Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan]

    Every tap, click, and swipe we make online shapes our digital lives, but it also opens doors—some we never meant to unlock. Extensions we trust, assistants we rely on, and even the codes we scan are turning into tools for attackers. The line between convenience and vulnerability has never been thinner. This week, we dive…

    Read More ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan]Continue

  • Blog

    From $22M in Ransom to +100M Stolen Records: 2025’s All-Star SaaS Threat Actors to Watch

    In 2024, cyber threats targeting SaaS surged, with 7,000 password attacks blocked per second (just in Entra ID)—a 75% increase from last year—and phishing attempts up by 58%, causing $3.5 billion in losses (source: Microsoft Digital Defense Report 2024). SaaS attacks are increasing, with hackers often evading detection through legitimate usage patterns. The cyber threat…

    Read More From $22M in Ransom to +100M Stolen Records: 2025’s All-Star SaaS Threat Actors to WatchContinue

  • Blog

    FireScam Android Malware Poses as Telegram Premium to Steal Data and Control Devices

    An Android information stealing malware named FireScam has been found masquerading as a premium version of the Telegram messaging app to steal data and maintain persistent remote control over compromised devices. “Disguised as a fake ‘Telegram Premium’ app, it is distributed through a GitHub.io-hosted phishing site that impersonates RuStore – a popular app store in…

    Read More FireScam Android Malware Poses as Telegram Premium to Steal Data and Control DevicesContinue

  • Blog

    Cybercriminals Target Ethereum Developers with Fake Hardhat npm Packages

    Cybersecurity researchers have revealed several malicious packages on the npm registry that have been found impersonating the Nomic Foundation’s Hardhat tool in order to steal sensitive data from developer systems. “By exploiting trust in open source plugins, attackers have infiltrated these platforms through malicious npm packages, exfiltrating critical data such as private keys, mnemonics,

    Read More Cybercriminals Target Ethereum Developers with Fake Hardhat npm PackagesContinue

  • Blog

    Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution

    A high-severity security flaw has been disclosed in ProjectDiscovery’s Nuclei, a widely-used open-source vulnerability scanner that, if successfully exploited, could allow attackers to bypass signature checks and potentially execute malicious code. Tracked as CVE-2024-43405, it carries a CVSS score of 7.4 out of a maximum of 10.0. It impacts all versions of Nuclei later than…

    Read More Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code ExecutionContinue

  • Blog

    PLAYFULGHOST Delivered via Phishing and SEO Poisoning in Trojanized VPN Apps

    Cybersecurity researchers have flagged a new malware called PLAYFULGHOST that comes with a wide range of information-gathering features like keylogging, screen capture, audio capture, remote shell, and file transfer/execution. The backdoor, according to Google’s Managed Defense team, shares functional overlaps with a known remote administration tool referred to as Gh0st RAT, which had its source

    Read More PLAYFULGHOST Delivered via Phishing and SEO Poisoning in Trojanized VPN AppsContinue

  • Blog

    U.S. Sanctions Chinese Cybersecurity Firm for State-Backed Hacking Campaigns

    The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Friday issued sanctions against a Beijing-based cybersecurity company known as Integrity Technology Group, Incorporated for orchestrating several cyber attacks against U.S. victims. These attacks have been publicly attributed to a Chinese state-sponsored threat actor tracked as Flax Typhoon (aka Ethereal Panda or

    Read More U.S. Sanctions Chinese Cybersecurity Firm for State-Backed Hacking CampaignsContinue

  • Blog

    Thousands of Buggy BeyondTrust Systems Remain Exposed

    Weeks after the critical vulnerability was reported and a hacking of the Treasury Department, nearly 9,000 BeyondTrust instances remain wide open to the Internet, researchers say.

    Read More Thousands of Buggy BeyondTrust Systems Remain ExposedContinue

  • Blog

    New HIPAA Cybersecurity Rules Pull No Punches

    Healthcare organizations of all shapes and sizes will be held to a stricter standard of cybersecurity starting in 2025 with new proposed rules, but not all have the budget for it.

    Read More New HIPAA Cybersecurity Rules Pull No PunchesContinue

  • Blog

    Treasury Dept. Sanctions Chinese Tech Vendor for Complicity

    Integrity Technology Group was found complicit with Flax Typhoon as part of a broader Chinese strategy to infiltrate the IT systems of US critical infrastructure.

    Read More Treasury Dept. Sanctions Chinese Tech Vendor for ComplicityContinue

Page navigation

Previous PagePrevious 1 … 369 370 371 372 373 … 376 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us