Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

    A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to

    Read More New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered CyberattacksContinue

  • Blog

    What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

    Shadow AI used to mean employees pasting things they shouldn’t into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop. The artifact moved from a prompt to a product. The risk surface moved…

    Read More What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security StacksContinue

  • Blog

    Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

    Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil’s largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of “Sicoob.Sdk” contain functionality to exfiltrate sensitive information, including PFX certificates that are used to

    Read More Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud SecretsContinue

  • Blog

    Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

    The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. “Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex…

    Read More Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code TunnelsContinue

  • Blog

    Dutch Raid Fails to Dent Russian Bulletproof Host

    Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the hosting provider’s core IP address space intact.

    Read More Dutch Raid Fails to Dent Russian Bulletproof HostContinue

  • Blog

    Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

    A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier. “The vulnerability allows any authenticated user to achieve…

    Read More Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary CodeContinue

  • Blog

    Agentic AI Isn’t Risky; the Way Orgs Deploy It Is

    AI agents aren’t black boxes — they’re models interacting with software tools. The risk lies in their overlap.

    Read More Agentic AI Isn’t Risky; the Way Orgs Deploy It IsContinue

  • Blog

    Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

    Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. “The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints,” Arctic Wolf said. “Threat actors disguised the credential stealer payload as a Fortinet endpoint

    Read More Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential StealerContinue

  • Blog

    Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

    Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day

    Read More Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account RemovalContinue

  • Blog

    ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

    Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now – meanwhile some researcher casually drops a technique that turns…

    Read More ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 MoreContinue

Page navigation

Previous PagePrevious 1 … 20 21 22 23 24 … 499 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us