Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

    ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery…

    Read More ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 FilesContinue

  • Blog

    New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

    Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic…

    Read More New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for EspionageContinue

  • Blog

    CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization

    Read More CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVContinue

  • Blog

    Agentic AI Is Untamable: Ask the Right Security Questions

    Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.

    Read More Agentic AI Is Untamable: Ask the Right Security QuestionsContinue

  • Blog

    1M+ Emails Use Hidden Text to Dupe AI Security Filters

    Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.

    Read More 1M+ Emails Use Hidden Text to Dupe AI Security FiltersContinue

  • Blog

    Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

    Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority’s employees into an office to get their…

    Read More Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL HackContinue

  • Blog

    ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

    A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak defaults are earning their keep, and some…

    Read More ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesContinue

  • Blog

    n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

    n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in…

    Read More n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another IssuerContinue

  • Blog

    New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

    Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026. “The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in a technical report. “While the number of C2 [command-and-control] domains is currently small, the daily

    Read More New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run CommandsContinue

  • Blog

    New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

    ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and quietly exits. At the next…

    Read More New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their PasswordContinue

Page navigation

Previous PagePrevious 1 … 68 69 70 71 72 … 597 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us