Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

    Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should’ve patched years ago. Good times. Phishing crews are getting smarter too –…

    Read More ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosContinue

  • Blog

    Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

    Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Ghost’s Content API that could allow an unauthenticated attacker to read…

    Read More Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix AttacksContinue

  • Blog

    The Alert Firehose Finally Meets Its Match

    Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear “Noisy,” “Too much data.” But ask the teams running NDR that includes agentic AI capabilities and you’ll hear they’re actually using it to catch threats earlier, triage faster, and chase fewer false positives. The old complaint lingers in part because…

    Read More The Alert Firehose Finally Meets Its MatchContinue

  • Blog

    Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

    Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader. “DPAPILoader decrypts and

    Read More Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto FirmsContinue

  • Blog

    TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

    A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 2026, at 8:20 p.m. UTC, with new packages published to the ecosystems in waves…

    Read More TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIOContinue

  • Blog

    npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

    GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor…

    Read More npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain AttacksContinue

  • Blog

    Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

    A new “coordinated” supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. “Although the affected packages were all Composer packages, the malicious code was not added to composer.json,” Socket said. “Instead, it was inserted into package.json, targeting projects that…

    Read More Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux MalwareContinue

  • Blog

    Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

    Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most “systemically” important software across the world since the cybersecurity initiative went live last month. Project Glasswing is an effort led by the artificial intelligence (AI) company, as part of which a small set…

    Read More Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used SoftwareContinue

  • Blog

    Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

    Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include – laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes laravel-lang/actions “The timing and pattern of the newly published tags

    Read More Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential StealerContinue

  • Blog

    LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

    A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions. “Any cPanel user (including an attacker or a compromised account)…

    Read More LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as RootContinue

Page navigation

1 2 3 … 474 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us