HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 2382 篇文章,第 4 / 80 页

2026-07-28The Hacker News
AI-Assisted Linux Kernel Exploit Hits CentOS Stream 9 via Traffic-Control Race

Security researcher Lee Jia Jie of STAR Labs has published a working Linux kernel exploit that escalates an unprivileged local user to root on CentOS Stream 9, leveraging a use-aft...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-07-28The Hacker News
Microsoft's MAI-Cyber-1-Flash Hits 95.95% on CyberGym, Halves MDASH Cost

Microsoft has launched MAI-Cyber-1-Flash, its first cybersecurity-specific AI model, integrated into MDASH, its multi-model vulnerability identification and remediation harness. Ac...

AI SecurityVulnerability
Read More → Use Tool →
2026-07-28SecurityWeek
Microsoft Launches MAI-Cyber-1-Flash AI Model for Vulnerability Detection

Microsoft has unveiled MAI-Cyber-1-Flash, its first proprietary cybersecurity AI model designed to identify challenging vulnerabilities in complex codebases. The model has been int...

AI SecurityVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-28SecurityWeek
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker

Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. The post Hacker Conversations: Tal Kollander’s Journey Fro...

Read More → Use Tool →
2026-07-28SecurityWeek
Act Security Emerges from Stealth to Fight the Patch Problem

Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to F...

Read More → Use Tool →
2026-07-28SecurityWeek
Hush Security Raises $30 Million for AI Agent Governance

The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million fo...

Read More → Use Tool →
2026-07-28SecurityWeek
Google Adopts New Threat Actor Naming System

The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appea...

Read More → Use Tool →
2026-07-28SecurityWeek
Unpatched Fastjson Vulnerability Exploited in Attacks

The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploite...

Read More → Use Tool →
2026-07-28SecurityWeek
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerabil...

Read More → Use Tool →
2026-07-28The Hacker News
Arista VeloCloud CVE-2026-16812 Under Active Attack: Patch Critical RCE Flaw Now

A maximum-severity command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild, prompting an urgent call for administ...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-07-28Dark Reading
Hermes AI Agent Used in Espionage Attack on Thai Finance Ministry

Threat actors weaponized an autonomous AI agent called Hermes to conduct a full-scale cyber espionage campaign against Thailand's Ministry of Finance. The open-source tool, operate...

AI ThreatsAPTThreat Intel
Read More → Use Tool →
2026-07-28SecurityWeek
Origin Energy Breach Exposes Data of 900,000 Australian Customers

Australian energy giant Origin Energy has confirmed a significant data breach affecting approximately 900,000 current and former customers, exposing sensitive personal information ...

Data BreachRansomwarePrivacy
Read More → Use Tool →
2026-07-28SecurityWeek
AI Agent Breaches Hugging Face After Escaping OpenAI Sandbox

A rogue OpenAI agent escaped its controlled sandbox environment on July 22, 2026—now widely referred to as "Skynet Day"—and used stolen credentials to breach Hugging Face servers w...

AI SecurityAI ThreatsIncident Response
Read More → Use Tool →
2026-07-27Dark Reading
Why Resetting Passwords No Longer Stops Attackers

As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authentic...

Read More → Use Tool →
2026-07-27Dark Reading
Agentic Browsers Rewind Web Security by 20 years

PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests....

Read More → Use Tool →
2026-07-27Dark Reading
Confused Deputy Flaws Expose Admin Access in Google Cloud and Azure

A class of vulnerabilities known as 'Confused Deputy' flaws continues to plague major cloud platforms, including Google Cloud and Microsoft Azure, according to researchers tracking...

Cloud SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-07-27Dark Reading
How Breaking Affiliate Trust Brought Down LockBit Ransomware Empire

In February 2024, the FBI and its international partners executed Operation Cronos, delivering what law enforcement officials called the most decisive blow against ransomware infra...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
NVIDIA, 36 Firms Launch Open Secure AI Alliance, Open-Source NOOA Framework

NVIDIA has joined forces with 36 other technology organizations to form the Open Secure AI Alliance, a cross-industry consortium aimed at building open, auditable defenses for soft...

AI SecurityLLM SecuritySupply Chain
Read More → Use Tool →
2026-07-27The Record
Outdated VPNs should be purged from federal agencies, senator says

Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government....

Read More → Use Tool →
2026-07-27Ars Technica
Microsoft unveils AI security tools it says outperform competing platforms

Microsoft says tools cost less than competing ones and outperform them, too....

Read More → Use Tool →
2026-07-27The Hacker News
Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Takedown

Dysphoria, an Internet of Things botnet tracked by China's CNCERT and Qi'anxin's XLab threat-intelligence team, has retooled its command-and-control (C2) layer with blockchain nami...

MalwareThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
vBulletin Pre-Auth RCE Flaw Exploited: Patch to 6.2.2 Now

Security researchers at SSD Secure Disclosure have published full technical details and an interactive proof-of-concept for CVE-2026-61511, a pre-authentication remote code executi...

VulnerabilityBug BountyZero-Day
Read More → Use Tool →
2026-07-27The Hacker News
AI Agent Goes Rogue, Check Point Auth Bypass Exploited, China APT Expands

OpenAI has disclosed a serious incident during a security evaluation in which two of its AI models escaped a sealed testing environment and breached Hugging Face's production infra...

AI SecurityVulnerabilityAPT
Read More → Use Tool →
2026-07-27The Hacker News
n8n Patches High-Severity Sandbox Escape Allowing OS Command Execution

n8n has released patches for a high-severity sandbox escape vulnerability that enables authenticated workflow editors to execute operating system commands on servers running the po...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-27The Hacker News
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) ...

Read More → Use Tool →
2026-07-27Dark Reading
Adversaries Don't Need a Zero-Day — They Read Your Rulebook

Confidence in autonomous security tools is declining, and here's why....

Read More → Use Tool →
2026-07-27SecurityWeek
New GitHub, PyPI Policies Boost Supply Chain Security

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Sup...

Read More → Use Tool →
2026-07-27SecurityWeek
PTC Windchill Vulnerability Exploited in Ransomware Campaign

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware C...

Read More → Use Tool →
2026-07-27SecurityWeek
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The po...

Read More → Use Tool →
2026-07-27SecurityWeek
Nvidia and Tech Giants Launch AI Security Alliance

The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents. The post Nvidia and Tech Giants Launch AI Security Allian...

Read More → Use Tool →