HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 2382 篇文章,第 1 / 80 页

2026-07-30The Hacker News
DPRK Hackers Use Fake macOS Updates to Steal Crypto via EtherHiding

North Korean-linked threat actors have been tied to a sophisticated macOS malvertising campaign that abuses fake software update screens to deliver cryptocurrency-stealing malware ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-30Dark Reading
Iran-Backed Hackers Target 30+ Minnesota Water Systems in Cyberattack

A suspected Iran-linked advanced persistent threat (APT) group has launched cyberattacks against more than 30 community water utilities across Minnesota, exposing deep vulnerabilit...

APTThreat IntelIncident Response
Read More → Use Tool →
2026-07-30Dark Reading
AI Harness Software Stacks Expose Hidden Exploit Vectors

Modern AI deployments rarely rely on a single model or framework. Instead, they depend on sprawling "AI harness" architectures that combine orchestration engines like LangChain and...

AI SecurityVulnerabilitySupply Chain
Read More → Use Tool →
2026-07-30SecurityWeek
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to ...

Read More → Use Tool →
2026-07-30SecurityWeek
Bank of America to Acquire Cybersecurity Firm MDSec

The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom. The post Bank of America to Acquire Cybersecurity Firm ...

Read More → Use Tool →
2026-07-30SecurityWeek
Okta to Acquire Identity Threat Detection Firm Permiso

The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection an...

Read More → Use Tool →
2026-07-30The Record
Semiconductor chip titan Analog Devices reports data breach

In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is s...

Read More → Use Tool →
2026-07-30Ars Technica
Chrome may get faster updates with no restart required

The last two versions of Chrome have included more patches than the previous 23 combined....

Read More → Use Tool →
2026-07-30The Hacker News
Weekly Cyber Threats: XWorm Phishing, GenieLocker Ransomware, CastleLoader Surge

Threat actors continue refining their tradecraft this week, blending social engineering with multi-stage loaders to compromise organizations across manufacturing, finance, and reta...

MalwareRansomwarePhishing
Read More → Use Tool →
2026-07-30The Hacker News
Azure Cosmos DB Flaw Exposed Master Key to Any Customer Database

A now-patched vulnerability in Microsoft Azure Cosmos DB could have granted attackers full read and write access to databases across customer tenants, according to cloud securit...

VulnerabilityCloud SecurityZero-Day
Read More → Use Tool →
2026-07-30The Hacker News
Microsoft Copilot Word Bug Lets Hidden Prompts Propagate Across Documents

Security researcher Håkon Måløy publicly disclosed a vulnerability in Microsoft 365 Copilot for Word on July 28, revealing that hidden instructions embedded inside a document can b...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-07-30The Hacker News
Check Point Launches AI Network Firewall to Close Enterprise Visibility Gap

Check Point Software Technologies has unveiled what it calls the industry's first AI Network Firewall, a new class of network security designed to inspect, detect, and govern AI-dr...

AI SecurityCloud Security
Read More → Use Tool →
2026-07-30KrebsOnSecurity
Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they sec...

Read More → Use Tool →
2026-07-30Dark Reading
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is ...

Read More → Use Tool →
2026-07-30SecurityWeek
Timeless Compliance: Why Better Questions Beat Bigger Frameworks

The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models ch...

Read More → Use Tool →
2026-07-30SecurityWeek
DataBahn Raises $40 Million for Agentic Data Pipeline Management

The company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline ...

Read More → Use Tool →
2026-07-30SecurityWeek
Cantina Emerges From Stealth With $8 Million in Funding

The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Milli...

Read More → Use Tool →
2026-07-30SecurityWeek
Discern Security Raises $13 Million in Series A Funding

The company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on Sec...

Read More → Use Tool →
2026-07-30SecurityWeek
Onyx Security Raises $113 Million to Control AI Agents in the Enterprise

The Series B funding round brings the total raised by Onyx Security to $153 million.  The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared fir...

Read More → Use Tool →
2026-07-30SecurityWeek
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale

Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. The post ‘DangleGeddon’: AI...

Read More → Use Tool →
2026-07-30The Record
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidenc...

Read More → Use Tool →
2026-07-30The Record
North Korean hackers behind major open-source supply chain attacks, Amazon says

A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found....

Read More → Use Tool →
2026-07-30The Record
Cyber extortionists steal data from UK Department for Education

Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the hackers said was more than 600,000 pieces of data allegedly including n...

Read More → Use Tool →
2026-07-30The Hacker News
AnySign4PC Zero-Day Exploited via Hacked Korean Sites to Plant Backdoors

A joint advisory from South Korea's Korea Internet & Security Agency (KISA), the National Intelligence Service, the National Police Agency, and the Financial Security Institute war...

APTZero-DayMalware
Read More → Use Tool →
2026-07-30The Hacker News
Silver Fox Deploys 3-Driver BYOVD Chain to Drop ValleyRAT in Japan

The Chinese-linked threat actor Silver Fox has been linked to a new campaign targeting a Japanese industrial manufacturer using a three-driver bring-your-own-vulnerable-driver (BYO...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-30The Hacker News
Laundry Bear APT Exploits OWA XSS Flaw to Retain Mailbox Access Post-Rotation

The Russia-linked threat cluster tracked as Laundry Bear (also known as CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) has been weaponizing a now-patched cross-site scripting ...

APTPhishingVulnerability
Read More → Use Tool →
2026-07-30The Hacker News
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new model...

Read More → Use Tool →
2026-07-30The Hacker News
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer ph...

Read More → Use Tool →
2026-07-30SecurityWeek
Semiconductor Firm Analog Devices Discloses Data Breach

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files. The post Semiconductor Firm Analog Devices Discloses Data Breach appeared...

Read More → Use Tool →
2026-07-30SecurityWeek
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms

Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rog...

Read More → Use Tool →