HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1264 篇文章,第 1 / 43 頁

2026-06-15The Hacker News
Critical LiteLLM Flaw Chain Lets Low-Privilege Users Hijack AI Gateways

Researchers at Obsidian Security have disclosed a three-vulnerability chain in LiteLLM, a widely deployed open-source AI gateway that brokers calls to more than 100 model providers...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-06-15The Hacker News
SearchLeak: One-Click Microsoft 365 Copilot Flaw Exposed Emails

Researchers at Varonis Threat Labs have disclosed a critical chain of three vulnerabilities in Microsoft 365 Copilot's Enterprise Search feature that, if exploited, would have allo...

VulnerabilityAI SecurityPhishing
Read More → Use Tool →
2026-06-15The Hacker News
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson ...

Read More → Use Tool →
2026-06-15The Hacker News
The Onboarding Password Mistake That Creates Unnecessary Risk

Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means...

Read More → Use Tool →
2026-06-15BleepingComputer
OptinMonster WordPress plugin hacked in CDN supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]...

Read More → Use Tool →
2026-06-15BleepingComputer
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks

Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileg...

Read More → Use Tool →
2026-06-15BleepingComputer
Council of Europe investigates ShinyHunters data breach claims

The Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. [...]...

Read More → Use Tool →
2026-06-15BleepingComputer
FBI: Fraudsters use couriers to steal money in crypto scams

The U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims of cryptocurrency investment scams, also known as pig butcheri...

Read More → Use Tool →
2026-06-15BleepingComputer
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl

Employees are increasingly building automations, agents, and apps with AI tools outside traditional security oversight. Tines explores how CISOs are handling AI-driven code sprawl,...

Read More → Use Tool →
2026-06-15BleepingComputer
Chinese hackers breach REDCap servers, steal medical research

A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. [...]...

Read More → Use Tool →
2026-06-15BleepingComputer
New attack turned Microsoft 365 Copilot into 1-click data theft tool

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint ...

Read More → Use Tool →
2026-06-15BleepingComputer
Infinite Campus data breach affects 137,000 school staff accounts

The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Cam...

Read More → Use Tool →
2026-06-15BleepingComputer
Webinar: How behavioral AI stops phishing and account takeovers

Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavi...

Read More → Use Tool →
2026-06-15Dark Reading
China-Nexus Actor Spy on US Researchers Undetected for a Year

Google discovered and disrupted the sprawling campaign, which stole RedCAP credentials to target numerous institutions and exfiltrate sensitive data....

Read More → Use Tool →
2026-06-15Dark Reading
The Beginning of the End of Social Engineering

AI-native operating systems are shifting the responsibility to stay vigilant against social engineering cyberattacks from the user onto the system itself....

Read More → Use Tool →
2026-06-15Dark Reading
US Cracks Down on Anthropic AI Models Amid Abuse Concerns

Anthropic abruptly suspended all access to Fable 5 and Mythos 5 after receiving an export control directive that banned foreign nationals from using the technology....

Read More → Use Tool →
2026-06-15SecurityWeek
Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer

Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen. The post Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sug...

Read More → Use Tool →
2026-06-15SecurityWeek
Chinese Hackers Target Medical, Military, and AI Research in North America

Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025. The post Chinese Hackers Target Medical, Military, and AI Research in Nor...

Read More → Use Tool →
2026-06-15SecurityWeek
NewCore Emerges From Stealth Mode With $66 Million in Funding

The startup has built a security-first identity platform to protect humans, machines, and AI agents. The post NewCore Emerges From Stealth Mode With $66 Million in Funding appeared...

Read More → Use Tool →
2026-06-15The Record
Cyberattack on Russian tech firm Astral disrupts business, government services for week

According to customer complaints, the disruption affected a range of services used by businesses, leading to interruptions in cash register operations, difficulties selling certain...

Read More → Use Tool →
2026-06-15The Record
Finland brings charges against cargo ship officers for cutting submarine cables

According to the deputy prosecutor general, the ship’s officers have now been charged with “having damaged two subsea telecommunications cables and of having attempted to damage a ...

Read More → Use Tool →
2026-06-15The Record
Anthropic says US government forced it to disable cybersecurity AI models

According to the company, the directive cited national security authorities. It appears to be the first time such authorities have been used to curtail the export of AI models rath...

Read More → Use Tool →
2026-06-15The Hacker News
152 Chrome Wallpaper Extensions Exposed as Adware with 105K Installs

Cybersecurity researchers at Socket have uncovered a sprawling network of 152 Google Chrome extensions posing as live wallpaper and new tab add-ons that covertly distribute a poten...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-06-15The Hacker News
WordPress Plugins Hacked: Hidden Backdoors Planted on 1.2M Sites

A coordinated supply chain attack compromised JavaScript files served by three popular WordPress plugins—PushEngage, OptinMonster, and TrustPulse—turning trusted scripts into vecto...

Supply ChainMalwareIncident Response
Read More → Use Tool →
2026-06-15The Hacker News
Sniper Dz PhaaS Platform Targets MENA Users with Fake Facebook Lures

Cybersecurity researchers at Group-IB have exposed a sprawling social engineering campaign operated through Sniper Dz, a turnkey phishing-as-a-service (PhaaS) platform dismantled l...

PhishingThreat IntelMalware
Read More → Use Tool →
2026-06-15The Hacker News
Palo Alto Networks PAN-OS GlobalProtect VPN Flaw Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability (CVSS 7.8) affecting the GlobalProtect VPN portal and gat...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-15SecurityWeek
Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang. The post Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges appear...

Read More → Use Tool →
2026-06-15SecurityWeek
Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems

The pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems.  The post Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems ...

Read More → Use Tool →
2026-06-15SecurityWeek
French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker

French officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign Tchap platform. The po...

Read More → Use Tool →
2026-06-15SecurityWeek
ShinyHunters Claims Council of Europe Hack

The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information. The post ShinyHunters Claims Council of E...

Read More → Use Tool →