HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

共 1272 篇文章,第 7 / 43 页

2026-06-09BleepingComputer
Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws

Today is Microsoft's June 2026 Patch Tuesday, with security updates for 200 flaws and three publicly disclosed zero-day vulnerabilities. [...]...

Read More → Use Tool →
2026-06-09BleepingComputer
Windows 11 KB5094126 & KB5093998 cumulative updates released

Microsoft has released Windows 11 KB5094126 and KB5093998 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]...

Read More → Use Tool →
2026-06-09BleepingComputer
XBOW tests Anthropic's Mythos Preview for offensive security

Anthropic's Mythos Preview was highly effective at finding vulnerability candidates, especially when analyzing source code. XBOW explores how the model performed across exploit dis...

Read More → Use Tool →
2026-06-09BleepingComputer
GitHub disables Microsoft repos pushing password-stealing malware

Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub, disrupting continuous integration pipelines. [...]...

Read More → Use Tool →
2026-06-09BleepingComputer
New Veeam vulnerability exposes backup servers to RCE attacks

Veeam has released security updates to patch a critical Backup & Replication security flaw that can be exploited to gain remote code execution (RCE) on domain-joined backup servers...

Read More → Use Tool →
2026-06-09Dark Reading
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs

Two separate campaigns target CVE-2025-8088, fixed last July, to conduct data theft and cyberespionage against military and government targets in Ukraine....

Read More → Use Tool →
2026-06-09SecurityWeek
Anthropic Launches Claude Fable 5: Mythos-Class AI With Cybersecurity Guardrails

The AI giant also announced that Project Glasswing partners are being given access to the upgraded Mythos 5. The post Anthropic Launches Claude Fable 5: Mythos-Class AI With Cybers...

Read More → Use Tool →
2026-06-09SecurityWeek
OpenSSL Patches High-Severity Vulnerability Found With AI

A total of 18 vulnerabilities have been patched in the latest OpenSSL releases, including many that were potentially discovered by AI. The post OpenSSL Patches High-Severity Vulner...

Read More → Use Tool →
2026-06-09SecurityWeek
Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation

Public LLM models with safeguards turned off can also build working exploits, increasing patch gap risks. The post Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creati...

Read More → Use Tool →
2026-06-09SecurityWeek
New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications

Atsign’s AI Architect applies cryptographic protections to agentic software development, aiming to prevent attackers from exploiting vulnerabilities by making application identitie...

Read More → Use Tool →
2026-06-09SecurityWeek
SAP Patches Critical NetWeaver, Commerce Vulnerabilities

The flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage. The post SAP Patches Critical NetWeaver, Commerce Vulnera...

Read More → Use Tool →
2026-06-09The Record
Hackers pose as women seeking romance to spy on Russian soldiers

The group, dubbed SiribClone by Russian cybersecurity firm F6, has been active since at least the summer of 2025 and has primarily targeted members of the Russian armed forces stat...

Read More → Use Tool →
2026-06-09The Hacker News
The Hidden Security Risk: Work Between Tools Slows Response

Despite record investment in SIEM platforms, firewalls, IAM systems, and AI-driven detection, enterprise network security teams are still struggling with the same fundamental probl...

Incident ResponseAI SecurityThreat Intel
Read More → Use Tool →
2026-06-09The Hacker News
FROST Attack Uses SSD Timing to Spy on Your Browsing History

Researchers at Graz University of Technology have unveiled FROST, a new side-channel attack that lets any malicious website determine which sites you visit and which applications y...

PrivacyVulnerability
Read More → Use Tool →
2026-06-09The Hacker News
Hades PyPI Attack Poisons 19 Packages with Bun-Powered Credential Stealer

A new supply chain offensive dubbed Hades has compromised 19 packages in the Python Package Index (PyPI), deploying 37 malicious wheel artifacts that silently install a Bun-based c...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-09The Hacker News
CISA Adds LiteLLM Command Injection Flaw to KEV After Wild Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity command injection vulnerability in BerriAI LiteLLM to its Known Exploited Vulnerabilities...

VulnerabilityLLM SecurityAI Security
Read More → Use Tool →
2026-06-09BleepingComputer
French govt messaging service breached in account hijacking attack

DINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platf...

Read More → Use Tool →
2026-06-09BleepingComputer
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks...

Read More → Use Tool →
2026-06-09BleepingComputer
Google patches new Chrome zero-day flaw exploited in the wild

Google has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year. [...

Read More → Use Tool →
2026-06-09SecurityWeek
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

The most recent variants of the self-propagating attacks are named Miasma and Hades. The post Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks appeared first ...

Read More → Use Tool →
2026-06-09SecurityWeek
Will AI Kill the Bug Bounty Industry?

Anthropic's Mythos is accelerating vulnerability discovery to machine speed, forcing the bug bounty industry and offensive security teams to adapt to a future where finding flaws i...

Read More → Use Tool →
2026-06-09SecurityWeek
Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks

The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Atta...

Read More → Use Tool →
2026-06-09SecurityWeek
Google Patches 5th Chrome Zero-Day of 2026: CVE-2026-11645

Google on Monday rolled out Chrome 149, a critical security update that patches 74 vulnerabilities, including a high-severity zero-day flaw actively exploited in the wild. The vuln...

Zero-DayVulnerabilityBug Bounty
Read More → Use Tool →
2026-06-08Dark Reading
AI Slop Will Kill Cybersecurity Storytelling If We Let It

AI-generated content threatens credibility in cybersecurity. This "Ask the Expert" column explores why human oversight matters and how to maintain authentic narratives....

Read More → Use Tool →
2026-06-08BleepingComputer
NFCShare Android Malware Steals Card Data via Fake Bank App Updates on GitHub

New variants of the NFCShare Android malware are spreading through a phishing campaign that impersonates legitimate banking apps, with malicious APKs hosted on public GitHub reposi...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-08BleepingComputer
SoFi Hong Kong Confirms Third-Party Vendor Data Breach

SoFi Securities (Hong Kong) Limited is notifying customers of a data breach that exposed an unknown volume of personal information through a third-party vendor database. The subsid...

Data BreachSupply ChainIncident Response
Read More → Use Tool →
2026-06-08The Hacker News
Linux Kernel nf_tables Flaw CVE-2026-23111 Enables Local Root Escalation

Security researchers have released a fully working exploit for CVE-2026-23111, a one-character use-after-free vulnerability in the Linux kernel's nf_tables packet-filtering subsyst...

VulnerabilityZero-Day
Read More → Use Tool →
2026-06-08BleepingComputer
New Apple feature automatically changes your compromised passwords

At WWDC 26, Apple announced an Apple Intelligence-powered feature that can automatically fix weak and compromised passwords. This works in Safari, and it's rolling out with iOS 27....

Read More → Use Tool →
2026-06-08BleepingComputer
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to stea...

Read More → Use Tool →
2026-06-08BleepingComputer
WhatsApp says it disrupted new NSO spyware phishing attacks

WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. [...]...

Read More → Use Tool →