Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

    Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below – ubnuler ubnlder ri18nr reaker rakier orakw joxn

    Read More 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto WalletsContinue

  • Blog

    One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

    A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker’s IP address, traces…

    Read More One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025Continue

  • Blog

    SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

    SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line “[Important] Your SafePal Order

    Read More SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 CustomersContinue

  • Blog

    CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

    Read More CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCEContinue

  • Blog

    Video Call Exploit Chains Two Flaws in Unisoc Modems

    Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.

    Read More Video Call Exploit Chains Two Flaws in Unisoc ModemsContinue

  • Blog

    Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

    GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score…

    Read More Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsContinue

  • Blog

    ‘Turf War’ Between Claude Agents Leads to Self-Replicating Malware

    Three testing models with the same goal but different directives engaged in “increasingly aggressive” territorial attacks on one another, according to Anthropic.

    Read More ‘Turf War’ Between Claude Agents Leads to Self-Replicating MalwareContinue

  • Blog

    Adam Shostack Talks Hugging Face & PHANTOM-B

    World-class threat modeler Adam Shostack shared he was “blown away” by OpenAI’s revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both “lightweight yet still usable.”

    Read More Adam Shostack Talks Hugging Face & PHANTOM-BContinue

  • Blog

    Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

    Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a

    Read More Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command InjectionContinue

  • Blog

    Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

    A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security…

    Read More Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP UploadsContinue

Page navigation

Previous PagePrevious 1 … 33 34 35 36 37 … 596 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us