Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

    Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a company’s…

    Read More AI Agent Exploits Langflow RCE to Automate Database Ransomware AttackContinue

  • Blog

    FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

    The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. “An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment

    Read More FortiBleed Credential Theft Linked to INC and Lynx Ransomware OperationsContinue

  • Blog

    New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

    Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the…

    Read More New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposContinue

  • Blog

    SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue

    Read More SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active ExploitationContinue

  • Blog

    Crafty Phishing Campaigns Auto-Adapt to Victim’s Device, OS

    Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.

    Read More Crafty Phishing Campaigns Auto-Adapt to Victim’s Device, OSContinue

  • Blog

    And the Winner in Dominant Malware Delivery? ClickFix

    Researchers say the highly effective social engineering technique is no longer the exception for malware attacks — it’s now the rule.

    Read More And the Winner in Dominant Malware Delivery? ClickFixContinue

  • Blog

    Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

    Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component’s internal network port. Synacktiv, which found the bug, says it can lead to a full cluster takeover. There is no fix and no…

    Read More Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes ClustersContinue

  • Blog

    19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

    A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on June 30, where a judge ordered…

    Read More 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking ChargesContinue

  • Blog

    SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

    Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites. These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others.

    Read More SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRATContinue

  • Blog

    VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

    Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs. The activity has been codenamed VEIL#DROP by Securonix. It’s suspected that the initial payloads are distributed either via spear-phishing or a drive-by compromise, which occurs when an unsuspecting user lands…

    Read More VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs StealerContinue

Page navigation

Previous PagePrevious 1 … 34 35 36 37 38 … 546 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us