Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

    North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim’s KakaoTalk desktop application to distribute malicious payloads to certain contacts. The activity has been attributed by South Korean threat intelligence firm Genians to a hacking group referred to as Konni. “Initial access was achieved through a spear-phishing…

    Read More Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate MalwareContinue

  • Blog

    CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Wing FTP to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2025-47813 (CVSS score: 4.3), is an information disclosure vulnerability that leaks the installation path of the application under certain conditions

    Read More CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server PathsContinue

  • Blog

    China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years

    Researchers uncovered an extensive cyberespionage campaign that used novel backdoors and familiar evasion techniques to maintain persistent access to regional targets.

    Read More China-Nexus Hackers Skulk in Southeast Asian Military Orgs for YearsContinue

  • Blog

    GlassWorm Malware Evolves to Hide in Dependencies

    Researchers have identified dozens of malicious GlassWorm extensions that come with new evasion techniques.

    Read More GlassWorm Malware Evolves to Hide in DependenciesContinue

  • Blog

    GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

    The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python repositories. “The attack targets Python projects — including Django apps, ML research code, Streamlit dashboards, and PyPI packages — by appending obfuscated code to files like setup.py, main.py, and app.py,”…

    Read More GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python ReposContinue

  • Blog

    ⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More

    Some weeks in security feel normal. Then you read a few tabs and get that immediate “ah, great, we’re doing this now” feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real fast. A few bits hit a little too close to real life, too. There’s…

    Read More ⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreContinue

  • Blog

    Attackers Abuse LiveChat to Phish Credit Card, Personal Data

    A social engineering campaign impersonating PayPal and Amazon uses customer support interactions to acquire sensitive info.

    Read More Attackers Abuse LiveChat to Phish Credit Card, Personal DataContinue

  • Blog

    Why Security Validation Is Becoming Agentic

    If you run security at any reasonably complex organization, your validation stack probably looks something like this: a BAS tool in one corner. A pentest engagement, or maybe an automated pentesting product, in another. A vulnerability scanner feeding an attack surface management platform somewhere else. Each tool gives you a slice of the picture. None…

    Read More Why Security Validation Is Becoming AgenticContinue

  • Blog

    ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers

    Three different ClickFix campaigns have been found to act as a delivery vector for the deployment of a macOS information stealer called MacSync. “Unlike traditional exploit-based attacks, this method relies entirely on user interaction – usually in the form of copying and executing commands – making it particularly effective against users who may not appreciate…

    Read More ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool InstallersContinue

  • Blog

    DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage

    Ukrainian entities have emerged as the target of a new campaign likely orchestrated by threat actors linked to Russia, according to a report from S2 Grupo’s LAB52 threat intelligence team. The campaign, observed in February 2026, has been assessed to share overlaps with a prior campaign mounted by Laundry Bear (aka UAC-0190 or Void Blizzard)…

    Read More DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth EspionageContinue

Page navigation

Previous PagePrevious 1 … 4 5 6 7 8 … 416 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us