Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

    cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS…

    Read More New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database RootContinue

  • Blog

    DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

    A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes…

    Read More DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RATContinue

  • Blog

    CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows

    Read More CISA Adds Exploited N-able N-central Flaw to KEV After Customer CompromisesContinue

  • Blog

    Device Code Phishing Up 1,500% in 2026; Vishing Doubles

    Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.

    Read More Device Code Phishing Up 1,500% in 2026; Vishing DoublesContinue

  • Blog

    Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

    Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.

    Read More Attackers Exploit N-able Patch Bypass Flaw on RMM ServersContinue

  • Blog

    New Tool Traces AI Videos Back to Their Source

    Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.

    Read More New Tool Traces AI Videos Back to Their SourceContinue

  • Blog

    Anthropic: AI Attacks Result of Security Gaps, Not Model Issues

    Last month’s incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.

    Read More Anthropic: AI Attacks Result of Security Gaps, Not Model IssuesContinue

  • Blog

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is “lib-mtop,” an unscoped package with the same name as a…

    Read More 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool UsersContinue

  • Blog

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest…

    Read More Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected AccountsContinue

  • Blog

    INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

    The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its…

    Read More INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 FlawsContinue

Page navigation

Previous PagePrevious 1 … 48 49 50 51 52 … 597 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us