Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

    Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to

    Read More 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginContinue

  • Blog

    JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

    JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes…

    Read More JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachContinue

  • Blog

    Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

    OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt’s GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack…

    Read More Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootContinue

  • Blog

    Former Citigroup CISO Blauner on What Makes A Great Security Leader

    The cybersecurity pioneer discusses the evolution of the CISO role, AI’s impact on careers, and why operational resilience is the profession’s next frontier.

    Read More Former Citigroup CISO Blauner on What Makes A Great Security LeaderContinue

  • Blog

    Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

    The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket…

    Read More Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysContinue

  • Blog

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have…

    Read More Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InContinue

  • Blog

    Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

    STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel’s network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and…

    Read More Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitContinue

  • Blog

    Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

    Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved

    Read More Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostContinue

  • Blog

    Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

    A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. “VeloCloud Orchestrator (VCO) on-prem has a security issue where this…

    Read More Attackers Exploit Arista VeloCloud Orchestrator Command Injection FlawContinue

  • Blog

    AI Agent Drives Espionage Attack on Thai Ministry of Finance

    Attackers used Hermes, an autonomous open source tool, in unrestricted “YOLO mode” to conduct espionage against Thailand’s Ministry of Finance.

    Read More AI Agent Drives Espionage Attack on Thai Ministry of FinanceContinue

Page navigation

Previous PagePrevious 1 … 56 57 58 59 60 … 597 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us