Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    150,000 Sites Compromised by JavaScript Injection Promoting Chinese Gambling Platforms

    An ongoing campaign that infiltrates legitimate websites with malicious JavaScript injects to promote Chinese-language gambling platforms has ballooned to compromise approximately 150,000 sites to date. “The threat actor has slightly revamped their interface but is still relying on an iframe injection to display a full-screen overlay in the visitor’s browser,” c/side security analyst Himanshu

    Read More 150,000 Sites Compromised by JavaScript Injection Promoting Chinese Gambling PlatformsContinue

  • Blog

    CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two six-year-old security flaws impacting Sitecore CMS and Experience Platform (XP) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below – CVE-2019-9874 (CVSS score: 9.8) – A deserialization vulnerability in the Sitecore.Security.AntiCSRF

    Read More CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek DevicesContinue

  • Blog

    NetApp SnapCenter Flaw Could Let Users Gain Remote Admin Access on Plug-In Systems

    A critical security flaw has been disclosed in NetApp SnapCenter that, if successfully exploited, could allow privilege escalation. SnapCenter is an enterprise-focused software that’s used to manage data protection across applications, databases, virtual machines, and file systems, offering the ability to backup, restore, and clone data resources. The vulnerability, tracked as

    Read More NetApp SnapCenter Flaw Could Let Users Gain Remote Admin Access on Plug-In SystemsContinue

  • Blog

    Apache Tomcat RCE

    What is the Vulnerability?On March 10, 2025, Apache issued a security advisory regarding a critical vulnerability (CVE-2025-24813) affecting the Apache Tomcat web server. This flaw could allow attackers to view or inject arbitrary content into security-sensitive files and potentially achieve remote code execution.Exploit code for this vulnerability is publicly available, and no authentication is required…

    Read More Apache Tomcat RCEContinue

  • Blog

    Security Expert Troy Hunt Lured in by Mailchimp Phish

    Hunt quickly took to his blog to notify the public of the breach and provide further details on how this could have happened.

    Read More Security Expert Troy Hunt Lured in by Mailchimp PhishContinue

  • Blog

    Cybersecurity Gaps Leave Doors Wide Open

    Attackers don’t always need to resort to sophisticated gambits to break and enter; organizations often make it easy for them to walk right in.

    Read More Cybersecurity Gaps Leave Doors Wide OpenContinue

  • Blog

    New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican Organizations

    The Chinese threat actor known as FamousSparrow has been linked to a cyber attack targeting a trade group in the United States and a research institute in Mexico to deliver its flagship backdoor SparrowDoor and ShadowPad. The activity, observed in July 2024, marks the first time the hacking crew has deployed ShadowPad, a malware widely…

    Read More New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican OrganizationsContinue

  • Blog

    Beyond STIX: Next-Level Cyber-Threat Intelligence

    While industry experts continue to analyze, interpret, and act on threat data, the complexity of cyber threats necessitates solutions that can quickly convert expert knowledge into machine-readable formats.

    Read More Beyond STIX: Next-Level Cyber-Threat IntelligenceContinue

  • Blog

    ‘Lucid’ Phishing-as-a-Service Exploits Faults in iMessage, Android RCS

    Cybercriminals in China have figured out how to undermine the strengths of mobile messaging protocols.

    Read More ‘Lucid’ Phishing-as-a-Service Exploits Faults in iMessage, Android RCSContinue

  • Blog

    EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware

    The threat actor known as EncryptHub exploited a recently-patched security vulnerability in Microsoft Windows as a zero-day to deliver a wide range of malware families, including backdoors and information stealers such as Rhadamanthys and StealC. “In this attack, the threat actor manipulates .msc files and the Multilingual User Interface Path (MUIPath) to download and execute…

    Read More EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC MalwareContinue

Page navigation

Previous PagePrevious 1 … 426 427 428 429 430 … 496 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us