Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

    Cybersecurity researchers have disclosed details of a new method for exfiltrating sensitive data from artificial intelligence (AI) code execution environments using domain name system (DNS) queries. In a report published Monday, BeyondTrust revealed that Amazon Bedrock AgentCore Code Interpreter’s sandbox mode permits outbound DNS queries that an attacker can exploit to enable interactive shells

    Read More AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCEContinue

  • Blog

    Warlock Ransomware Group Augments Post-Exploitation Activities

    In a recent attack, the group showcased stealthier cross-network activity, thanks to its use of a new BYOVD technique and other tools.

    Read More Warlock Ransomware Group Augments Post-Exploitation ActivitiesContinue

  • Blog

    LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader

    The ransomware operation known as LeakNet has adopted the ClickFix social engineering tactic delivered through compromised websites as an initial access method. The use of ClickFix, where users are tricked into manually running malicious commands to address non-existent errors, is a departure from relying on traditional methods for obtaining initial access, such as through stolen…

    Read More LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory LoaderContinue

  • Blog

    Inside Olympic Cybersecurity: Lessons From Paris 2024 to Milan Cortina 2026

    Discover how Franz Regul, former CISO for the Paris 2024 Olympics, tackled unique cybersecurity challenges to protect the Olympics from evolving threats.

    Read More Inside Olympic Cybersecurity: Lessons From Paris 2024 to Milan Cortina 2026Continue

  • Blog

    AI is Everywhere, But CISOs are Still Securing It with Yesterday’s Skills and Tools, Study Finds

    A majority of security leaders are struggling to defend AI systems with tools and skills that are not fit for the challenge, according to the AI and Adversarial Testing Benchmark Report 2026 from Pentera. The report, based on a survey of 300 US CISOs and senior security leaders, examines how organizations are securing AI infrastructure…

    Read More AI is Everywhere, But CISOs are Still Securing It with Yesterday’s Skills and Tools, Study FindsContinue

  • Blog

    Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

    North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim’s KakaoTalk desktop application to distribute malicious payloads to certain contacts. The activity has been attributed by South Korean threat intelligence firm Genians to a hacking group referred to as Konni. “Initial access was achieved through a spear-phishing…

    Read More Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate MalwareContinue

  • Blog

    CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Wing FTP to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2025-47813 (CVSS score: 4.3), is an information disclosure vulnerability that leaks the installation path of the application under certain conditions

    Read More CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server PathsContinue

  • Blog

    China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years

    Researchers uncovered an extensive cyberespionage campaign that used novel backdoors and familiar evasion techniques to maintain persistent access to regional targets.

    Read More China-Nexus Hackers Skulk in Southeast Asian Military Orgs for YearsContinue

  • Blog

    GlassWorm Malware Evolves to Hide in Dependencies

    Researchers have identified dozens of malicious GlassWorm extensions that come with new evasion techniques.

    Read More GlassWorm Malware Evolves to Hide in DependenciesContinue

  • Blog

    GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

    The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python repositories. “The attack targets Python projects — including Django apps, ML research code, Streamlit dashboards, and PyPI packages — by appending obfuscated code to files like setup.py, main.py, and app.py,”…

    Read More GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python ReposContinue

Page navigation

1 2 3 … 412 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us