter? Can attackers exploit them? Are our defenses effective? Continuous Threat…

    Read More CTEM in Practice: Prioritization, Validation, and Outcomes That MatterContinue

  • Blog

    Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas

    A critical security flaw has been disclosed in Grist‑Core, an open-source, self-hosted version of the Grist relational spreadsheet-database, that could result in remote code execution. The vulnerability, tracked as CVE-2026-24002 (CVSS score: 9.1), has been codenamed Cellbreak by Cyera Research Labs. “One malicious formula can turn a spreadsheet into a Remote Code Execution (RCE) beachhead,”

    Read More Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet FormulasContinue

  • Blog

    China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023

    Cybersecurity researchers have discovered a JScript-based command-and-control (C2) framework called PeckBirdy that has been put to use by China-aligned APT actors since 2023 to target multiple environments. The flexible framework has been put to use against Chinese gambling industries and malicious activities targeting Asian government entities and private organizations, according to Trend Micro

    Read More China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023Continue

  • Blog

    Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation

    Microsoft on Monday issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability exploited in attacks. The vulnerability, tracked as CVE-2026-21509, carries a CVSS score of 7.8 out of 10.0. It has been described as a security feature bypass in Microsoft Office. “Reliance on untrusted inputs in a security decision in Microsoft Office allows…

    Read More Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active ExploitationContinue

  • Blog

    Beyond MFA: Building true resilience against identity-based attacks

    Categories: Sophos Insights Tags: Identity Security, MFA, Sophos ITDR

    Read More Beyond MFA: Building true resilience against identity-based attacksContinue

Page navigation

Previous PagePrevious 1 … 170 171 172 173 174 … 539 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us