Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure

    Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active exploitation of the recently disclosed security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software as early as September 10, 2025, a whole week before it was publicly disclosed. “This is not ‘just’ a CVSS 10.0 flaw in a solution long favored…

    Read More Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public DisclosureContinue

  • Blog

    New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module

    Cybersecurity researchers have discovered an updated version of a known Apple macOS malware called XCSSET that has been observed in limited attacks. “This new variant of XCSSET brings key changes related to browser targeting, clipboard hijacking, and persistence mechanisms,” the Microsoft Threat Intelligence team said in a Thursday report. “It employs sophisticated encryption and obfuscation

    Read More New macOS XCSSET Variant Targets Firefox with Clipper and Persistence ModuleContinue

  • Blog

    Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

    The U.K. National Cyber Security Centre (NCSC) has revealed that threat actors have exploited the recently disclosed security flaws impacting Cisco firewalls as part of zero-day attacks to deliver previously undocumented malware families like RayInitiator and LINE VIPER. “The RayInitiator and LINE VIPER malware represent a significant evolution on that used in the previous campaign,…

    Read More Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER MalwareContinue

  • Blog

    Cisco’s Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOS

    Patch now: Cisco recently disclosed four actively exploited zero-days affecting millions of devices, including three targeted by a nation-state actor previously discovered to be behind the “ArcaneDoor” campaign.

    Read More Cisco’s Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOSContinue

  • Blog

    Chinese APT Drops ‘Brickstorm’ Backdoors on Edge Devices

    The China-linked cyber-espionage group UNC5221 is compromising network appliances that cannot run traditional EDR agents to deploy new versions of the “Brickstorm” backdoor.

    Read More Chinese APT Drops ‘Brickstorm’ Backdoors on Edge DevicesContinue

  • Blog

    Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

    Cisco is urging customers to patch two security flaws impacting the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, which it said have been exploited in the wild. The zero-day vulnerabilities in question are listed below – CVE-2025-20333 (CVSS score: 9.9) – An…

    Read More Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation DirectiveContinue

  • Blog

    Salesforce AI Agents Forced to Leak Sensitive Data

    Yet again researchers have uncovered an opportunity (dubbed “ForcedLeak” for indirect prompt injection against autonomous agents lacking sufficient security controls — but this time the risk involves PII, corporate secrets, physical location data, and so much more.

    Read More Salesforce AI Agents Forced to Leak Sensitive DataContinue

  • Blog

    Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network

    The threat actor known as Vane Viper has been outed as a purveyor of malicious ad technology (adtech), while relying on a tangled web of shell companies and opaque ownership structures to deliberately evade responsibility. “Vane Viper has provided core infrastructure in widespread malvertising, ad fraud, and cyberthreat proliferation for at least a decade,” Infoblox…

    Read More Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud NetworkContinue

  • Blog

    Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection

    Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for building artificial intelligence (AI) agents, that could allow attackers to potentially exfiltrate sensitive data from its customer relationship management (CRM) tool by means of an indirect prompt injection. The vulnerability has been codenamed ForcedLeak (CVSS score: 9.4) by Noma Security,

    Read More Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt InjectionContinue

  • Blog

    How Cloud Service Disruptions Are Making Resilience Critical for Developers

    Outages affecting DevOps tools threaten to leave developers coding like it’s 1999. How serious is the threat and what can companies do?

    Read More How Cloud Service Disruptions Are Making Resilience Critical for DevelopersContinue

Page navigation

Previous PagePrevious 1 … 333 334 335 336 337 … 597 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us