Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package

    Cybersecurity researchers have discovered what has been described as the first-ever instance of a Model Context Protocol (MCP) server spotted in the wild, raising software supply chain risks. According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called “postmark-mcp” that copied an official Postmark Labs library of…

    Read More First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP PackageContinue

  • Blog

    China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks

    Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU). “The new variant’s features overlap with both the RainyDay and Turian backdoors, including abuse of the same legitimate applications for DLL side-loading,…

    Read More China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN NetworksContinue

  • Blog

    Volvo Employee SSNs Stolen in Supplier Ransomware Attack

    Three international vehicle manufacturers have fallen to supply chain cyberattacks in the past month alone.

    Read More Volvo Employee SSNs Stolen in Supplier Ransomware AttackContinue

  • Blog

    Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam

    A new campaign has been observed impersonating Ukrainian government agencies in phishing attacks to deliver CountLoader, which is then used to drop Amatera Stealer and PureMiner. “The phishing emails contain malicious Scalable Vector Graphics (SVG) files designed to trick recipients into opening harmful attachments,” Fortinet FortiGuard Labs researcher Yurren Wan said in a report shared…

    Read More Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and VietnamContinue

  • Blog

    Iranian State Hackers Use SSL.com Certificates to Sign Malware

    Security researchers say multiple threat groups, including Iran’s Charming Kitten APT offshoot Subtle Snail, are deploying malware with code-signing certificates from the Houston-based company.

    Read More Iranian State Hackers Use SSL.com Certificates to Sign MalwareContinue

  • Blog

    Prep is Underway, But 2026 FIFA World Cup Poses Significant Cyber Challenges

    The world’s most-popular sports contest starts in June 2026 across 16 venues in three countries: Securing the event infrastructure from cyber threats will require massive collaboration.

    Read More Prep is Underway, But 2026 FIFA World Cup Poses Significant Cyber ChallengesContinue

  • Blog

    New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks

    The Russian advanced persistent threat (APT) group known as COLDRIVER has been attributed to a fresh round of ClickFix-style attacks designed to deliver two new “lightweight” malware families tracked as BAITSWITCH and SIMPLEFIX. Zscaler ThreatLabz, which detected the new multi-stage ClickFix campaign earlier this month, described BAITSWITCH as a downloader that ultimately drops SIMPLEFIX, a

    Read More New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused CyberattacksContinue

  • Blog

    Crash Tests for Security: Why BAS Is Proof of Defense, Not Assumptions

    Car makers don’t trust blueprints. They smash prototypes into walls. Again and again. In controlled conditions. Because design specs don’t prove survival. Crash tests do. They separate theory from reality. Cybersecurity is no different. Dashboards overflow with “critical” exposure alerts. Compliance reports tick every box.  But none of that proves what matters most to a…

    Read More Crash Tests for Security: Why BAS Is Proof of Defense, Not AssumptionsContinue

  • Blog

    HeartCrypt’s wholesale impersonation effort

    How the notorious Packer-as-a-Service operation built itself into a hydra

    Read More HeartCrypt’s wholesale impersonation effortContinue

  • Blog

    Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure

    Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active exploitation of the recently disclosed security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software as early as September 10, 2025, a whole week before it was publicly disclosed. “This is not ‘just’ a CVSS 10.0 flaw in a solution long favored…

    Read More Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public DisclosureContinue

Page navigation

Previous PagePrevious 1 … 321 322 323 324 325 … 586 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us