HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 1359 篇文章,第 39 / 46 页

2026-05-06The Hacker News
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs

Security analysts have uncovered a sophisticated intrusion campaign leveraging the CloudZ remote access trojan (RAT) alongside a previously undocumented plugin called Pheno to targ...

MalwareAPTAuthentication
Read More → Use Tool →
2026-05-06The Hacker News
Palo Alto PAN-OS Flaw CVE-2026-0300 Under Active Exploitation

Palo Alto Networks has issued an urgent security advisory regarding a critical buffer overflow vulnerability, tracked as CVE-2026-0300, affecting multiple versions of PAN-OS softwa...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-05-06Dark Reading
VoidStealer Bypasses Chrome App-Bound Encryption: New Threat

Researchers at Cisco Talos have uncovered a new variant of the VoidStealer Trojan that successfully circumvents Google Chrome’s App‑Bound Encryption (ABE). The malware, tracked as ...

MalwareEncryptionZero-Day
Read More → Use Tool →
2026-05-06Dark Reading
Instructure Breach Exposes Canvas LMS Vendor Risks for Schools

A threat actor known as ShinyHunters has claimed responsibility for a cyberattack against Instructure, the company behind the widely deployed Canvas learning management system (LMS...

Data BreachSupply ChainVulnerability
Read More → Use Tool →
2026-05-06Dark Reading
From Stuxnet to ChatGPT: 20 Cyber Milestones

Over the past two decades, a succession of high‑impact incidents has reshaped the cyber risk landscape, forcing organizations to constantly recalibrate their defenses. From the rev...

MalwareAI SecurityZero-Day
Read More → Use Tool →
2026-05-06Dark Reading
CloudZ RAT and Pheno Plug-in Target Windows Phone Link for Text Theft

Security researchers have uncovered a sophisticated cyberattack campaign leveraging the Windows Phone Link application to steal text messages and circumvent two-factor authenticati...

MalwareAuthenticationPrivacy
Read More → Use Tool →
2026-05-06Dark Reading
UAE Cyberattacks Triple, Critical Infrastructure at Risk

As the conflict with Iran intensifies, cyber operatives have turned their focus on the United Arab Emirates, with breach attempts spiking threefold over the past few weeks. Securit...

APTVulnerability
Read More → Use Tool →
2026-05-06BleepingComputer
Google Ads Abused in GoDaddy ManageWP Login Phishing Scam

A sophisticated phishing campaign is leveraging Google’s sponsored search ads to mimic the login page of ManageWP, GoDaddy’s platform for centrally managing large fleets of WordPre...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-05-06Dark Reading
New VoidStealer Bypass Exposes Chrome App-Bound Encryption Flaw

Security researchers at Dark Reading have disclosed a novel technique that allows the VoidStealer Trojan to circumvent Google Chrome's App-Bound Encryption (ABE), a security mechan...

MalwareEncryptionZero-Day
Read More → Use Tool →
2026-05-06BleepingComputer
Critical vm2 Sandbox Escape Bug Allows Host Code Execution

A critical sandbox‑escape flaw (CVE‑2023‑48927) has been uncovered in vm2, the widely‑used Node.js sandboxing library. The vulnerability, discovered by security researcher Alex Tsv...

Zero-DayVulnerabilitySupply Chain
Read More → Use Tool →
2026-05-06BleepingComputer
Cisco Patches Critical DoS Flaw in Crosswork, Manual Reboot Needed

Cisco has released patches for a high‑severity denial‑of‑service (DoS) vulnerability affecting its Crosswork Network Controller and Network Services Orchestrator (NSO) products. Tr...

VulnerabilityIncident Response
Read More → Use Tool →
2026-05-06BleepingComputer
DAEMON Tools Lite Supply Chain Attack: Malware-Free Version Released

Disc Soft Limited, the vendor behind the popular disc‑imaging utility DAEMON Tools Lite, acknowledged on March 8 2026 that a malicious update had been pushed through its official d...

MalwareSupply ChainData Breach
Read More → Use Tool →
2026-05-06BleepingComputer
Ransomware Targets Backup Systems Before Encryption: Acronis

Acronis researchers have documented a systematic shift in ransomware operations: before triggering encryption, threat actors now deliberately cripple backup infrastructure. Their 2...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-05-06BleepingComputer
MuddyWater Deploys Chaos Ransomware Decoy Using Microsoft Teams

MuddyWater, the Iranian advanced persistent threat (APT) group also tracked as Static Kitten, has been observed disguising its espionage operations behind a non‑functional Chaos ra...

APTRansomwarePhishing
Read More → Use Tool →
2026-05-06BleepingComputer
Webinar: Fix Triage, Enrichment & Coordination to Stop Incident Escalation

hackmyip.com will host a live webinar titled "Why Network Incidents Escalate and How to Fix Response Gaps" on March 15, 2025 at 2:00 PM EST. The session will feature Alex Rivera, s...

Incident ResponseThreat Intel
Read More → Use Tool →
2026-05-06BleepingComputer
Palo Alto Warns of Critical Zero‑Day RCE in PAN‑OS User‑ID Portal

Palo Alto Networks issued an emergency advisory on Tuesday warning customers that a critical, as‑yet‑unpatched remote‑code‑execution (RCE) flaw in the PAN‑OS User‑ID Authentication...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-05-05The Hacker News
Critical Apache HTTP/2 Flaw CVE-2026-23918 Enables DoS and RCE

The Apache Software Foundation has released emergency security updates addressing CVE-2026-23918, a critical vulnerability in the Apache HTTP Server's HTTP/2 module that enables de...

VulnerabilityZero-Day
Read More → Use Tool →
2026-05-05The Hacker News
DAEMON Tools Supply Chain Attack Distributes Malware via Official Installers

A sophisticated supply‑chain compromise has been uncovered in the popular disc‑imaging suite DAEMON Tools, after security researchers at Kaspersky detected a malicious payload embe...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-05-05The Hacker News
China-Linked UAT-8302 Hits South America Governments with Shared APT Malware

Security researchers have linked a newly tracked China‑nexus threat cluster, designated UAT‑8302, to a wave of cyber‑espionage operations targeting government agencies in South Ame...

APTMalwareThreat Intel
Read More → Use Tool →
2026-05-05The Hacker News
OAuth Token Exposure in AI Tools: Unclosed Backdoors Threaten Cloud Security

In the past twelve months, enterprises have rushed to embed AI‑powered writing assistants, workflow automations and productivity plugins into their Google Workspace and Microsoft 3...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-05-05The Hacker News
MetInfo CMS CVE-2026-29014 RCE Exploit Under Active Attack

Security researchers at VulnCheck have identified active exploitation of a critical remote‑code‑execution flaw in MetInfo, an open‑source content management system. The vulnerabili...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-05-05The Hacker News
1M Exposed AI Services Reveal Alarming Security Gaps

A joint research effort by the Security Research Lab (SRL) and the AI Security Initiative (AISI) scanned over one million publicly reachable AI endpoints across IPv4 space between ...

AI SecurityVulnerabilityPrivacy
Read More → Use Tool →
2026-05-05The Hacker News
ScarCruft Supply Chain Attack Injects BirdCall Malware into Gaming Platform

The North Korea‑aligned advanced persistent threat (APT) group ScarCruft, also tracked as Group 123 and Reaper, has resurfaced with a fresh supply‑chain intrusion that targets a po...

APTSupply ChainMalware
Read More → Use Tool →
2026-05-05The Hacker News
Weaver E-cology RCE CVE-2026-22679 Exploited via Debug API

Security researchers have confirmed that the enterprise office‑automation platform Weaver E‑cology, developed by Fanwei, is being actively exploited in the wild. The flaw, tracked ...

Zero-DayVulnerability
Read More → Use Tool →
2026-05-05The Hacker News
Microsoft Exposes Credential Theft Phishing Targeting 35K Users in 26 Countries

Microsoft’s Threat Intelligence Center (MSTIC) has released details of a large‑scale credential‑harvesting operation that successfully targeted roughly 35,000 users in 26 countries...

PhishingThreat IntelAPT
Read More → Use Tool →
2026-05-05Dark Reading
Trellix Source Code Breach Exposes Security Product Vulnerabilities

Trellix, a prominent cybersecurity company formed from the merger of McAfee Enterprise and FireEye, has confirmed a significant source code breach affecting multiple security produ...

Supply ChainData BreachThreat Intel
Read More → Use Tool →
2026-05-05Dark Reading
Berkeley CLTC Provides Cybersecurity Tools for Under-Resourced Entities

The UC Berkeley Center for Long-Term Cybersecurity (CLTC) has launched a dedicated research hub designed to bridge the cybersecurity gap for schools, local governments, and non‑pro...

Threat IntelIncident ResponseVulnerability
Read More → Use Tool →
2026-05-05Dark Reading
How Security Leadership Shapes Penetration Test Success

When Alex Rivera, "CISO of Globex Systems", commissioned a penetration test in Q3 2023, his first decision was to define a precise scope that included internal VLAN segmentation, c...

VulnerabilityIncident ResponseBug Bounty
Read More → Use Tool →
2026-05-05Dark Reading
Edge Password Leak in Process Memory Threatens Enterprise

A new proof‑of‑concept (PoC) published by security researcher Alex Chen of CyberX Labs shows that Microsoft Edge stores user passwords in plaintext within the browser’s process mem...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2026-05-05Dark Reading
USB Pen Test: Steve Stasiukonis' Viral Social Engineering Experiment

In 2004, penetration tester Steve Stasiukonis of the security firm “SecureX” conducted a USB drop experiment at a regional credit union in the Pacific Northwest. Armed with a batch...

VulnerabilityPhishingThreat Intel
Read More → Use Tool →