HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

2026-06-27The Hacker News
Russian Hackers Use Fake Signal Support Texts to Steal Messaging Credentials

Ukraine's Security Service (SSU), working alongside the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage campaign attributed to Russian inte...

PhishingAPTAuthentication
Read More → Use Tool →
2026-06-23The Hacker News
FortiBleed: 110M Credentials Stolen from 430K FortiGate Firewalls

A Russian-speaking initial access broker (IAB) has been linked to a massive credential-harvesting campaign called FortiBleed, which has compromised over 430,000 FortiGate firewalls...

Threat IntelVulnerabilityAuthentication
Read More → Use Tool →
2026-06-19BleepingComputer
Icarus Hackers Claim Klue OAuth Breach Exposing Salesforce Data

Market intelligence platform Klue has confirmed a security incident in which attackers exploited a compromised legacy credential to steal OAuth tokens, gaining access to multiple c...

Data BreachSupply ChainAuthentication
Read More → Use Tool →
2026-06-19The Hacker News
CISA Warns: FortiBleed Campaign Hits 86,644 FortiGate Devices Globally

CISA has issued an urgent advisory urging Fortinet customers to secure their FortiGate appliances against an ongoing malicious campaign dubbed FortiBleed, which has already comprom...

Data BreachAuthenticationThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
Orphaned AI Agents: Hidden Access Risks in Enterprise Networks

When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-06-17BleepingComputer
Account Takeover Attacks Surge: How Attackers Bypass MFA in 2026

Organizations now manage thousands of human and non-human identities spread across cloud services, SaaS applications, endpoints, and remote environments. As hybrid work, BYOD polic...

AuthenticationPhishingThreat Intel
Read More → Use Tool →
2026-06-17The Hacker News
Top 10 Attack Surface Exposures of 2026: 60% of Organizations at Risk

A new analysis of 3,000 organizational attack surfaces reveals that unnecessary internet-facing services remain the weakest link in enterprise defense. Intruder's 2026 Attack Surfa...

VulnerabilityThreat IntelAuthentication
Read More → Use Tool →
2026-06-16The Hacker News
Rokarolla Android Trojan Targets 217 Banking and Crypto Apps With 137 Commands

Security researchers at Zimperium's zLabs have uncovered a new Android banking trojan dubbed Rokarolla, named after its command-and-control infrastructure. The malware targets 217 ...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-06-16BleepingComputer
UK to Require ID or Face Scan for All New Social Media Accounts

The UK government will require anyone opening a new social media account to verify their age by uploading government-issued ID or passing a facial age scan, under regulations annou...

RegulationPrivacyAuthentication
Read More → Use Tool →
2026-06-15BleepingComputer
Critical SimpleHelp Flaw Lets Hackers Create Rogue Admin Accounts

A critical vulnerability in SimpleHelp remote management software, tracked as CVE-2026-48558, enables unauthenticated attackers to create privileged Technician accounts on servers ...

VulnerabilityAuthenticationIncident Response
Read More → Use Tool →
2026-06-15The Hacker News
Palo Alto Networks PAN-OS GlobalProtect VPN Flaw Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability (CVSS 7.8) affecting the GlobalProtect VPN portal and gat...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-13BleepingComputer
Ex-IT Worker Gets 21 Months in Prison for Cyberattacks on Iowa School District

Ezekiel Dean Potter, a 34-year-old former senior IT support specialist for Iowa's Saydel Community School District, has been sentenced to 21 months in federal prison for a sustaine...

AuthenticationIncident ResponseData Breach
Read More → Use Tool →
2026-06-13The Hacker News
Critical Splunk Enterprise Flaw Enables Unauthenticated RCE via PostgreSQL Sidecar

Splunk has rolled out emergency security patches for a critical vulnerability in Splunk Enterprise that allows remote attackers to execute arbitrary code without any authentication...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-06-13BleepingComputer
Operation Highland: Velvet Ant APT Spied on Air-Gapped Network for 10 Years

The Chinese state-linked espionage group "Velvet Ant" maintained undetected access to a large organization's critical infrastructure for an extraordinary 10 years, according to res...

APTAuthenticationThreat Intel
Read More → Use Tool →
2026-06-12The Hacker News
China-Linked Velvet Ant APT Backdoored Linux Login Software for a Decade

A China-nexus advanced persistent threat tracked as Velvet Ant by incident response firm Sygnia maintained covert access to a target network for nearly a decade by compromising the...

APTAuthenticationSupply Chain
Read More → Use Tool →
2026-06-12BleepingComputer
Critical phpBB Auth Bypass Flaw Unpatched for 10 Years Exposes Admin Accounts

Security researchers at application security firm Aikido have disclosed a severe authentication bypass vulnerability in phpBB, the widely used open-source forum platform, that h...

AuthenticationVulnerabilityBug Bounty
Read More → Use Tool →
2026-06-12The Record
Coupang Hit With Record $409M Fine After Massive 33.7M User Data Breach

South Korea's Personal Information Protection Commission (PIPC) has imposed a record 624.7 billion won ($409 million) fine on Coupang, the country's largest online retailer, over a...

Data BreachRegulationAuthentication
Read More → Use Tool →
2026-06-10The Hacker News
Ivanti, Fortinet, SAP Patch Critical RCE and Auth Bypass Flaws

Fortinet, Ivanti, and SAP have rolled out urgent security updates addressing multiple critical vulnerabilities that could enable arbitrary code execution, authentication bypass, an...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-06-06BleepingComputer
Critical Everest Forms Pro Flaw Actively Exploited to Hijack WordPress Sites

Hackers are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin to seize full control of vulnerable w...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-04The Hacker News
Cisco Unified CM SSRF Flaw (CVE-2026-20230): PoC Public, Full Patch Months Away

Cisco has released a patch for a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) and its Session Management Edition that allows an u...

VulnerabilityThreat IntelAuthentication
Read More → Use Tool →
2026-06-03The Hacker News
Microsoft 365 Android Bug Let Any App Steal User Account Tokens

A single leftover debug flag in production builds of several Microsoft 365 Android applications disabled a critical security check, allowing any app installed on the same device to...

VulnerabilityAuthentication
Read More → Use Tool →
2026-06-03The Hacker News
One-Click GitHub.dev Attack Steals Full OAuth Tokens via VS Code

Cybersecurity researchers have disclosed a critical one-click attack chain that abuses Microsoft Visual Studio Code (VS Code) webviews to steal fully scoped GitHub OAuth tokens. Di...

VulnerabilityAuthenticationSupply Chain
Read More → Use Tool →
2026-06-03The Hacker News
IVIP: Closing the Identity Dark Matter Gap in Enterprise IAM

Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...

AuthenticationAI SecurityCloud Security
Read More → Use Tool →
2026-06-03The Hacker News
Unpatched Windows Search URI Flaw Lets Attackers Steal NTLMv2 Hashes

Cybersecurity researchers at Huntress have disclosed an unpatched vulnerability in the Windows "search:" URI handler that can be weaponized to leak a user's NTLMv2 hash to a remote...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-03BleepingComputer
Acer Wave 7 Routers Hit by Two Max-Severity Zero-Day Vulnerabilities

Acer has confirmed it is actively developing patches for two maximum-severity zero-day vulnerabilities impacting its Wave 7 mesh routers. Both flaws were reported by independent se...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-06-02BleepingComputer
Hackers Steal Instagram Accounts Using AI-Generated Selfies to Bypass Meta Verification

Attackers have hijacked multiple high-value Instagram accounts by exploiting Meta's AI-powered support assistant, tricking it into transferring ownership using deepfake selfie vide...

AI ThreatsAuthenticationDeepfake
Read More → Use Tool →
2026-06-02The Hacker News
Dashlane Confirms Brute-Force Attack Exposed Encrypted Vaults of Under 20 Users

Password manager Dashlane has disclosed a brute-force security incident in which encrypted password vaults belonging to fewer than 20 personal plan subscribers were downloaded by a...

Data BreachAuthenticationIncident Response
Read More → Use Tool →
2026-06-01BleepingComputer
Red Hat npm Supply Chain Attack Spreads Shai-Hulud 'Miasma' Malware

More than 30 npm packages under the @redhat-cloud-services namespace were compromised in a sophisticated supply‑chain attack that delivered a new variant of the Shai‑Hulud credenti...

Supply ChainMalwareAuthentication
Read More → Use Tool →
2026-05-30The Hacker News
CVE-2026-0257: PAN-OS GlobalProtect Bypass Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a medium-severity authentication bypass vulnerability (CVSS 7.8) affecting PAN-OS and Prisma Access GlobalPro...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-05-28The Hacker News
Critical Gogs RCE Vulnerability Allows Code Execution

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, enabling authenticated users to execute arbitrary code on affected serv...

VulnerabilityZero-DayAuthentication
Read More → Use Tool →
2026-05-26The Hacker News
MFA Prompt Bombing: Push-Based 2FA Exploitation Explained

Multi-factor authentication (MFA) was designed to close a critical gap in identity security by requiring a second factor beyond passwords. However, attackers have developed a techn...

AuthenticationPhishingThreat Intel
Read More → Use Tool →
2026-05-22The Record
FBI Warns of Kali365 Phishing Service Targeting Microsoft 365

The FBI has issued a critical advisory regarding Kali365, a Telegram-based Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to compromise Microsoft 365 accounts b...

PhishingCloud SecurityAuthentication
Read More → Use Tool →
2026-05-21The Hacker News
Identity is the Attack Path: Cloud Security Risks in 2025

A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...

Cloud SecurityAuthenticationAI Security
Read More → Use Tool →
2026-05-21Dark Reading
Enterprises Boost AI Agent Identity Security Budgets as Omdia Reveals Shifting Priorities

Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-05-18The Hacker News
Developer Workstations Now Critical Supply Chain Attack Targets

In a concentrated 48-hour window, threat actors launched coordinated attacks against npm, PyPI, and Docker Hub, marking a significant escalation in software supply chain aggression...

Supply ChainThreat IntelAuthentication
Read More → Use Tool →
2026-05-18The Hacker News
Ivanti, Fortinet, SAP, VMware Patch Critical RCE, SQL Injection, Privilege Escalation

Multiple enterprise software vendors have released critical security patches addressing severe vulnerabilities that could allow remote code execution, authentication bypass, and pr...

VulnerabilityZero-DayAuthentication
Read More → Use Tool →
2026-05-08SecurityWeek
PCPJack Worm Cleans TeamPCP, Steals AWS Cloud Credentials

Security researchers have identified a new self‑propagating threat, named PCPJack, that behaves like a worm while simultaneously purging systems infected by the earlier TeamPCP mal...

MalwareCloud SecurityAuthentication
Read More → Use Tool →
2026-05-08The Record
Virginia Man Convicted for Deleting 96 Government Databases

A federal jury in Virginia has convicted 39-year-old Richmond resident James E. Thornton on multiple charges stemming from a 2023 cyber intrusion that resulted in the deletion of 9...

Data BreachIncident ResponseAuthentication
Read More → Use Tool →
2026-05-08The Hacker News
Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials

Cybersecurity researchers have disclosed a previously unknown Linux backdoor called PamDOORa that is being actively advertised on the Russian cybercrime forum Rehub for $1,600 by a...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-05-06The Hacker News
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs

Security analysts have uncovered a sophisticated intrusion campaign leveraging the CloudZ remote access trojan (RAT) alongside a previously undocumented plugin called Pheno to targ...

MalwareAPTAuthentication
Read More → Use Tool →
2026-05-06Dark Reading
CloudZ RAT and Pheno Plug-in Target Windows Phone Link for Text Theft

Security researchers have uncovered a sophisticated cyberattack campaign leveraging the Windows Phone Link application to steal text messages and circumvent two-factor authenticati...

MalwareAuthenticationPrivacy
Read More → Use Tool →
2026-05-06BleepingComputer
Google Ads Abused in GoDaddy ManageWP Login Phishing Scam

A sophisticated phishing campaign is leveraging Google’s sponsored search ads to mimic the login page of ManageWP, GoDaddy’s platform for centrally managing large fleets of WordPre...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-05-05Dark Reading
Edge Password Leak in Process Memory Threatens Enterprise

A new proof‑of‑concept (PoC) published by security researcher Alex Chen of CyberX Labs shows that Microsoft Edge stores user passwords in plaintext within the browser’s process mem...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2026-05-04The Hacker News
Progress Patches Critical MOVEit Automation Authentication Bypass

Progress Software has released urgent updates for MOVEit Automation (formerly Central) that address two security flaws, the most severe of which is a critical authentication bypass...

VulnerabilityAuthentication
Read More → Use Tool →
2026-05-04Dark Reading
cPanel Authentication Bypass Zero‑Day Exploit Threatens Millions

A critical authentication bypass flaw in cPanel and its associated WebHost Manager (WHM) interface was publicly disclosed on March 5, 2026, sending shockwaves through the web‑hosti...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-05-04BleepingComputer
Credit Union Loan Fraud: Stolen Identity Verification Exposed

Fraudsters are not breaking into credit unions with zero‑days or ransomware; they are exploiting the normal loan origination workflow. Flare’s threat‑intelligence team uncovered a ...

AuthenticationThreat IntelPrivacy
Read More → Use Tool →
2026-05-04BleepingComputer
Progress Warns of Critical MOVEit Automation Auth Bypass (CVE-2025-2025)

Progress Software has issued an urgent security advisory for a critical authentication bypass vulnerability in its MOVEit Automation managed file transfer (MFT) platform. Tracked a...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-05-02BleepingComputer
ConsentFix v3: Automated OAuth Abuse Targets Azure

Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
Critical cPanel Authentication Vulnerability: Patch Now

cPanel and its WebHost Manager (WHM) product line contain a critical authentication flaw that could allow a remote attacker to bypass login controls and gain full control of the ho...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-04-17Dark Reading
Tycoon 2FA Phishers Switch to Device Code Phishing Attacks

Tycoon, a well‑known phishing collective that has long abused two‑factor authentication (2FA) bypass tricks, has quietly shifted to a new attack vector: OAuth 2.0 device‑code phish...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-04-07KrebsOnSecurity
Russia Exploits Router Flaws to Harvest Microsoft Office Tokens

Security researchers have linked a new wave of cyber‑attacks to Russia’s military intelligence, specifically the APT groups tied to the GRU, which are actively exploiting known vul...

APTVulnerabilityAuthentication
Read More → Use Tool →
2026-03-17Ars Technica
World ID Iris Tokens to Secure AI Agents, Prevent Swarms

Worldcoin’s World ID initiative, built by Tools for Humanity, is deploying a biometric authentication system based on iris scanning to assign a unique human identity to every AI ag...

AI SecurityPrivacyAuthentication
Read More → Use Tool →
2026-03-03Ars Technica
Google Tightens Android Developer Verification: Security vs Open Access

Google has announced significant changes to its Android app distribution model, implementing mandatory developer verification for all apps published on Google Play Store. The new r...

RegulationPrivacyAuthentication
Read More → Use Tool →
2026-01-21Ars Technica
SMS Sign-In Links Expose Millions of Users' Sensitive Data

Even major online services that pride themselves on seamless login experiences are quietly exposing sensitive user data through SMS sign‑in links. Security researchers analyzing th...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2025-10-03Ars Technica
Google Confirms Android Developer Verification Tiers: Free and Paid Options

Google has officially announced its Android developer verification program will feature both free and paid tiers, marking a significant shift in how developers are authenticated be...

Supply ChainAuthenticationPrivacy
Read More → Use Tool →
2025-07-23Ars Technica
Clorox Sues Vendor After $380M Hack Exposes Password Failures

Clorox has filed a lawsuit against a service desk vendor following a 2023 cybersecurity breach that cost the company approximately $380 million. The legal action centers on allegat...

Data BreachSupply ChainAuthentication
Read More → Use Tool →
2022-08-29Threatpost
0ktapus Phishing Attacks Compromised 130 Firms, Bypassed MFA

A coordinated phishing operation attributed to the threat group 0ktapus has ensnared more than 130 organizations across multiple industries, according to researchers at Threatpost....

PhishingThreat IntelAuthentication
Read More → Use Tool →