Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. “The attack chain begins with a fake CAPTCHA page and

    Read More Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser CredentialsContinue

  • Blog

    Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

    Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

    Read More Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web ShellsContinue

  • Blog

    Zero Trust for AI Agents Starts With Fixing Zero Visibility

    The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an…

    Read More Zero Trust for AI Agents Starts With Fixing Zero VisibilityContinue

  • Blog

    Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

    Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8…

    Read More Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted LinkContinue

  • Blog

    SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows – CVE-2026-65660 (CVSS score: 8.8) – A code injection vulnerability in Microsoft Office SharePoint

    Read More SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the WildContinue

  • Blog

    Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

    Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. “Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” said Frank Balonis,…

    Read More Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber AttackContinue

  • Blog

    AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

    When autonomous AI agents “escape the sandbox,” the real story isn’t rogue machines — it’s the same access-control failures we’ve seen for decades.

    Read More AI Sandbox Escapes: Why Forensic Readiness Matters More Than ContainmentContinue

  • Blog

    What We Missed: Google Gemini Joins the AI Escape Party

    In this video conversation, Dark Reading editors discuss some of the news they didn’t get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.

    Read More What We Missed: Google Gemini Joins the AI Escape PartyContinue

  • Blog

    Stopping IT Worker Scams Requires Revamped HR Process

    Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.

    Read More Stopping IT Worker Scams Requires Revamped HR ProcessContinue

  • Blog

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below – actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: “Access to this

    Read More Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud MalwareContinue

Page navigation

1 2 3 … 604 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us