Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication

    A set of five critical security shortcomings have been disclosed in the Ingress NGINX Controller for Kubernetes that could result in unauthenticated remote code execution, putting over 6,500 clusters at immediate risk by exposing the component to the public internet. The vulnerabilities (CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, and CVE-2025-1974 ), assigned a CVSS score of

    Read More Critical Ingress NGINX Controller Vulnerability Allows RCE Without AuthenticationContinue

  • Blog

    China-Nexus APT ‘Weaver Ant’ Caught in Yearslong Web Shell Attack

    The persistent threat actor was caught using sophisticated Web shell techniques against an unnamed telecommunications company in Asia.

    Read More China-Nexus APT ‘Weaver Ant’ Caught in Yearslong Web Shell AttackContinue

  • Blog

    US Weakens Disinformation Defenses, as Russia & China Ramp Up

    Russia and China spend billions of dollars on state media, propaganda, and disinformation, while the Trump administration has slashed funding for US agencies.

    Read More US Weakens Disinformation Defenses, as Russia & China Ramp UpContinue

  • Blog

    Microsoft Adds Inline Data Protection to Edge for Business to Block GenAI Data Leaks

    Microsoft on Monday announced a new feature called inline data protection for its enterprise-focused Edge for Business web browser. The native data security control is designed to prevent employees from sharing sensitive company-related data into consumer generative artificial intelligence (GenAI) apps like OpenAI ChatGPT, Google Gemini, and DeepSeek. The list will be expanded over time…

    Read More Microsoft Adds Inline Data Protection to Edge for Business to Block GenAI Data LeaksContinue

  • Blog

    FCC Investigates China-Backed Tech Suppliers for Evading US Operations Ban

    FCC chairman warns these companies may still be operating in the US because they don’t believe that being added to its “Covered List” poses any serious risk.

    Read More FCC Investigates China-Backed Tech Suppliers for Evading US Operations BanContinue

  • Blog

    VanHelsing RaaS Launch: 3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics

    A ransomware-as-a-service (RaaS) operation called VanHelsing has already claimed three victims since it launched on March 7, 2025. “The RaaS model allows a wide range of participants, from experienced hackers to newcomers, to get involved with a $5,000 deposit. Affiliates keep 80% of the ransom payments, while the core operators earn 20%,” Check Point said…

    Read More VanHelsing RaaS Launch: 3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion TacticsContinue

  • Blog

    ⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and More

    A quiet tweak in a popular open-source tool opened the door to a supply chain breach—what started as a targeted attack quickly spiraled, exposing secrets across countless projects. That wasn’t the only stealth move. A new all-in-one malware is silently stealing passwords, crypto, and control—while hiding in plain sight. And over 300 Android apps joined…

    Read More ⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and MoreContinue

  • Blog

    ⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and More

    A quiet tweak in a popular open-source tool opened the door to a supply chain breach—what started as a targeted attack quickly spiraled, exposing secrets across countless projects. That wasn’t the only stealth move. A new all-in-one malware is silently stealing passwords, crypto, and control—while hiding in plain sight. And over 300 Android apps joined…

    Read More ⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and MoreContinue

  • Blog

    VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware

    Cybersecurity researchers have uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace that are designed to deploy ransomware that’s under development to its users. The extensions, named “ahban.shiba” and “ahban.cychelloworld,” have since been taken down by the marketplace maintainers. Both the extensions, per ReversingLabs, incorporate code that’s designed to invoke a

    Read More VSCode Marketplace Removes Two Extensions Deploying Early-Stage RansomwareContinue

  • Blog

    VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware

    Cybersecurity researchers have uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace that are designed to deploy ransomware that’s under development to its users. The extensions, named “ahban.shiba” and “ahban.cychelloworld,” have since been taken down by the marketplace maintainers. Both the extensions, per ReversingLabs, incorporate code that’s designed to invoke a

    Read More VSCode Marketplace Removes Two Extensions Deploying Early-Stage RansomwareContinue

Page navigation

Previous PagePrevious 1 … 430 431 432 433 434 … 496 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us