Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack

    Cybersecurity researchers have disclosed details of a new ransomware family called Osiris that targeted a major food service franchisee operator in Southeast Asia in November 2025. The attack leveraged a malicious driver called POORTRY as part of a known technique referred to as bring your own vulnerable driver (BYOVD) to disarm security software, the Symantec…

    Read More New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD AttackContinue

  • Blog

    Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access

    A critical security flaw has been disclosed in the GNU InetUtils telnet daemon (telnetd) that went unnoticed for nearly 11 years. The vulnerability, tracked as CVE-2026-24061, is rated 9.8 out of 10.0 on the CVSS scoring system. It affects all versions of GNU InetUtils from version 1.9.3 up to and including version 2.7. “Telnetd in…

    Read More Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root AccessContinue

  • Blog

    Latin American Orgs Lack Confidence in Cyber Defenses, Skills

    Cybersecurity professionals in Latin America are least likely to have faith in their countries’ preparedness for cyberattacks on critical infrastructure, the World Economic Forum says.

    Read More Latin American Orgs Lack Confidence in Cyber Defenses, SkillsContinue

  • Blog

    ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories

    Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them. What stands out is how little friction attackers now need. Some activity focused on quiet reach…

    Read More ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ StoriesContinue

  • Blog

    DPRK Actors Deploy VS Code Tunnels for Remote Hacking

    A spear-phishing campaign tied to the Democratic People’s Republic of Korea (DPRK) uses trusted Microsoft infrastructure to avoid detection.

    Read More DPRK Actors Deploy VS Code Tunnels for Remote HackingContinue

  • Blog

    Filling the Most Common Gaps in Google Workspace Security

    Security teams at agile, fast-growing companies often have the same mandate: secure the business without slowing it down. Most teams inherit a tech stack optimized for breakneck growth, not resilience. In these environments, the security team is the helpdesk, the compliance expert, and the incident response team all rolled into one. Securing the cloud office…

    Read More Filling the Most Common Gaps in Google Workspace SecurityContinue

  • Blog

    Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts

    A new malicious package discovered in the Python Package Index (PyPI) has been found to impersonate a popular library for symbolic mathematics to deploy malicious payloads, including a cryptocurrency miner, on Linux hosts. The package, named sympy-dev, mimics SymPy, replicating the latter’s project description verbatim in an attempt to deceive unsuspecting users into thinking that…

    Read More Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux HostsContinue

  • Blog

    SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release

    A new security flaw in SmarterTools SmarterMail email software has come under active exploitation in the wild, two days after the release of a patch. The vulnerability, which currently does not have a CVE identifier, is tracked by watchTowr Labs as WT-2026-0001. It was patched by SmarterTools on January 15, 2026, with Build 9511, following…

    Read More SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch ReleaseContinue

  • Blog

    Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations

    Cybersecurity company Arctic Wolf has warned of a “new cluster of automated malicious activity” that involves unauthorized firewall configuration changes on Fortinet FortiGate devices. The activity, it said, commenced on January 15, 2026, adding it shares similarities with a December 2025 campaign in which malicious SSO logins on FortiGate appliances were recorded against the admin…

    Read More Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall ConfigurationsContinue

  • Blog

    Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex

    Cisco has released fresh patches to address what it described as a “critical” security vulnerability impacting multiple Unified Communications (CM) products and Webex Calling Dedicated Instance that it has been actively exploited as a zero-day in the wild. The vulnerability, CVE-2026-20045 (CVSS score: 8.2), could permit an unauthenticated remote attacker to execute arbitrary commands on…

    Read More Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and WebexContinue

Page navigation

Previous PagePrevious 1 … 51 52 53 54 55 … 416 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us