Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    GigaWiper Lets Threat Actors Choose Their Own Destructive Attack

    A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.

    Read More GigaWiper Lets Threat Actors Choose Their Own Destructive AttackContinue

  • Blog

    ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More

    Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don’t file tickets. That’s the shape of this week. Trusted code turns on the people…

    Read More ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreContinue

  • Blog

    New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

    Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false “fact” about the user, hide the change, and quietly steer its answers in later sessions. When it…

    Read More New MemGhost Attack Plants Persistent False Memories in AI Agents Through One EmailContinue

  • Blog

    Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

    A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing

    Read More Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session TheftContinue

  • Blog

    Turning the Tables on Email Scammers With ‘ScamBuster’

    An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.

    Read More Turning the Tables on Email Scammers With ‘ScamBuster’Continue

  • Blog

    Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling

    Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what you were doing,…

    Read More Meta Files Patent for AI That Can Listen All Day and Track How You’re FeelingContinue

  • Blog

    Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

    A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped…

    Read More Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst CopilotsContinue

  • Blog

    Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

    Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. “The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success…

    Read More Attacker Uses Suspected AI-Generated PowerShell Script to Map Active DirectoryContinue

  • Blog

    Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

    An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse, French security firm Lexfo lifted the operator’s entire toolkit and pivoted through it to two…

    Read More Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365Continue

  • Blog

    iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below – CVE-2026-48939 – A vulnerability in the

    Read More iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysContinue

Page navigation

Previous PagePrevious 1 … 74 75 76 77 78 … 597 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us