网络安全资讯
来自顶级安全媒体的最新动态
共 2382 篇文章,第 5 / 80 页
The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and us...
On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the sco...
Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and ...
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered....
Proofpoint researchers have uncovered a sophisticated crypter-as-a-service called Cruciferra that is enabling multiple unrelated cybercrime clusters to deliver remote access trojan...
Zscaler ThreatLabz has uncovered a sophisticated cyber espionage campaign attributed to an East Asia-linked threat actor targeting government entities across the Middle East. Detec...
GitHub has rolled out a new cooldown mechanism in Dependabot that forces the automated dependency-management tool to wait at least three days after a package release is published b...
Coca-Cola has confirmed that the recent ransomware attack on its dairy subsidiary Fairlife resulted in a data breach, with the Anubis ransomware group claiming to have stolen appro...
The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. The post Beelzebub Raises $3.4 Million for Hacker-Trapping Platf...
The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. The post What’s Hiding in Your Mob...
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harves...
Binary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5. The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls ...
In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network. The post DentaQuest Data Breach Potentially Impacts Over 23 Million People app...
Atlanta-based medical revenue cycle management company MCBS (Medical Computer Business Services) has disclosed that a September 2025 cyberattack compromised the personal data of mo...
A long-running malvertising campaign dubbed SourTrade is bypassing traditional detection by never delivering a complete malicious file over the network. Instead, the operation, doc...
Security researchers at ThreatBook and Imperva have confirmed in-the-wild exploitation of a critical remote code execution vulnerability in Fastjson, Alibaba's widely deployed Java...
Security researcher depthfirst published working exploit code on July 24 for a GitLab remote code execution flaw that GitLab quietly patched on June 10 without filing it as a secur...
A new investigation from CTM360, published via The Hacker News, reveals that insurance-focused phishing operations have evolved beyond traditional credential harvesting into real-t...
Threat actors affiliated with the Cl0p ransomware operation—tracked under aliases including Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest—are actively exploiting intern...
The operators behind the DevMan ransomware-as-a-service (RaaS) scheme continue to run a dedicated web platform that lets affiliates generate payloads, track earnings, and coordinat...
Rockwell Automation has released patches for four high-severity vulnerabilities in its Arena Simulation software, a discrete-event simulation tool used by organizations to model, v...
As ransomware attacks, supply chain compromises, and state-sponsored intrusions continue to escalate, corporate boards are increasingly recognizing cybersecurity as a strategic pri...
A rogue OpenAI-powered agent recently infiltrated Hugging Face, exploiting the platform's open infrastructure to operate outside its intended guardrails. The incident, reported by ...
The North Korean threat actor BlueNoroff has operationalized a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, according to...
Cybersecurity researchers at Zenity Labs have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents, codenamed AgentForger, that allowed a single phishing link to...
Security researchers H0j3n and Aniq Fakhrul have publicly released a working exploit, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certifica...
Two critical command-injection vulnerabilities in Bing Images allowed specially crafted SVG files to execute arbitrary code as NT AUTHORITY\SYSTEM on Microsoft's production image-p...
A critical security flaw in the Vatican's official prayer application has exposed the personal information of more than 700,000 users worldwide, raising serious concerns about data...
Microsoft has patched a critical configuration flaw in Azure Automation that, combined with a chain of code vulnerabilities, could have allowed attackers to take over identities be...
Varonis Threat Labs has uncovered a sophisticated infostealer dubbed Dolphin X that leverages an AI behavioral profiler to score and prioritize infected hosts based on user activit...