Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    APT41 Uses Google Calendar Events for C2

    APT41, a Chinese state-sponsored threat actor also known as “Double Dragon,” used Google Calendar as command-and-control infrastructure during a campaign last fall.

    Read More APT41 Uses Google Calendar Events for C2Continue

  • Blog

    PumaBot Targets Linux Devices in Latest Botnet Campaign

    While the botnet may not be completely automated, it uses certain tactics when targeting devices that indicate that it may, at the very least, be semiautomated.

    Read More PumaBot Targets Linux Devices in Latest Botnet CampaignContinue

  • Blog

    LexisNexis Informs 360K+ Customers of Third-Party Data Leak

    While the leak affected customer data, LexisNexis said in a notification letter that its products and systems were not compromised.

    Read More LexisNexis Informs 360K+ Customers of Third-Party Data LeakContinue

  • Blog

    Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools

    Fake installers for popular artificial intelligence (AI) tools like OpenAI ChatGPT and InVideo AI are being used as lures to propagate various threats, such as the CyberLock and Lucky_Gh0$t ransomware families, and a new malware dubbed Numero. “CyberLock ransomware, developed using PowerShell, primarily focuses on encrypting specific files on the victim’s system,” Cisco Talos researcher…

    Read More Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular ToolsContinue

  • Blog

    A Defense-in-Depth Approach for the Modern Era

    By integrating intelligent network policies, zero-trust principles, and AI-driven insights, enterprises can create a robust defense against the next generation of cyber threats.

    Read More A Defense-in-Depth Approach for the Modern EraContinue

  • Blog

    New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers

    Cybersecurity researchers have taken the wraps off an unusual cyber attack that leveraged malware with corrupted DOS and PE headers, according to new findings from Fortinet. The DOS (Disk Operating System) and PE (Portable Executable) headers are essential parts of a Windows PE file, providing information about the executable. While the DOS header makes the…

    Read More New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE HeadersContinue

  • Blog

    DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints

    The threat actors behind the DragonForce ransomware gained access to an unnamed Managed Service Provider’s (MSP) SimpleHelp remote monitoring and management (RMM) tool, and then leveraged it to exfiltrate data and drop the locker on multiple endpoints. It’s believed that the attackers exploited a trio of security flaws in SimpleHelp (CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) that…

    Read More DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer EndpointsContinue

  • Blog

    ‘Haozi’ Gang Sells Turnkey Phishing Tools to Amateurs

    The phishing operation is using Telegram groups to sell a phishing-as-a-service kit with customer service, a mascot, and infrastructure that requires little technical knowledge to install.

    Read More ‘Haozi’ Gang Sells Turnkey Phishing Tools to AmateursContinue

  • Blog

    Chinese APT41 Exploits Google Calendar for Malware Command-and-Control Operations

    Google on Wednesday disclosed that the Chinese state-sponsored threat actor known as APT41 leveraged a malware called TOUGHPROGRESS that uses Google Calendar for command-and-control (C2). The tech giant, which discovered the activity in late October 2024, said the malware was hosted on a compromised government website and was used to target multiple other government entities….

    Read More Chinese APT41 Exploits Google Calendar for Malware Command-and-Control OperationsContinue

  • Blog

    Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin

    Cybersecurity researchers have disclosed a critical unpatched security flaw impacting TI WooCommerce Wishlist plugin for WordPress that could be exploited by unauthenticated attackers to upload arbitrary files. TI WooCommerce Wishlist, which has over 100,000 active installations, is a tool to allow e-commerce site customers to save their favorite products for later and share the lists…

    Read More Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist PluginContinue

Page navigation

Previous PagePrevious 1 … 460 461 462 463 464 … 599 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us