HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 1359 篇文章,第 40 / 46 页

2026-05-05BleepingComputer
New Quasar Linux Malware Targets Developers with Rootkit and Backdoor Features

Security researchers have uncovered a previously undocumented Linux implant, dubbed Quasar Linux (QLNX), that is actively targeting software developers. Discovered during an invest...

MalwareAPTSupply Chain
Read More → Use Tool →
2026-05-05BleepingComputer
Instructure Breach: Hacker Claims 280M Records from 8,800 Schools

Education technology provider Instructure has disclosed a significant data breach after a threat actor operating under the alias 'CSAMKing' claimed to have stolen approximately 280...

Data BreachPrivacyThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
DAEMON Tools Backdoor Attack: Supply Chain Compromise

On April 8, 2026, Disc Soft Ltd. confirmed that the official DAEMON Tools Pro installer (version 8.0.0.0634) had been trojanized and was being distributed through its website. The ...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
Student Arrested for Hacking Taiwan High-Speed Rail, Triggering Emergency Brakes

On 12 March 2026, Taiwanese authorities arrested a 23‑year‑old university student for allegedly compromising the TETRA (Terrestrial Trunked Radio) communication network that underp...

VulnerabilityIncident ResponseThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
FTC Bans Kochava from Selling US Location Data Without Consent

The Federal Trade Commission announced a settlement with data broker Kochava and its subsidiary Collective Data Solutions (CDS) that prohibits them from selling or sharing precise ...

PrivacyRegulation
Read More → Use Tool →
2026-05-05BleepingComputer
EOL Open Source Risks: CVE Feed Gaps Exposed

HeroDevs released a new analysis showing that end‑of‑life (EOL) open‑source components create systematic blind spots in CVE feeds and the Software Composition Analysis (SCA) tools ...

VulnerabilitySupply ChainZero-Day
Read More → Use Tool →
2026-05-05BleepingComputer
Vimeo Data Breach Exposes 119,000 Users' Personal Information

The ShinyHunters extortion group has claimed responsibility for a significant data breach at Vimeo, the popular online video platform owned by IAC. Security researchers first ident...

Data BreachPrivacy
Read More → Use Tool →
2026-05-05BleepingComputer
Google Ups Android Exploit Bounties to $1.5M

Google announced a major overhaul of its Android and Chrome vulnerability reward programs, raising the maximum payout to $1.5 million for the most sophisticated exploit chains targ...

Bug BountyZero-Day
Read More → Use Tool →
2026-05-05BleepingComputer
Latvian Gets 8.5 Years for Karakurt Ransomware Negotiator Role

A Latvian national was sentenced on Friday to 8.5 years in a U.S. federal prison after being extradited to face charges related to his work as a "cold case" negotiator for the Russ...

RansomwareThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
CloudZ RAT Abuses Microsoft Phone Link to Steal SMS & OTPs

Security researchers have uncovered a new variant of the CloudZ remote‑access trojan (RAT) that delivers a previously undocumented plugin named Pheno. This plugin exploits the Micr...

MalwarePrivacyVulnerability
Read More → Use Tool →
2026-05-05BleepingComputer
ScarCruft APT37 Deploys BirdCall Android Malware via Game Platform

The North Korean threat group APT37, also tracked as ScarCruft, has been observed delivering an Android variant of its BirdCall backdoor through a supply‑chain compromise of a popu...

Supply ChainAPTMalware
Read More → Use Tool →
2026-05-05BleepingComputer
EOL Open-Source Software Exposes CVE Feed Gaps for SCA Tools

Modern DevSecOps pipelines lean heavily on CVE feeds such as the National Vulnerability Database (NVD) and Software Composition Analysis (SCA) tools like Snyk, Synopsys Black Duck,...

VulnerabilitySupply Chain
Read More → Use Tool →
2026-05-04The Hacker News
Phishing Campaign Exploits SimpleHelp and ScreenConnect RMM Tools in 80+ Orgs

Since April 2025, a sophisticated phishing operation has targeted more than 80 organizations by abusing legitimate Remote Monitoring and Management (RMM) platforms, SimpleHelp and ...

PhishingMalwareSupply Chain
Read More → Use Tool →
2026-05-04The Hacker News
Progress Patches Critical MOVEit Automation Authentication Bypass

Progress Software has released urgent updates for MOVEit Automation (formerly Central) that address two security flaws, the most severe of which is a critical authentication bypass...

VulnerabilityAuthentication
Read More → Use Tool →
2026-05-04The Hacker News
AI Phishing Surge, Android Spy Tool, Linux Zero-Day, GitHub RCE – Weekly Recap

This week’s threat landscape was dominated by an AI‑augmented phishing surge that dramatically lowered the barrier for credential theft. Researchers at Cisco Talos documented a cam...

PhishingZero-DayVulnerability
Read More → Use Tool →
2026-05-04The Hacker News
AI-Assisted Attack: 17-Year-Old Arrested for 7M User Data Breach

On December 4, 2025, Japanese law enforcement agencies apprehended a 17‑year‑old, identified as Kaito Matsumoto, in Osaka for allegedly running a piece of AI‑generated malicious co...

AI ThreatsData BreachMalware
Read More → Use Tool →
2026-05-04The Hacker News
Silver Fox ABCDoor Malware Hits India, Russia via Tax Phishing

The China-based advanced persistent threat (APT) group Silver Fox, also tracked as Monarch, SwimSnake, The Great Thief of Valley, UTG-Q-1000, and Void Arachne, has launched a sophi...

APTPhishingMalware
Read More → Use Tool →
2026-05-04The Hacker News
cPanel Zero-Day Exploit Targets Gov, MSP Networks

Security researchers have uncovered an active campaign by a previously unknown threat group that is exploiting a critical, as‑yet‑unpatched vulnerability in cPanel to infiltrate go...

Zero-DayAPTVulnerability
Read More → Use Tool →
2026-05-04The Hacker News
Global Police Bust: 276 Arrested, 9 Crypto Scam Centers Dismantled, $701M Seized

An international law enforcement coalition dubbed 'Operation Crypto Shield,' led by the FBI, Europol, and China's Ministry of Public Security, has achieved a landmark victory again...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-05-04Dark Reading
Cybercriminal Syndicates Exploit Supply Chain to Boost Physical Cargo Theft

Physical cargo theft is no longer the domain of opportunistic street gangs; it has morphed into a high‑tech enterprise orchestrated by transnational cybercriminal syndicates. Accor...

Supply ChainAPTThreat Intel
Read More → Use Tool →
2026-05-04Dark Reading
RMM Tools Exploited in Stealthy Phishing Campaign Targeting 80+ Orgs

Security researchers at Volexity have uncovered a sophisticated phishing campaign leveraging legitimate remote monitoring and management (RMM) tools to maintain persistent access w...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-05-04Dark Reading
cPanel Authentication Bypass Zero‑Day Exploit Threatens Millions

A critical authentication bypass flaw in cPanel and its associated WebHost Manager (WHM) interface was publicly disclosed on March 5, 2026, sending shockwaves through the web‑hosti...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-05-04Dark Reading
Silver Fox APT Targets India, Russia with Tax-Themed ABCDoor Attacks

Security researchers have uncovered a sophisticated campaign by the China-backed advanced persistent threat (APT) group Silver Fox, targeting organizations in India and Russia with...

APTMalwarePhishing
Read More → Use Tool →
2026-05-04Dark Reading
How Dark Reading Launched Cybersecurity Media Without Print in 2006

Twenty years ago, Dark Reading entered the cybersecurity media landscape without the traditional safety net of a print edition, proving that compelling content and editorial expert...

Threat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Zero-Day CVE-2026-22679 in Weaver E-Cology Exploited Since March

Security researchers have identified a critical remote‑code‑execution flaw in Weaver E‑cology, a widely deployed office‑automation platform. The vulnerability, tracked as CVE‑2026‑...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Kaspersky: Amazon SES Phishing Evades Email Security

Kaspersky researchers identified a surge in phishing campaigns leveraging Amazon Simple Email Service (SES). Attackers abuse the trusted infrastructure by sending emails via verifi...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Malicious PyTorch Lightning Package Steals AWS and Browser Credentials

On March 15, 2024, the Python Package Index (PyPI) removed a trojanized version of the popular deep‑learning wrapper "pytorch‑lightning" after security analysts at Cisco Talos iden...

MalwareSupply ChainCloud Security
Read More → Use Tool →
2026-05-04BleepingComputer
Trellix Data Breach Exposes Source Code - What You Need to Know

Cybersecurity firm Trellix has disclosed a significant data breach after threat actors gained unauthorized access to a portion of its source code repository. The incident, discover...

Data BreachSupply ChainThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Amazon SES Phishing Surge: Evading Standard Security Filters

Amazon Simple Email Service (SES), the cloud‑based email sending platform offered by Amazon Web Services, is increasingly being weaponized by threat actors to distribute phishing e...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Credit Union Loan Fraud: Stolen Identity Verification Exposed

Fraudsters are not breaking into credit unions with zero‑days or ransomware; they are exploiting the normal loan origination workflow. Flare’s threat‑intelligence team uncovered a ...

AuthenticationThreat IntelPrivacy
Read More → Use Tool →