HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1912 篇文章,第 1 / 64 頁

2026-07-10The Hacker News
Exposed WP-SHELLSTORM Server Reveals Mass WordPress Backdoor Operation

A cybercrime operation tracked as WP-SHELLSTORM inadvertently exposed its own infrastructure for 22 days, leaving a rented US-based server at 137.175.93[.]126 wide open with no aut...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-10The Hacker News
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no...

Read More → Use Tool →
2026-07-10The Hacker News
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius A...

Read More → Use Tool →
2026-07-10The Hacker News
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., k...

Read More → Use Tool →
2026-07-10The Hacker News
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with...

Read More → Use Tool →
2026-07-10The Hacker News
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated ...

Read More → Use Tool →
2026-07-10The Hacker News
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat...

Read More → Use Tool →
2026-07-10SecurityWeek
China, India-Linked Hackers Both Targeted Same Pakistani Police Force

Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne. The post China, India-Linked Hackers Both Targeted Sam...

Read More → Use Tool →
2026-07-10SecurityWeek
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers ap...

Read More → Use Tool →
2026-07-10SecurityWeek
GigaWiper Combines Multiple Malware for System-Level Sabotage

The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-...

Read More → Use Tool →
2026-07-10SecurityWeek
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism

Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucina...

Read More → Use Tool →
2026-07-10SecurityWeek
Network of 200 GitHub Repositories Used for Malware Infection

A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware ...

Read More → Use Tool →
2026-07-09The Hacker News
Dormant GitHub Accounts Weaponized for Corporate Reconnaissance via API Scraping

Datadog Security Labs is sounding the alarm over a coordinated series of campaigns that systematically enumerate corporate GitHub organizations, repositories, and user accounts thr...

Supply ChainThreat IntelCloud Security
Read More → Use Tool →
2026-07-09The Hacker News
GigaWiper: New Windows Backdoor Pairs Disk Wiping With Spyware

Microsoft has dissected a destructive Windows backdoor dubbed GigaWiper, a Go-based implant that bundles three distinct destructive payloads into a single command-driven toolkit. T...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-09Dark Reading
Iranian APT Groups Target Every Internet-Facing Vulnerability

Iranian state-sponsored hacking groups have significantly broadened their targeting scope, moving past traditional critical infrastructure attacks to compromise any organization wi...

APTThreat IntelVulnerability
Read More → Use Tool →
2026-07-09Dark Reading
Microsoft Reins in RoguePlanet Zero-Day Threat

The researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft z...

Read More → Use Tool →
2026-07-09Dark Reading
AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready

If you're handling them like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach....

Read More → Use Tool →
2026-07-09The Hacker News
npm 12 Disables Install Scripts by Default to Cut Supply Chain Risk

GitHub has officially released npm 12, the latest version of the world's most widely used JavaScript package manager, with a major security-focused overhaul that disables install s...

Supply ChainAuthenticationVulnerability
Read More → Use Tool →
2026-07-09The Hacker News
AI-Powered Attacks Move in Minutes: Zero Trust Defense Strategies

AI-powered attacks have compressed the attacker's timeline from days to minutes. Using models like "Mythos," adversaries generate tailored phishing bait, identify high-value target...

AI SecurityAI ThreatsAuthentication
Read More → Use Tool →
2026-07-09The Hacker News
INTERPOL Arrests 6K in Fraud Sweep, npm Supply Chain Hits Payment SDKs

A coordinated global anti-fraud operation, codenamed First Light 2026, led to the arrest of 5,811 individuals across 97 countries and territories, with authorities intercepting $29...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-09Dark Reading
As Global Conflicts Go Digital, Businesses Need Wartime Gameplans

The fate of a Ukrainian tax software company shows how modern cyberwarfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to protec...

Read More → Use Tool →
2026-07-09Dark Reading
AI Gateways Offer Attackers the Keys to the Kingdom

A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data....

Read More → Use Tool →
2026-07-09SecurityWeek
QIZ Security Raises $17 Million for Cryptographic Governance Platform

The Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance P...

Read More → Use Tool →
2026-07-09SecurityWeek
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge

Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK. The post UK Government Rolls Out Agentic AI Defen...

Read More → Use Tool →
2026-07-09SecurityWeek
Palo Alto Networks Patches 13 Vulnerabilities

Buffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 ...

Read More → Use Tool →
2026-07-09SecurityWeek
12 Million Impacted by Data Breach at Japanese Telco KDDI

Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appear...

Read More → Use Tool →
2026-07-09The Record
Latvian forestry company still restoring systems weeks after ransomware attack

A foreign, financially motivated group was responsible for a cyberattack on state-owned forestry company Latvijas Valsts Mezi (LVM), officials said....

Read More → Use Tool →
2026-07-09The Record
NSA revives 'Tailored Access Operations' name for elite hacking unit

NSA last week changed the moniker of its Office of Computer Network Operations (CNO) back to Tailored Access Operations (TAO), a name that is sure to elicit nostalgia among the bro...

Read More → Use Tool →
2026-07-09The Record
EU takes member states to court over unimplemented cybersecurity law

Ireland, Spain, France and the Netherlands are more than 20 months late in transposing the NIS2 Directive for the cybersecurity of critical infrastructure....

Read More → Use Tool →
2026-07-09The Hacker News
Vulnerability Clearinghouses: Why Data Isn't the Real Fix

The cybersecurity world converged on a single word this summer: clearinghouse. Chainguard launched Athena, a long-rumored platform that had been quietly processing pre-disclosure v...

Supply ChainVulnerabilityThreat Intel
Read More → Use Tool →