Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware

    The financially motivated threat actor known as FIN6 has been observed leveraging fake resumes hosted on Amazon Web Services (AWS) infrastructure to deliver a malware family called More_eggs. “By posing as job seekers and initiating conversations through platforms like LinkedIn and Indeed, the group builds rapport with recruiters before delivering phishing messages that lead to…

    Read More FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs MalwareContinue

  • Blog

    Rust-based Myth Stealer Malware Spread via Fake Gaming Sites Targets Chrome, Firefox Users

    Cybersecurity researchers have shed light on a previously undocumented Rust-based information stealer called Myth Stealer that’s being propagated via fraudulent gaming websites. “Upon execution, the malware displays a fake window to appear legitimate while simultaneously decrypting and executing malicious code in the background,” Trellix security researchers Niranjan Hegde, Vasantha Lakshmanan

    Read More Rust-based Myth Stealer Malware Spread via Fake Gaming Sites Targets Chrome, Firefox UsersContinue

  • Blog

    Poisoned npm Packages Disguised as Utilities Aim for System Wipeout

    Backdoors lurking in legitimate-looking code contain file-deletion commands that can destroy production systems and cause massive disruptions to software supply chains.

    Read More Poisoned npm Packages Disguised as Utilities Aim for System WipeoutContinue

  • Blog

    SSH Keys: The Most Powerful Credential You’re Probably Ignoring

    SSH keys enable critical system access but often lack proper management. This security blind spot creates significant risk through untracked, unrotated credentials that persist across your infrastructure.

    Read More SSH Keys: The Most Powerful Credential You’re Probably IgnoringContinue

  • Blog

    Sophos Emergency Incident Response is now available

    The first service combining the power of Sophos and Secureworks.

    Read More Sophos Emergency Incident Response is now availableContinue

  • Blog

    The Hidden Threat in Your Stack: Why Non-Human Identity Management is the Next Cybersecurity Frontier

    Modern enterprise networks are highly complex environments that rely on hundreds of apps and infrastructure services. These systems need to interact securely and efficiently without constant human oversight, which is where non-human identities (NHIs) come in. NHIs — including application secrets, API keys, service accounts, and OAuth tokens — have exploded in recent years, thanks…

    Read More The Hidden Threat in Your Stack: Why Non-Human Identity Management is the Next Cybersecurity FrontierContinue

  • Blog

    Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account

    Google has stepped in to address a security flaw that could have made it possible to brute-force an account’s recovery phone number, potentially exposing them to privacy and security risks. The issue, according to Singaporean security researcher “brutecat,” leverages an issue in the company’s account recovery feature. That said, exploiting the vulnerability hinges on several…

    Read More Researcher Found Flaw to Discover Phone Numbers Linked to Any Google AccountContinue

  • Blog

    Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises

    The threat actor known as Rare Werewolf (formerly Rare Wolf) has been linked to a series of cyber attacks targeting Russia and the Commonwealth of Independent States (CIS) countries. “A distinctive feature of this threat is that the attackers favor using legitimate third-party software over developing their own malicious binaries,” Kaspersky said. “The malicious functionality…

    Read More Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian EnterprisesContinue

  • Blog

    CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities Catalog

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added two critical security flaws impacting Erlang/Open Telecom Platform (OTP) SSH and Roundcube to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities in question are listed below – CVE-2025-32433 (CVSS score: 10.0) – A missing authentication for a critical

    Read More CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities CatalogContinue

  • Blog

    New Trump Cybersecurity Order Reverses Biden, Obama Priorities

    The White House put limits on cyber sanctions, killed the digital ID program, and refocused the government’s cyber activities to enabling AI, rolling out post-quantum cryptography, and promoting secure software design.

    Read More New Trump Cybersecurity Order Reverses Biden, Obama PrioritiesContinue

Page navigation

Previous PagePrevious 1 … 339 340 341 342 343 … 491 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us