Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

    Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. “The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS,” ESET said in a report shared with The Hacker News. “Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP,

    Read More China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based StealthContinue

  • Blog

    Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

    The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. “The attack email contained a message impersonating an MS account security alert,” the Genians Security Center (GSC) said. “It was designed to create concern over possible

    Read More Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT MalwareContinue

  • Blog

    Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

    Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. “A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,…

    Read More Cisco Releases Security Updates for Actively Exploited SD-WAN Manager FlawContinue

  • Blog

    CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case…

    Read More CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationContinue

  • Blog

    Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

    A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the unusual part: the attackers rewired the victims’ own Google Workspace…

    Read More Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense EmailsContinue

  • Blog

    North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

    Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes

    Read More North Korean Hackers Are Turning Developer Tools Into Malware Delivery ChannelsContinue

  • Blog

    Copilot ‘SearchLeak’ Attack Allows 1-Click Data Theft

    The critical, three-stage attack is now patched, but it’s part of a new group of AI prompt-injection issues that use hidden URLs and other variables.

    Read More Copilot ‘SearchLeak’ Attack Allows 1-Click Data TheftContinue

  • Blog

    China-Nexus Actor Spied on US Researchers Undetected for a Year

    Google discovered and disrupted the sprawling campaign, which stole RedCAP credentials to target numerous institutions and exfiltrate sensitive data.

    Read More China-Nexus Actor Spied on US Researchers Undetected for a YearContinue

  • Blog

    Most CISOs Report Pressure to Bury Bad Security News

    Executive leaders may not be saying it aloud, but business objectives and priorities don’t always promote timely disclosures.

    Read More Most CISOs Report Pressure to Bury Bad Security NewsContinue

  • Blog

    LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

    A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface. A server takeover exposes every provider…

    Read More LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway ServersContinue

Page navigation

Previous PagePrevious 1 … 51 52 53 54 55 … 546 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us