Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts

    A new malicious package discovered in the Python Package Index (PyPI) has been found to impersonate a popular library for symbolic mathematics to deploy malicious payloads, including a cryptocurrency miner, on Linux hosts. The package, named sympy-dev, mimics SymPy, replicating the latter’s project description verbatim in an attempt to deceive unsuspecting users into thinking that…

    Read More Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux HostsContinue

  • Blog

    SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release

    A new security flaw in SmarterTools SmarterMail email software has come under active exploitation in the wild, two days after the release of a patch. The vulnerability, which currently does not have a CVE identifier, is tracked by watchTowr Labs as WT-2026-0001. It was patched by SmarterTools on January 15, 2026, with Build 9511, following…

    Read More SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch ReleaseContinue

  • Blog

    Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations

    Cybersecurity company Arctic Wolf has warned of a “new cluster of automated malicious activity” that involves unauthorized firewall configuration changes on Fortinet FortiGate devices. The activity, it said, commenced on January 15, 2026, adding it shares similarities with a December 2025 campaign in which malicious SSO logins on FortiGate appliances were recorded against the admin…

    Read More Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall ConfigurationsContinue

  • Blog

    Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex

    Cisco has released fresh patches to address what it described as a “critical” security vulnerability impacting multiple Unified Communications (CM) products and Webex Calling Dedicated Instance that it has been actively exploited as a zero-day in the wild. The vulnerability, CVE-2026-20045 (CVSS score: 8.2), could permit an unauthenticated remote attacker to execute arbitrary commands on…

    Read More Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and WebexContinue

  • Blog

    AI Agents Undermine Progress in Browser Security

    Web browser companies have put in substantial effort over the last three decades to strengthen the browser security stack to withstand abuses. Agentic browsers are undoing all that work.

    Read More AI Agents Undermine Progress in Browser SecurityContinue

  • Blog

    ‘Contagious Interview’ Attack Now Delivers Backdoor Via VS Code

    Once trust is granted to the repository’s author, a malicious app executes arbitrary commands on the victim’s system with no other user interaction.

    Read More ‘Contagious Interview’ Attack Now Delivers Backdoor Via VS CodeContinue

  • Blog

    Phishing Campaign Zeroes in on LastPass Customers

    The bait incudes plausible subject lines and credible messages, most likely thanks to attackers’ use of large language models to craft them.

    Read More Phishing Campaign Zeroes in on LastPass CustomersContinue

  • Blog

    North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews

    As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with the campaign claiming 20 potential victim organizations spanning artificial intelligence (AI), cryptocurrency, financial services, IT services, marketing, and software development sectors in Europe, South Asia, the Middle East, and Central America. The new findings

    Read More North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job InterviewsContinue

  • Blog

    Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

    Zoom and GitLab have released security updates to resolve a number of security vulnerabilities that could result in denial-of-service (DoS) and remote code execution. The most severe of the lot is a critical security flaw impacting Zoom Node Multimedia Routers (MMRs) that could permit a meeting participant to conduct remote code execution attacks. The vulnerability,…

    Read More Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass FlawsContinue

  • Blog

    Complex VoidLink Linux Malware Created by AI

    Researchers say the advanced framework was built almost entirely by agents, marking a significant evolution in the use of AI to develop wholly original malware.

    Read More Complex VoidLink Linux Malware Created by AIContinue

Page navigation

Previous PagePrevious 1 … 174 175 176 177 178 … 539 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us