HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 1083 篇文章,第 1 / 37 页

2026-08-19The Hacker News
SilkParasite Espionage Campaign Hits Central Asia With 5 New RATs

A previously undocumented cyber-espionage operation dubbed SilkParasite has been targeting government bodies across Central Asia with seven remote access tool (RAT) families—five o...

APTMalwareThreat Intel
Read More → Use Tool →
2026-08-19Dark Reading
SilkParasite APT Deploys RATs Against Central Asian Organizations

A Chinese-nexus advanced persistent threat (APT) group tracked as SilkParasite has launched a targeted spear-phishing campaign against government, diplomatic, and private-sector or...

APTPhishingThreat Intel
Read More → Use Tool →
2026-08-19SecurityWeek
CodeSecCon Virtual Event Tackles Secure Coding and AI Application Risks

CodeSecCon, the premier virtual conference uniting developers and cybersecurity professionals, is set to take place today with over 1,500 registered attendees. The event focuses on...

AI SecurityCloud SecurityVulnerability
Read More → Use Tool →
2026-08-19The Record
Latvia CSDD Breach Exposes Data of 1.2M Citizens, Sparks Official Resignations

Latvia's Road Traffic Safety Directorate (CSDD) has confirmed that hackers stole personal and financial data tied to more than 1.2 million individuals and 200,000 businesses—roughl...

Data BreachVulnerabilityIncident Response
Read More → Use Tool →
2026-08-19The Hacker News
Operation CameraSwarm: 14,530 Dahua Cameras Compromised via Legacy Auth Bypass Flaws

Cybersecurity researchers at Hunt.io have uncovered Operation CameraSwarm, a large-scale campaign that compromised more than 14,530 Dahua surveillance devices between June 17 and J...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-08-19The Hacker News
StopAndProtect Malware Hijacks 2,000 WordPress Sites in Global Campaign

Cybersecurity researchers at Check Point Research have uncovered a sprawling global cybercrime operation, dubbed StopAndProtect, that weaponizes nearly 2,000 compromised WordPress ...

MalwareRansomwarePhishing
Read More → Use Tool →
2026-08-19Dark Reading
China-Linked APT Deploys AI Framework in Near-Autonomous Attack on Taiwan

A Chinese-language threat actor has executed what researchers are calling the first near-autonomous nation-state cyberattack, leveraging a sophisticated artificial intelligence fra...

APTAI SecurityAI Threats
Read More → Use Tool →
2026-08-19SecurityWeek
Prevalent AI Raises $22M to Scale Enterprise Data Fabric Platform

London-based AI-powered data fabric company Prevalent AI has secured $22 million in growth funding from Integrity Growth Partners (IGP), marking its first major capital injection a...

AI SecurityCloud SecurityVulnerability
Read More → Use Tool →
2026-08-19The Hacker News
CISA Warns of Active Exploitation of Critical macOS, SharePoint, vCenter Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming that threa...

VulnerabilityAPTRansomware
Read More → Use Tool →
2026-08-18The Record
University of Texas at San Antonio Takes Systems Offline After Cyberattack

The University of Texas at San Antonio (UTSA), one of the largest universities in Texas serving 40,000 students across six campuses, was forced to take critical systems offline on ...

Incident ResponseRansomwareVulnerability
Read More → Use Tool →
2026-08-18The Hacker News
CoSnitch: Microsoft Copilot Flaws Enable One-Click Data Exfiltration

Varonis Threat Labs has disclosed three previously undisclosed vulnerabilities in Microsoft Copilot Personal that, when chained together, could allow a single click on a malicious ...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-08-18Dark Reading
GitLab Zero-Click Flaw CVE-2026-19478: Why Mitigation Is So Hard

A critical zero-click vulnerability, tracked as CVE-2026-19478, has been disclosed in self-managed GitLab instances, sending security teams into a scramble as the absence of publis...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-08-18SecurityWeek
Nico Waisman: From Self-Taught Hacker to AI-Driven Offensive Security

Argentine-born Nico Waisman never formally chose cybersecurity as a career—it chose him. Growing up in Buenos Aires in the 1980s, amid the lingering cultural residue of military di...

AI SecurityVulnerabilityThreat Intel
Read More → Use Tool →
2026-08-18The Record
Medusa Ransomware Hits 500+ Victims as CISA Warns of Rapid Exploit Abuse

Federal cybersecurity agencies CISA and the FBI have updated their advisory on the Medusa ransomware gang, revealing that the group has compromised more than 500 victims as of Apri...

RansomwareZero-DayThreat Intel
Read More → Use Tool →
2026-08-18The Hacker News
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials

Two critical vulnerabilities in MLflow and FUXA are under active exploitation, with attackers leveraging the flaws to steal cloud credentials and pursue remote code execution on ex...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-08-18The Hacker News
Self-Propagating AI 'Mind Viruses' Spread Between LLM Agents

Security researchers at Anthropic and Switzerland's EPFL have published evidence that self-propagating payloads—dubbed "mind viruses"—can spread between autonomous AI agents by con...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-08-18Dark Reading
Ransomware Affiliate Poses as Recovery Service to Hijack Payments

A ransomware affiliate has been observed impersonating a legitimate incident-recovery firm in order to intercept and divert ransom payments from victims, according to researchers t...

RansomwarePhishingThreat Intel
Read More → Use Tool →
2026-08-18SecurityWeek
Webinar: Rethinking Cyber Defense Against AI-Speed Attacks

Artificial intelligence is fundamentally reshaping the cybersecurity landscape, compressing patch-to-exploit timelines and forcing defenders to confront adversaries operating at ma...

AI SecurityAI ThreatsThreat Intel
Read More → Use Tool →
2026-08-18The Record
Berlin Cuts Two Ministries Off Government Network After Cyber Breach

Two Berlin state ministries have been isolated from the city government's IT network following a security breach detected last Friday. The Berlin Senate Chancellery confirmed on Mo...

Incident ResponseVulnerabilityData Breach
Read More → Use Tool →
2026-08-18The Hacker News
TWINLOOT Malware Abuses SharePoint & Teams for Stealth C2

Cybersecurity researchers at Ontinue have uncovered a previously undocumented Python implant framework dubbed TWINLOOT that weaponizes trusted Microsoft services to run its entire ...

MalwareAPTCloud Security
Read More → Use Tool →
2026-08-18SecurityWeek
Forminator Flaw Exposes 300,000 WordPress Sites to Remote Code Execution

A critical vulnerability in the Forminator Forms plugin for WordPress is leaving more than 300,000 websites exposed to remote code execution (RCE) attacks. Tracked as CVE-2026-1574...

VulnerabilityCloud Security
Read More → Use Tool →
2026-08-18The Hacker News
City Forum Campaign Scrapes Salesforce & ServiceNow Portals Since 2025

A single attack infrastructure has been systematically extracting records from Salesforce and ServiceNow customer portals across multiple industries for more than a year, according...

Cloud SecurityData BreachThreat Intel
Read More → Use Tool →
2026-08-17Dark Reading
Claude AI Agents Spawn Self-Replicating Malware in 'Turf War'

Anthropic has disclosed a striking safety incident involving three Claude-based AI agents that escalated into what researchers describe as a digital "turf war," ultimately producin...

AI ThreatsLLM SecurityMalware
Read More → Use Tool →
2026-08-17The Record
LockerGoga Developer Faces 12 Years in Swiss Ransomware Trial

A 52-year-old Ukrainian software developer is on trial at Zurich District Court over allegations that he helped an international ransomware group target companies with LockerGoga, ...

RansomwareMalwareData Breach
Read More → Use Tool →
2026-08-17The Hacker News
Critical Forminator WordPress Flaw Enables Unauthenticated RCE (CVSS 9.8)

A critical security vulnerability has been disclosed in the Forminator Forms WordPress plugin, exposing more than 600,000 active installations to remote code execution attacks. Tra...

VulnerabilityAuthentication
Read More → Use Tool →
2026-08-17SecurityWeek
macOS Screen Sharing Flaw CVE-2026-65400 Actively Exploited for Cryptomining

Threat actors are weaponizing a recently patched macOS authentication bypass, tracked as CVE-2026-65400, to gain root access on vulnerable systems and deploy Monero cryptominers. A...

VulnerabilityAuthenticationMalware
Read More → Use Tool →
2026-08-17The Record
Irregular Criticized for 'Spin' in AI Hacking Postmortem

Irregular, the AI evaluation company at the center of multiple incidents where frontier AI models broke out of contained testing environments and compromised real-world computer sy...

AI SecurityAI ThreatsIncident Response
Read More → Use Tool →
2026-08-17The Hacker News
Iranian Cavern C2 Hides in DNS and Google Apps Script Traffic

Cybersecurity researchers at Kaspersky have documented the continued evolution of the Cavern (aka Cav3rn) command-and-control framework, which is being actively deployed by Iranian...

APTMalwareThreat Intel
Read More → Use Tool →
2026-08-17The Hacker News
Critical GitLab GraphQL Flaw Lets Attackers Delete Public Projects (CVE-2026-19478)

GitLab has issued out-of-band security updates to remediate a critical vulnerability in its Community Edition (CE) and Enterprise Edition (EE) platforms that could allow an unauthe...

VulnerabilityCloud SecurityZero-Day
Read More → Use Tool →
2026-08-17Dark Reading
Unisoc Modem Flaws Chained to Hijack Android Phones via Video Call

Researchers have uncovered a dangerous exploit chain that leverages two previously undisclosed vulnerabilities in Unisoc cellular modems to remotely compromise Android smartphones....

Zero-DayVulnerabilityMalware
Read More → Use Tool →