Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Scattered Lapsus$ Hunters Snared in Cyber Researcher Honeypot

    Scattered Lapsus$ Hunters, also known as ShinyHunters, were drawn in using a realistic, yet mostly fake, dataset.

    Read More Scattered Lapsus$ Hunters Snared in Cyber Researcher HoneypotContinue

  • Blog

    Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

    Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside browsing data to servers under the attackers’ control. The names of the extensions, which collectively have over 900,000 users, are below – Chat GPT for Chrome with GPT-5, Claude Sonnet &…

    Read More Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 UsersContinue

  • Blog

    ClickFix Campaign Serves Up Fake Blue Screen of Death

    Threat actors are using the social engineering technique and a legitimate Microsoft tool to deploy the DCRat remote access Trojan against targets in the hospitality sector.

    Read More ClickFix Campaign Serves Up Fake Blue Screen of DeathContinue

  • Blog

    Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover

    The CERT Coordination Center (CERT/CC) has disclosed details of an unpatched security flaw impacting TOTOLINK EX200 wireless range extender that could allow a remote authenticated attacker to gain full control of the device. The flaw, CVE-2025-65606 (CVSS score: N/A), has been characterized as a flaw in the firmware-upload error-handling logic, which could cause the device…

    Read More Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device TakeoverContinue

  • Blog

    Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat

    Source: Securonix Cybersecurity researchers have disclosed details of a new campaign dubbed PHALT#BLYX that has leveraged ClickFix-style lures to display fixes for fake blue screen of death (BSoD) errors in attacks targeting the European hospitality sector. The end goal of the multi-stage campaign is to deliver a remote access trojan known as DCRat, according to…

    Read More Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRatContinue

  • Blog

    What is Identity Dark Matter?

    The Invisible Half of the Identity Universe Identity used to live in one place – an LDAP directory, an HR system, a single IAM portal. Not anymore. Today, identity is fragmented across SaaS, on-prem, IaaS, PaaS, home-grown, and shadow applications. Each of these environments carries its own accounts, permissions, and authentication flows. Traditional IAM and…

    Read More What is Identity Dark Matter?Continue

  • Blog

    VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX

    Popular artificial intelligence (AI)-powered Microsoft Visual Studio Code (VS Code) forks such as Cursor, Windsurf, Google Antigravity, and Trae have been found to recommend extensions that are non-existent in the Open VSX registry, potentially opening the door to supply chain risks when bad actors publish malicious packages under those names. The problem, according to Koi,…

    Read More VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSXContinue

  • Blog

    New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

    A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to execute arbitrary system commands on the underlying host. The vulnerability, tracked as CVE-2025-68668, is rated 9.9 on the CVSS scoring system. It has been described as a case of a protection mechanism failure….

    Read More New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System CommandsContinue

  • Blog

    Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers

    Users of the “@adonisjs/bodyparser” npm package are being advised to update to the latest version following the disclosure of a critical security vulnerability that, if successfully exploited, could allow a remote attacker to write arbitrary files on the server. Tracked as CVE-2026-21440 (CVSS score: 9.2), the flaw has been described as a path traversal issue…

    Read More Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on ServersContinue

  • Blog

    Startup Trends Shaking Up Browsers, SOC Automation, AppSec

    In 2025, these startups have reimagined browser security, pioneered application security for AI-generated code, and are building consensus on agentic vs. human costs.

    Read More Startup Trends Shaking Up Browsers, SOC Automation, AppSecContinue

Page navigation

Previous PagePrevious 1 … 187 188 189 190 191 … 538 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us