Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Regeneron Pledges Privacy Protection in $256M Bid for 23andMe

    Regeneron’s acquisition of 23andMe raises significant privacy concerns as experts warn about the lack of comprehensive federal regulations governing the transfer of genetic information.

    Read More Regeneron Pledges Privacy Protection in $256M Bid for 23andMeContinue

  • Blog

    Bumblebee Malware Takes Flight via Trojanized VMware Utility

    An employee inadvertently downloaded a malicious version of the legitimate RVTools utility, which launched an investigation into an attempted supply chain attack aimed at delivering the recently revived initial-access loader.

    Read More Bumblebee Malware Takes Flight via Trojanized VMware UtilityContinue

  • Blog

    Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery

    A threat actor known as Hazy Hawk has been observed hijacking abandoned cloud resources of high-profile organizations, including Amazon S3 buckets and Microsoft Azure endpoints, by leveraging misconfigurations in the Domain Name System (DNS) records. The hijacked domains are then used to host URLs that direct users to scams and malware via traffic distribution systems…

    Read More Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware DeliveryContinue

  • Blog

    Large Retailers Land in Scattered Spider’s Ransomware Web

    The threat group games IT help desks to gain entry into retailer networks, and signs show it has shifted its attention from the UK to US targets.

    Read More Large Retailers Land in Scattered Spider’s Ransomware WebContinue

  • Blog

    100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting Ads

    An unknown threat actor has been attributed to creating several malicious Chrome Browser extensions since February 2024 that masquerade as seemingly benign utilities but incorporate covert functionality to exfiltrate data, receive commands, and execute arbitrary code. “The actor creates websites that masquerade as legitimate services, productivity tools, ad and media creation or analysis

    Read More 100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting AdsContinue

  • Blog

    ‘Hazy Hawk’ Cybercrime Gang Swoops In for Cloud Resources

    Since December 2023, the threat group has preyed on domains belonging to the US Centers for Disease Control and Prevention (CDC) and numerous other reputable organizations worldwide to redirect users to malicious sites.

    Read More ‘Hazy Hawk’ Cybercrime Gang Swoops In for Cloud ResourcesContinue

  • Blog

    Why Rigid Security Programs Keep Failing

    Organizations that stay ahead of attacks won’t be the most compliant ones — they’ll be the ones most honest about what actually works.

    Read More Why Rigid Security Programs Keep FailingContinue

  • Blog

    Novel Phishing Attack Combines AES With Poisoned npm Packages

    Researchers discovered a phishing attack in the wild that takes multiple well-tread technologies like open source packages and AES encryption and combines them.

    Read More Novel Phishing Attack Combines AES With Poisoned npm PackagesContinue

  • Blog

    South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware

    High-level government institutions in Sri Lanka, Bangladesh, and Pakistan have emerged as the target of a new campaign orchestrated by a threat actor known as SideWinder. “The attackers used spear phishing emails paired with geofenced payloads to ensure that only victims in specific countries received the malicious content,” Acronis researchers Santiago Pontiroli, Jozsef Gegeny, and…

    Read More South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom MalwareContinue

  • Blog

    AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service Exploitation

    Cybersecurity researchers have discovered risky default identity and access management (IAM) roles impacting Amazon Web Services that could open the door for attackers to escalate privileges, manipulate other AWS services, and, in some cases, even fully compromise AWS accounts. “These roles, often created automatically or recommended during setup, grant overly broad permissions, such as full…

    Read More AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service ExploitationContinue

Page navigation

Previous PagePrevious 1 … 364 365 366 367 368 … 492 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us