Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI Tools

    Cybersecurity researchers have disclosed a malicious campaign that leverages search engine optimization (SEO) poisoning techniques to deliver a known malware loader called Oyster (aka Broomstick or CleanUpLoader). The malvertising activity, per Arctic Wolf, promotes fake websites hosting trojanized versions of legitimate tools like PuTTY and WinSCP, aiming to trick software professionals

    Read More SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI ToolsContinue

  • Blog

    Chrome Store Features Extension Poisoned With Sophisticated Spyware

    A color picker for Google’s browser with more than 100,000 downloads hijacks sessions every time a user navigates to a new webpage and also redirects them to malicious sites.

    Read More Chrome Store Features Extension Poisoned With Sophisticated SpywareContinue

  • Blog

    Strengthening cyber resilience: Introducing Internal Attack Surface Management (IASM) for Sophos Managed Risk

    Enhanced vulnerability management delivered as a managed service.

    Read More Strengthening cyber resilience: Introducing Internal Attack Surface Management (IASM) for Sophos Managed RiskContinue

  • Blog

    ⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and More

    Everything feels secure—until one small thing slips through. Even strong systems can break if a simple check is missed or a trusted tool is misused. Most threats don’t start with alarms—they sneak in through the little things we overlook. A tiny bug, a reused password, a quiet connection—that’s all it takes. Staying safe isn’t just…

    Read More ⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreContinue

  • Blog

    Manufacturing Security: Why Default Passwords Must Go

    If you didn’t hear about Iranian hackers breaching US water facilities, it’s because they only managed to control a single pressure station serving 7,000 people. What made this attack noteworthy wasn’t its scale, but how easily the hackers gained access — by simply using the manufacturer’s default password “1111.” This narrow escape prompted CISA to urge manufacturers…

    Read More Manufacturing Security: Why Default Passwords Must GoContinue

  • Blog

    TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail Sectors

    A hacking group with ties other than Pakistan has been found targeting Indian government organizations with a modified variant of a remote access trojan (RAT) called DRAT. The activity has been attributed by Recorded Future’s Insikt Group to a threat actor tracked as TAG-140, which it said overlaps with SideCopy, an adversarial collective assessed to…

    Read More TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail SectorsContinue

  • Blog

    Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties

    Taiwan’s National Security Bureau (NSB) has warned that China-developed applications like RedNote (aka Xiaohongshu), Weibo, TikTok, WeChat, and Baidu Cloud pose security risks due to excessive data collection and data transfer to China. The alert comes following an inspection of these apps carried out in coordination with the Ministry of Justice Investigation Bureau (MJIB) and…

    Read More Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China TiesContinue

  • Blog

    Alert: Exposed JDWP Interfaces Lead to Crypto Mining, Hpingbot Targets SSH for DDoS

    Threat actors are weaponizing exposed Java Debug Wire Protocol (JDWP) interfaces to obtain code execution capabilities and deploy cryptocurrency miners on compromised hosts. “The attacker used a modified version of XMRig with a hard-“coded configuration, allowing them to avoid suspicious command-line arguments that are often flagged by defenders,” Wiz researchers Yaara Shriki and Gili

    Read More Alert: Exposed JDWP Interfaces Lead to Crypto Mining, Hpingbot Targets SSH for DDoSContinue

  • Blog

    NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors

    Cybersecurity researchers have shed light on a previously undocumented threat actor called NightEagle (aka APT-Q-95) that has been observed targeting Microsoft Exchange servers as a part of a zero-day exploit chain designed to target government, defense, and technology sectors in China. According to QiAnXin’s RedDrip Team, the threat actor has been active since 2023 and…

    Read More NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech SectorsContinue

  • Blog

    Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It

    Generative AI is changing how businesses work, learn, and innovate. But beneath the surface, something dangerous is happening. AI agents and custom GenAI workflows are creating new, hidden ways for sensitive enterprise data to leak—and most teams don’t even realize it. If you’re building, deploying, or managing AI systems, now is the time to ask:…

    Read More Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop ItContinue

Page navigation

Previous PagePrevious 1 … 312 313 314 315 316 … 490 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us