HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 1344 篇文章,第 28 / 45 页

2026-05-19Dark Reading
Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS

The SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution....

Read More → Use Tool →
2026-05-19The Record
Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

There is no evidence that the incident has recurred, but the flaw remains unexplained and has not been publicly acknowledged by the company....

Read More → Use Tool →
2026-05-19The Hacker News
Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN's Satori Thre...

Read More → Use Tool →
2026-05-19The Hacker News
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed Dir...

Read More → Use Tool →
2026-05-19The Hacker News
The New Phishing Click: How OAuth Consent Bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five ...

Read More → Use Tool →
2026-05-19The Hacker News
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC. "The Drupal Security Team ur...

Read More → Use Tool →
2026-05-19BleepingComputer
Microsoft plans to improve Windows 11 driver quality in 2026

Microsoft plans to raise the quality bar of Windows 11 drivers, as drivers "sit at the heart of every Windows experience" and connect the OS to the "silicon, components, and periph...

Read More → Use Tool →
2026-05-19BleepingComputer
Microsoft blames macOS update for undismissible Teams location prompts

Microsoft has confirmed user reports that the Teams team collaboration app is displaying non-dismissible location prompts on some macOS systems. [...]...

Read More → Use Tool →
2026-05-19BleepingComputer
New Shai-Hulud malware wave compromises 600 npm packages

Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign. [...]...

Read More → Use Tool →
2026-05-19BleepingComputer
7-Eleven confirms data breach claimed by the ShinyHunters gang

Convenience store chain giant 7-Eleven confirmed that its systems were breached in a cyberattack claimed by the ShinyHunters extortion group last month. [...]...

Read More → Use Tool →
2026-05-19BleepingComputer
Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation

Microsoft's total vulnerability count stayed steady in 2025, but critical flaws surged year over year. BeyondTrust breaks down why attackers are increasingly focused on privilege e...

Read More → Use Tool →
2026-05-19BleepingComputer
Webinar: The hidden bottlenecks in network incident response

IT teams are increasingly overwhelmed by alerts from disconnected systems, forcing responders to manually coordinate investigations during network incidents. This webinar explores ...

Read More → Use Tool →
2026-05-19Dark Reading
Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution

Dark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed t...

Read More → Use Tool →
2026-05-19The Record
UK regulator to require tech firms to tackle deepfakes, non-consensual intimate images

The regulator’s announcement said the change is being made due to the “urgent need to better protect women and girls online.”...

Read More → Use Tool →
2026-05-19The Record
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs

The company unsealed a legal case in U.S. District Court on Tuesday detailing the disruption of Fox Tempest — a popular service that has operated since May 2025 and provides cyberc...

Read More → Use Tool →
2026-05-19The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code...

Read More → Use Tool →
2026-05-19The Hacker News
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extensio...

Read More → Use Tool →
2026-05-19The Hacker News
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sen...

Read More → Use Tool →
2026-05-19BleepingComputer
Microsoft confirms patching issues in restricted Windows networks

Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates. [...]...

Read More → Use Tool →
2026-05-19The Hacker News
GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sen...

Read More → Use Tool →
2026-05-19The Hacker News
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the...

Read More → Use Tool →
2026-05-18Dark Reading
Is 2026 the Year AI Bills of Materials Get Real?

Understanding AI BOMs and where they fit into risk management for artificial intelligence....

Read More → Use Tool →
2026-05-18BleepingComputer
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers

More than 200 individuals were arrested for cybercrime activities during INTERPOL's Operation Ramz, which focused on the Middle East and North Africa. [...]...

Read More → Use Tool →
2026-05-18BleepingComputer
SHub macOS infostealer variant spoofs Apple security updates

A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. [...]...

Read More → Use Tool →
2026-05-18BleepingComputer
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees

Many employees already use shadow AI tools at work without security review. Adaptive Security breaks down how teams can build practical AI governance without adding friction for em...

Read More → Use Tool →
2026-05-18KrebsOnSecurity
CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several h...

Read More → Use Tool →
2026-05-18Dark Reading
Microsoft Exchange Zero-Day Under Attack, No Patch Available

CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes....

Read More → Use Tool →
2026-05-18Dark Reading
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments

The now patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence....

Read More → Use Tool →
2026-05-18Dark Reading
Shai-Hulud Worm Clones Spread After Code Release

The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale....

Read More → Use Tool →
2026-05-18Dark Reading
Boulevard of Broken Dreams: 2 Decades of Cyber Fails

From the MGM and Caesars fiasco and MOVEit's patch nightmare to epic business blunders and the jaded reality of living in a post-breach world, Dark Reading looks back at the mistak...

Read More → Use Tool →