Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    MFA Won’t Save You From OAuth Consent Abuse

    MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.

    Read More MFA Won’t Save You From OAuth Consent AbuseContinue

  • Blog

    New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

    WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain…

    Read More New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code ExecutionContinue

  • Blog

    Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

    The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed…

    Read More Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2Continue

  • Blog

    Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

    Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a…

    Read More Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege EscalationContinue

  • Blog

    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references…

    Read More An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.Continue

  • Blog

    Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

    A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude…

    Read More Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding AgentsContinue

  • Blog

    WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

    Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and

    Read More WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageContinue

  • Blog

    Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

    A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”

    Read More Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerContinue

  • Blog

    AI Agent Breaches Spanish Organization, Modifies Personal Data

    AI-driven cyberattacks used to be exotic. Soon, it’ll be odd if threat actors aren’t using agents to do all of their bidding.

    Read More AI Agent Breaches Spanish Organization, Modifies Personal DataContinue

  • Blog

    RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

    Read More RatHat Android Malware Abuses ADB to Retain Shell Access After UninstallContinue

Page navigation

Previous PagePrevious 1 2 3 4 … 596 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us