HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 1305 篇文章,第 14 / 44 页

2026-06-03Dark Reading
Malicious Notifications Could Trick Google Gemini Users

A prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more....

Read More → Use Tool →
2026-06-03Dark Reading
Global Stock Exchange Hit by Monthslong Email Campaign

A threat actor got a near-continuous view into an influential finance executive's email inbox, thanks to clever use of legitimate, native Windows tools....

Read More → Use Tool →
2026-06-03SecurityWeek
Organizations Warned of Exploited Linux Kernel Vulnerability

An improper authentication bug allows attackers to escalate their privileges and escape containers. The post Organizations Warned of Exploited Linux Kernel Vulnerability appeared f...

Read More → Use Tool →
2026-06-03SecurityWeek
‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds

The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold. The post ‘HTTP/2 Bomb’ E...

Read More → Use Tool →
2026-06-03SecurityWeek
Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash

Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities. The post Microsoft Tries to Calm Legal Threat Fe...

Read More → Use Tool →
2026-06-03The Record
New cyber force would cost up to $11 billion to start, commission says

The military branch would take 12 to 18 months to get up and running and also include roughly 5,000 members of the National Guard and up to 6,000 civilians, according to the commis...

Read More → Use Tool →
2026-06-02Dark Reading
Zoom CISO: AI as a Security Enabler, Not Role-Replacer

Zoom CISO Sandra McLeod discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and her advice for aspiring cybersecurity...

Read More → Use Tool →
2026-06-02BleepingComputer
WeedHack Malware Hits 116,000+ Minecraft Systems in Global Infostealer Campaign

A large-scale malware-as-a-service operation dubbed WeedHack has infected more than 116,464 systems since January 2026 by targeting Minecraft players with trojanized mods, clients,...

MalwareThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
Google June 2026 Android Update Fixes 124 Flaws, One Actively Exploited

Google has rolled out its June 2026 Android security bulletin, addressing 124 vulnerabilities across the mobile operating system, including a high-severity privilege escalation fla...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
Russian Gamaredon APT Exploits WinRAR Flaw to Deploy GammaWorm Against Ukraine

Russian state-sponsored hacking group Gamaredon, officially linked to the Federal Security Service (FSB), has been exploiting a WinRAR path traversal vulnerability (CVE-2025-8088) ...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog Amid Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Oracle WebLogic Server flaw, tracked as CVE-2024-21182, to its Known Exploited Vulnerabil...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-06-02BleepingComputer
Microsoft Coreutils Brings Native Linux Commands to Windows at Build 2026

Microsoft announced at its Build 2026 developer conference the release of Coreutils for Windows, a package that delivers common Linux command-line utilities as native Windows appli...

Cloud SecuritySupply Chain
Read More → Use Tool →
2026-06-02BleepingComputer
OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models

OpenAI says it's rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, includi...

Read More → Use Tool →
2026-06-02BleepingComputer
Critical Kirki flaw exploited to hijack WordPress admin accounts

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to a...

Read More → Use Tool →
2026-06-02BleepingComputer
Over 116,000 Mincraft systems infected in WeedHack malware campaign

A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January. [...]...

Read More → Use Tool →
2026-06-02BleepingComputer
AI-built ransomware toolkit automates EDR evasion, AD discovery

A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions. [...]...

Read More → Use Tool →
2026-06-02Dark Reading
Zoom CISO: AI as Security Enabler, Not Role-Replacer

As Zoom's CISO, Sandra McLeod, discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and advice for aspiring cybersecur...

Read More → Use Tool →
2026-06-02Dark Reading
FBI-Flagged Phishing Kit Kali365 Expands Its Reach

Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing....

Read More → Use Tool →
2026-06-02Dark Reading
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks

A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware....

Read More → Use Tool →
2026-06-02Dark Reading
China Uses Dual-Method Cyberattack on Czech Orgs

China is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware....

Read More → Use Tool →
2026-06-02Dark Reading
Securing AI Agents Before They Go Rogue Is Next to Impossible

High-autonomy agents with broad permissions and unfettered access are a recipe for disaster, and enterprises need to act now before they become the next horror story....

Read More → Use Tool →
2026-06-02SecurityWeek
Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks

The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. The p...

Read More → Use Tool →
2026-06-02The Record
White House unveils pared-back AI executive order

The order notes that federal access to the models should be subject to “appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and non...

Read More → Use Tool →
2026-06-02BleepingComputer
Microsoft Exchange Online Outage Disrupts Email Delivery in North America and Germany

Microsoft is actively investigating a widespread service disruption affecting the mail flow pipeline for Exchange Online customers in North America and Germany. The incident, track...

Cloud SecurityIncident Response
Read More → Use Tool →
2026-06-02BleepingComputer
Hackers Steal Instagram Accounts Using AI-Generated Selfies to Bypass Meta Verification

Attackers have hijacked multiple high-value Instagram accounts by exploiting Meta's AI-powered support assistant, tricking it into transferring ownership using deepfake selfie vide...

AI ThreatsAuthenticationDeepfake
Read More → Use Tool →
2026-06-02The Hacker News
AI-Driven Exploitation Is Breaking Vulnerability Management in 2026

The window between vulnerability disclosure and indiscriminate exploitation has collapsed from days to hours, driven by AI-powered tooling that automates discovery, reproduction, a...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-02BleepingComputer
Why the browser is now the front line for AI security

AI-powered attacks and shadow AI adoption are creating new security risks inside the browser. Push Security explains why browser visibility is becoming critical for both threat det...

Read More → Use Tool →
2026-06-02BleepingComputer
CISA flags two-year-old Oracle flaw as actively exploited in attacks

CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploit...

Read More → Use Tool →
2026-06-02SecurityWeek
Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis

As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control. T...

Read More → Use Tool →
2026-06-02SecurityWeek
Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations. The pos...

Read More → Use Tool →