Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    JSON Config File Leaks Azure ActiveDirectory Credentials

    In this type of misconfiguration, cyberattackers could use exposed secrets to authenticate directly via Microsoft’s OAuth 2.0 endpoints and infiltrate Azure cloud environments.

    Read More JSON Config File Leaks Azure ActiveDirectory CredentialsContinue

  • Blog

    Shadow AI Discovery: A Critical Part of Enterprise AI Governance

    The Harsh Truths of AI Adoption MITs State of AI in Business report revealed that while 40% of organizations have purchased enterprise LLM subscriptions, over 90% of employees are actively using AI tools in their daily work. Similarly, research from Harmonic Security found that 45.4% of sensitive AI interactions are coming from personal email accounts,…

    Read More Shadow AI Discovery: A Critical Part of Enterprise AI GovernanceContinue

  • Blog

    Innovation unlocked: Sophos Endpoint is now integrated with Taegis MDR and XDR

    Customers gain immediate access to combined prevention, detection, and response capabilities in a single platform – while lowering costs and simplifying operations.

    Read More Innovation unlocked: Sophos Endpoint is now integrated with Taegis MDR and XDRContinue

  • Blog

    Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices

    Cybersecurity researchers have flagged a Ukrainian IP network for engaging in massive brute-force and password spraying campaigns targeting SSL VPN and RDP devices between June and July 2025. The activity originated from a Ukraine-based autonomous system FDN3 (AS211736), per French cybersecurity company Intrinsec. “We believe with a high level of confidence that FDN3 is part…

    Read More Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP DevicesContinue

  • Blog

    Silver Fox Exploits Microsoft-Signed WatchDog Driver to Deploy ValleyRAT Malware

    The threat actor known as Silver Fox has been attributed to abuse of a previously unknown vulnerable driver associated with WatchDog Anti-malware as part of a Bring Your Own Vulnerable Driver (BYOVD) attack aimed at disarming security solutions installed on compromised hosts. The vulnerable driver in question is “amsdk.sys” (version 1.0.600), a 64-bit, validly signed…

    Read More Silver Fox Exploits Microsoft-Signed WatchDog Driver to Deploy ValleyRAT MalwareContinue

  • Blog

    Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets

    Cybersecurity researchers have discovered a malicious npm package that comes with stealthy features to inject malicious code into desktop apps for cryptocurrency wallets like Atomic and Exodus on Windows systems. The package, named nodejs-smtp, impersonates the legitimate email library nodemailer with an identical tagline, page styling, and README descriptions, attracting a total of 347

    Read More Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus WalletsContinue

  • Blog

    Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans

    Cybersecurity researchers are calling attention to a new shift in the Android malware landscape where dropper apps, which are typically used to deliver banking trojans, to also distribute simpler malware such as SMS stealers and basic spyware. These campaigns are propagated via dropper apps masquerading as government or banking apps in India and other parts…

    Read More Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking TrojansContinue

  • Blog

    ⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & More

    Cybersecurity today is less about single attacks and more about chains of small weaknesses that connect into big risks. One overlooked update, one misused account, or one hidden tool in the wrong hands can be enough to open the door. The news this week shows how attackers are mixing methods—combining stolen access, unpatched software, and…

    Read More ⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & MoreContinue

  • Blog

    When Browsers Become the Attack Surface: Rethinking Security for Scattered Spider

    As enterprises continue to shift their operations to the browser, security teams face a growing set of cyber challenges. In fact, over 80% of security incidents now originate from web applications accessed via Chrome, Edge, Firefox, and other browsers. One particularly fast-evolving adversary, Scattered Spider, has made it their mission to wreak havoc on enterprises…

    Read More When Browsers Become the Attack Surface: Rethinking Security for Scattered SpiderContinue

  • Blog

    ScarCruft Uses RokRAT Malware in Operation HanKook Phantom Targeting South Korean Academics

    Cybersecurity researchers have discovered a new phishing campaign undertaken by the North Korea-linked hacking group called ScarCruft (aka APT37) to deliver a malware known as RokRAT. The activity has been codenamed Operation HanKook Phantom by Seqrite Labs, stating the attacks appear to target individuals associated with the National Intelligence Research Association, including academic figures

    Read More ScarCruft Uses RokRAT Malware in Operation HanKook Phantom Targeting South Korean AcademicsContinue

Page navigation

Previous PagePrevious 1 … 174 175 176 177 178 … 414 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us