HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 2382 篇文章,第 6 / 80 页

2026-07-24SecurityWeek
AegisAI Raises $36M Series A to Combat AI-Powered Phishing

Email security startup AegisAI has secured $36 million in a Series A funding round led by Battery Ventures, with participation from Accel and Foundation Capital. The raise brings t...

PhishingAI SecurityAI Threats
Read More → Use Tool →
2026-07-24The Record
UK Cyber Policy Continuity: Burnham Reappoints Lloyd Amid Ministry Overhaul

New UK Prime Minister Andy Burnham has reappointed Liz Lloyd to a junior ministerial post, retaining her cybersecurity portfolio despite a sweeping cabinet reshuffle that dissolved...

RegulationAPT
Read More → Use Tool →
2026-07-24The Record
Wrench Attacks on Crypto Holders Surge 33% in First Half of 2026

Cryptocurrency holders are increasingly being targeted through physical-world coercion rather than purely digital exploits, according to a new report from blockchain security audit...

Threat IntelPrivacyAuthentication
Read More → Use Tool →
2026-07-24The Hacker News
Hacker Uses Hermes AI Agent Unattended to Breach Thailand Finance Ministry

A threat actor deployed Nous Research's open-source Hermes assistant on a rented server, enabled its YOLO mode, and pointed it at Thailand's Ministry of Finance, where the agent au...

AI SecurityThreat IntelData Breach
Read More → Use Tool →
2026-07-24The Hacker News
Golden Chickens MaaS Unveils 4 New Malware Families Targeting Browsers

The operators behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families—TinyEgg, ChonkyChicken, a modularized variant of Chonk...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-07-24The Hacker News
Beyond AI Agent Visibility: Why Security Teams Must Enforce Least Privilege

AI agent security is rapidly maturing through a familiar enterprise cycle: adoption, visibility, and finally, control. But as organizations discover, enforcing least privilege for ...

AI SecurityAI ThreatsAuthentication
Read More → Use Tool →
2026-07-24The Hacker News
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found ...

Read More → Use Tool →
2026-07-24The Hacker News
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTOR...

Read More → Use Tool →
2026-07-24The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compr...

Read More → Use Tool →
2026-07-24Dark Reading
Europe's Multilingual Reality Exposes AI Security Gaps

The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language....

Read More → Use Tool →
2026-07-24SecurityWeek
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday

Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking...

Read More → Use Tool →
2026-07-24SecurityWeek
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.  The post Data Breach Confirmed After Australian Energy Giant Ori...

Read More → Use Tool →
2026-07-23The Hacker News
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of...

Read More → Use Tool →
2026-07-23Dark Reading
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message....

Read More → Use Tool →
2026-07-23Ars Technica
Forgot your Google password? Now you can log in with a selfie.

Google's selfie videos can be used for account access, AI Avatars, and age verification....

Read More → Use Tool →
2026-07-23The Hacker News
This Week in Cyber Threats: NPM Stealer, VS Code Backdoor & AI Prompt Injection

A wave of supply chain attacks dominated this week's threat landscape, with malicious packages and counterfeit developer tools targeting developers across platforms. An npm package...

Supply ChainMalwareAI Threats
Read More → Use Tool →
2026-07-23The Hacker News
Claude Cowork SharedRoot Flaw Lets AI Agent Escape VM and Access Mac Files

Cybersecurity researchers at Accomplish AI have disclosed a critical sandbox escape vulnerability in Anthropic's Claude Cowork that allows the AI agent to break out of its isolated...

AI SecurityVulnerabilityLLM Security
Read More → Use Tool →
2026-07-23The Hacker News
Chaos Ransomware Hides C2 Traffic Inside Headless Browsers

The Chaos ransomware group has adopted a novel technique to conceal its command-and-control communications, routing traffic through the victim's own Chrome or Edge browser using a ...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-23The Hacker News
China-Linked JadeProx Uses TriBack Loader in Multi-Region Attacks

Group-IB researchers have exposed a China-nexus threat cluster tracked as JadeProx after discovering an unprotected Alibaba Cloud server in the Singapore region in mid-April 2026. ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-23The Hacker News
How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instea...

Read More → Use Tool →
2026-07-23The Hacker News
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel...

Read More → Use Tool →
2026-07-23The Hacker News
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on...

Read More → Use Tool →
2026-07-23SecurityWeek
OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That C...

Read More → Use Tool →
2026-07-23SecurityWeek
Is Patching Dead? Vulnerability Management in the Post-Mythos Era

You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching D...

Read More → Use Tool →
2026-07-23SecurityWeek
Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared f...

Read More → Use Tool →
2026-07-23SecurityWeek
Abstract Raises $25 Million to Expand Composable Security Operations Platform

The latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appear...

Read More → Use Tool →
2026-07-23SecurityWeek
Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips...

Read More → Use Tool →
2026-07-23The Record
International alert spotlights Russia-linked attacks on Zimbra webmail

A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said....

Read More → Use Tool →
2026-07-23The Record
State Department imposes visa restrictions on foreign cyber scammers

Individuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio....

Read More → Use Tool →
2026-07-23The Record
Major Australian energy supplier confirms customer data compromised

Origin Energy said it was working to figure out how many Australians were affected by a recent data breach....

Read More → Use Tool →