Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads….

    Read More Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersContinue

  • Blog

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger…

    Read More New CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensContinue

  • Blog

    Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

    Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to…

    Read More Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationContinue

  • Blog

    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. “This…

    Read More N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistContinue

  • Blog

    Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

    Read More Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsContinue

  • Blog

    Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

    A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer…

    Read More Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and InfostealerContinue

  • Blog

    ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

    ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU…

    Read More ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto WalletsContinue

  • Blog

    UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

    A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via…

    Read More UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS DataContinue

  • Blog

    AI-Generated Patches Fail Half the Time

    A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.

    Read More AI-Generated Patches Fail Half the TimeContinue

  • Blog

    New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

    WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

    Read More New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAPContinue

Page navigation

1 2 3 … 554 Next PageNext
Terms & Conditions
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us