Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Android Malware Hijacks Update System for Car Head Units

    Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.

    Read More Android Malware Hijacks Update System for Car Head UnitsContinue

  • Blog

    FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

    The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company…

    Read More FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. OrganizationsContinue

  • Blog

    Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

    Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

    Read More Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH TunnelerContinue

  • Blog

    NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

    Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

    Read More NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 SessionsContinue

  • Blog

    CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also

    Read More CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected NothingContinue

  • Blog

    Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

    The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed…

    Read More Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run CodeContinue

  • Blog

    Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

    The SOC we’ve always known was built around a model that guarantees most of the alert queue will never receive analyst review. There’s never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide…

    Read More Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis EngineContinue

  • Blog

    ‘NovaCookies’ Kit Steals Microsoft 365 Sessions for $320 a Month

    The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

    Read More ‘NovaCookies’ Kit Steals Microsoft 365 Sessions for $320 a MonthContinue

  • Blog

    Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests

    Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the…

    Read More Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in TestsContinue

  • Blog

    OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

    OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts “were being used to…

    Read More OpenAI Bans Russian ChatGPT Accounts Used to Run Influence OperationContinue

Page navigation

Previous PagePrevious 1 … 23 24 25 26 27 … 596 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us