HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 1271 篇文章,第 2 / 43 页

2026-06-15The Hacker News
WordPress Plugins Hacked: Hidden Backdoors Planted on 1.2M Sites

A coordinated supply chain attack compromised JavaScript files served by three popular WordPress plugins—PushEngage, OptinMonster, and TrustPulse—turning trusted scripts into vecto...

Supply ChainMalwareIncident Response
Read More → Use Tool →
2026-06-15The Hacker News
Sniper Dz PhaaS Platform Targets MENA Users with Fake Facebook Lures

Cybersecurity researchers at Group-IB have exposed a sprawling social engineering campaign operated through Sniper Dz, a turnkey phishing-as-a-service (PhaaS) platform dismantled l...

PhishingThreat IntelMalware
Read More → Use Tool →
2026-06-15The Hacker News
Palo Alto Networks PAN-OS GlobalProtect VPN Flaw Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability (CVSS 7.8) affecting the GlobalProtect VPN portal and gat...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-15SecurityWeek
Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang. The post Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges appear...

Read More → Use Tool →
2026-06-15SecurityWeek
Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems

The pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems.  The post Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems ...

Read More → Use Tool →
2026-06-15SecurityWeek
French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker

French officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign Tchap platform. The po...

Read More → Use Tool →
2026-06-15SecurityWeek
ShinyHunters Claims Council of Europe Hack

The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information. The post ShinyHunters Claims Council of E...

Read More → Use Tool →
2026-06-15SecurityWeek
FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service

The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses. The post FBI, Google Dismantle ‘Outsider ...

Read More → Use Tool →
2026-06-15SecurityWeek
Maine Disables Data Breach Portal Due to Fake Submissions

Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action. The post Maine Disables Data Breach Portal Due to Fake Submissions ...

Read More → Use Tool →
2026-06-14The Record
Belarus-linked hackers target Gmail accounts of Polish public figures and their families

Poland has warned that Ghostwriter, the Belarus-linked hacker group, has expanded its phishing operations to target personal Gmail accounts belonging to senior public figures and t...

Read More → Use Tool →
2026-06-14BleepingComputer
FBI Shuts Down Outsider Enterprise: AI Phishing Service with 1M+ URLs

The FBI, in coordination with Google and Black Lotus Labs, has dismantled a sprawling Chinese phishing-as-a-service operation known as Outsider Enterprise, responsible for 9,000 fa...

PhishingAI ThreatsIncident Response
Read More → Use Tool →
2026-06-13BleepingComputer
Ex-IT Worker Gets 21 Months in Prison for Cyberattacks on Iowa School District

Ezekiel Dean Potter, a 34-year-old former senior IT support specialist for Iowa's Saydel Community School District, has been sentenced to 21 months in federal prison for a sustaine...

AuthenticationIncident ResponseData Breach
Read More → Use Tool →
2026-06-13The Hacker News
Critical Splunk Enterprise Flaw Enables Unauthenticated RCE via PostgreSQL Sidecar

Splunk has rolled out emergency security patches for a critical vulnerability in Splunk Enterprise that allows remote attackers to execute arbitrary code without any authentication...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-06-13BleepingComputer
Operation Highland: Velvet Ant APT Spied on Air-Gapped Network for 10 Years

The Chinese state-linked espionage group "Velvet Ant" maintained undetected access to a large organization's critical infrastructure for an extraordinary 10 years, according to res...

APTAuthenticationThreat Intel
Read More → Use Tool →
2026-06-13SecurityWeek
NPM 12 to Block Dependency Scripts by Default to Curb Supply Chain Attacks

GitHub has announced that NPM 12, expected to release in July, will no longer execute dependency scripts by default, a significant security overhaul aimed at neutralizing the wave ...

Supply ChainMalware
Read More → Use Tool →
2026-06-13The Hacker News
U.S. Orders Anthropic to Halt Fable 5 and Mythos 5 Access for Foreign Users

Anthropic announced on Friday that it will abruptly disable its most advanced AI models, Claude Fable 5 and Mythos 5, for all users after the U.S. government issued an export contr...

AI SecurityRegulationLLM Security
Read More → Use Tool →
2026-06-13BleepingComputer
Anthropic Suspends Fable 5 and Mythos 5 Globally After US Export Control Order

Anthropic has pulled the plug on its two most powerful AI models, Fable 5 and Mythos 5, for every user worldwide after receiving a US government export control directive on June 12...

AI SecurityRegulationPrivacy
Read More → Use Tool →
2026-06-13SecurityWeek
Anthropic Takes Fable 5 and Mythos 5 Offline Over US Export Controls

Anthropic announced Friday that it has taken its latest artificial intelligence models, Fable 5 and Mythos 5, offline to comply with a directive from the Trump administration aimed...

AI SecurityRegulationAI Threats
Read More → Use Tool →
2026-06-12The Hacker News
400+ Arch Linux AUR Packages Hijacked in Atomic Arch Supply Chain Attack

In a sweeping supply chain attack dubbed Atomic Arch, threat actors compromised more than 400 packages in the Arch User Repository (AUR) between June 11 and June 12, rewriting buil...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-06-12The Hacker News
Google Sues Chinese Smishing Network for Weaponizing Gemini AI

Google has filed a federal lawsuit in Manhattan against a Chinese cybercrime operation it accuses of abusing its Gemini AI assistant to power a large-scale smishing campaign target...

PhishingAI ThreatsRegulation
Read More → Use Tool →
2026-06-12The Hacker News
China-Linked Velvet Ant APT Backdoored Linux Login Software for a Decade

A China-nexus advanced persistent threat tracked as Velvet Ant by incident response firm Sygnia maintained covert access to a target network for nearly a decade by compromising the...

APTAuthenticationSupply Chain
Read More → Use Tool →
2026-06-12BleepingComputer
Maine Pulls Breach Portal Offline After Fake VRChat and Discord Disclosures

The Maine Attorney General's Office has temporarily disabled public access to its state-run data breach notification portal after fraudulent breach reports impersonating VRChat and...

Data BreachRegulationIncident Response
Read More → Use Tool →
2026-06-12BleepingComputer
Critical phpBB Auth Bypass Flaw Unpatched for 10 Years Exposes Admin Accounts

Security researchers at application security firm Aikido have disclosed a severe authentication bypass vulnerability in phpBB, the widely used open-source forum platform, that h...

AuthenticationVulnerabilityBug Bounty
Read More → Use Tool →
2026-06-12Dark Reading
ShinyHunters Exploit Oracle Zero-Day in Major University Data Breach

ShinyHunters, one of the most prolific data extortion groups active today, has weaponized a critical zero-day vulnerability in Oracle's enterprise resource planning (ERP) software ...

Zero-DayData BreachVulnerability
Read More → Use Tool →
2026-06-12The Hacker News
Agentjacking Attack Exploits Sentry MCP to Hijack AI Coding Agents

Cybersecurity researchers at Tenet Security have uncovered a new attack class dubbed “Agentjacking” that tricks AI coding agents into executing arbitrary code on developer machines...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-12BleepingComputer
Conti Ransomware Operator Pleads Guilty to Wire Fraud Conspiracy

A Ukrainian national extradited from Ireland to the United States has pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation, the U.S. Dep...

RansomwareMalwareData Breach
Read More → Use Tool →
2026-06-12BleepingComputer
400+ Arch Linux AUR Packages Compromised to Push eBPF Rootkit and Infostealer

More than 400 packages in the Arch User Repository (AUR) have been compromised to distribute a Linux rootkit and infostealer malware designed to harvest developer credentials, acce...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-12BleepingComputer
Early Supply-Chain Attack Warning Signs Hidden in Dark Web Forums

Supply-chain attacks rarely appear under their real name in underground forums. Long before a malicious package, compromised update, or breached vendor makes headlines, the precurs...

Supply ChainThreat IntelData Breach
Read More → Use Tool →
2026-06-12Dark Reading
Anthropic's Claude Mythos 5 & Fable 5: What Security Teams Need to Know

Anthropic has clarified the distinction between its latest large language model releases, confirming that Claude Mythos 5 does not represent a fundamental shift in the security pos...

AI SecurityLLM SecurityRegulation
Read More → Use Tool →
2026-06-12SecurityWeek
Google Cybersecurity Layoffs, $400M Coupang Fine & LiteLLM Patch

This week in cybersecurity saw a wave of high-impact developments spanning government accountability, corporate breaches, and AI security. A former IBM cybersecurity executive has ...

Data BreachRegulationAI Security
Read More → Use Tool →