HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

2026-05-13BleepingComputer
West Pharma Cyberattack: Data Stolen, Systems Encrypted

West Pharmaceutical Services, a $3 billion S&P 500 drug‑packaging firm, disclosed on May 13, 2026 that it was hit by a material cyberattack. The company detected the intrusion on M...

Data BreachRansomware
Read More → Use Tool →
2026-05-13The Hacker News
GemStuffer Campaign: 150+ RubyGems Abused for U.K. Council Data Exfiltration

Cybersecurity researchers have identified a sophisticated campaign dubbed "GemStuffer" that has compromised the RubyGems package repository with over 150 malicious gems designed to...

Supply ChainData Breach
Read More → Use Tool →
2026-05-11SecurityWeek
Operation HookedWing: 500+ Orgs Hit in 4-Year Phishing Campaign

A sophisticated phishing operation dubbed "Operation HookedWing" has been systematically targeting organizations across critical sectors for over four years, according to threat in...

PhishingAPTData Breach
Read More → Use Tool →
2026-05-08SecurityWeek
Braintrust Data Breach: AWS API Keys Leaked, Prompting Rotation

Braintrust, an AI infrastructure provider, disclosed on March 5 2026 that an unauthorized party had gained access to one of its Amazon Web Services (AWS) accounts. The intrusion, d...

Data BreachCloud SecurityAI Security
Read More → Use Tool →
2026-05-08SecurityWeek
RansomHouse Ransomware Breach: Trellix Internal Services Exposed

RansomHouse, a known ransomware operation, has claimed responsibility for a breach at Trellix, a prominent cybersecurity vendor. The group posted several screenshots on a dark‑web ...

RansomwareData BreachThreat Intel
Read More → Use Tool →
2026-05-08The Record
GM Pays $12M in Largest CCPA Settlement for Driver Data Violations

General Motors has agreed to pay a $12.75 million settlement to the State of California for collecting and sharing sensitive driver data without proper consent, marking the largest...

PrivacyRegulationData Breach
Read More → Use Tool →
2026-05-08The Record
Virginia Man Convicted for Deleting 96 Government Databases

A federal jury in Virginia has convicted 39-year-old Richmond resident James E. Thornton on multiple charges stemming from a 2023 cyber intrusion that resulted in the deletion of 9...

Data BreachIncident ResponseAuthentication
Read More → Use Tool →
2026-05-08The Record
Canvas Cyberattack Forces Universities to Reschedule Final Exams

On Thursday, May 30 2025, a coordinated cyber incident hit Instructure's Canvas learning management system, displaying a ransom note from an unidentified cybercriminal group to stu...

Data BreachSupply ChainRansomware
Read More → Use Tool →
2026-05-08The Hacker News
Patient Zero Webinar: Preventing Stealth Breaches Through Threat Intel

The Hacker News recently highlighted an emerging cybersecurity threat model dubbed "Patient Zero" that organizations increasingly struggle to detect. A specialized webinar hosted b...

PhishingThreat IntelData Breach
Read More → Use Tool →
2026-05-08BleepingComputer
NVIDIA Confirms GeForce NOW Data Breach Affects Armenian Users

NVIDIA has officially confirmed a data breach impacting its GeForce NOW service, exposing personal information for a subset of users in Armenia. The disclosure, made in a statement...

Data BreachPrivacyCloud Security
Read More → Use Tool →
2026-05-08BleepingComputer
RansomHouse Claims Trellix Source Code Breach – What You Need to Know

Trellix, a prominent cybersecurity vendor, disclosed on [date] that its internal source‑code repository had been compromised. The intrusion was promptly claimed by the RansomHouse ...

Data BreachRansomwareSupply Chain
Read More → Use Tool →
2026-05-08BleepingComputer
Zara Data Breach Exposes 197K Customers’ Personal Data

Zara, the Spanish fast‑fashion giant, has confirmed a data breach that exposed the personal information of approximately 197,000 customers. The compromise was uncovered after the b...

Data BreachPrivacy
Read More → Use Tool →
2026-05-08KrebsOnSecurity
Canvas Data Breach Hits US Schools: Ransomware, Zero‑Day Exploit Disrupts Classes

A massive data‑extortion campaign slammed the widely‑used learning‑management platform Canvas on Tuesday, forcing districts and universities across the United States to suspend onl...

Data BreachRansomware
Read More → Use Tool →
2026-05-08Dark Reading
ShinyHunters Claims Second Instructure Breach: 300M+ Users Exposed

ShinyHunters, the notorious threat group behind a string of high‑profile data thefts, announced on March 5 that it had executed a second intrusion into Instructure, the education‑t...

Data BreachAPTPrivacy
Read More → Use Tool →
2026-05-07The Hacker News
Edge Plaintext Passwords, ICS 0‑Days, Patch‑or‑Die Alerts: 2026 Threat Report

The first week of 2026 has been marked by a confluence of critical vulnerabilities and aggressive threat campaigns that underscore the continuing fragility of enterprise and indust...

Zero-DayVulnerabilityData Breach
Read More → Use Tool →
2026-05-07BleepingComputer
ShinyHunters Exploits Zero‑Day to Deface Canvas Login Portals at 300+ Colleges

On March 12, 2025, the ShinyHunters ransomware group successfully compromised Instructure, the maker of the Canvas learning management system, by exploiting a previously unknown vu...

Zero-DayData BreachVulnerability
Read More → Use Tool →
2026-05-07BleepingComputer
How Browsers Bypass DLP: AI Prompts and Copy/Paste Create Data Leakage

Organizations investing heavily in data loss prevention (DLP) solutions are discovering a critical blind spot: the browser has become the primary vector for inadvertent data exfilt...

Data BreachAI SecurityPrivacy
Read More → Use Tool →
2026-05-06Dark Reading
Instructure Breach Exposes Canvas LMS Vendor Risks for Schools

A threat actor known as ShinyHunters has claimed responsibility for a cyberattack against Instructure, the company behind the widely deployed Canvas learning management system (LMS...

Data BreachSupply ChainVulnerability
Read More → Use Tool →
2026-05-06BleepingComputer
DAEMON Tools Lite Supply Chain Attack: Malware-Free Version Released

Disc Soft Limited, the vendor behind the popular disc‑imaging utility DAEMON Tools Lite, acknowledged on March 8 2026 that a malicious update had been pushed through its official d...

MalwareSupply ChainData Breach
Read More → Use Tool →
2026-05-05Dark Reading
Trellix Source Code Breach Exposes Security Product Vulnerabilities

Trellix, a prominent cybersecurity company formed from the merger of McAfee Enterprise and FireEye, has confirmed a significant source code breach affecting multiple security produ...

Supply ChainData BreachThreat Intel
Read More → Use Tool →
2026-05-05Dark Reading
Edge Password Leak in Process Memory Threatens Enterprise

A new proof‑of‑concept (PoC) published by security researcher Alex Chen of CyberX Labs shows that Microsoft Edge stores user passwords in plaintext within the browser’s process mem...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2026-05-05BleepingComputer
Instructure Breach: Hacker Claims 280M Records from 8,800 Schools

Education technology provider Instructure has disclosed a significant data breach after a threat actor operating under the alias 'CSAMKing' claimed to have stolen approximately 280...

Data BreachPrivacyThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
Vimeo Data Breach Exposes 119,000 Users' Personal Information

The ShinyHunters extortion group has claimed responsibility for a significant data breach at Vimeo, the popular online video platform owned by IAC. Security researchers first ident...

Data BreachPrivacy
Read More → Use Tool →
2026-05-04The Hacker News
AI-Assisted Attack: 17-Year-Old Arrested for 7M User Data Breach

On December 4, 2025, Japanese law enforcement agencies apprehended a 17‑year‑old, identified as Kaito Matsumoto, in Osaka for allegedly running a piece of AI‑generated malicious co...

AI ThreatsData BreachMalware
Read More → Use Tool →
2026-05-04BleepingComputer
Trellix Data Breach Exposes Source Code - What You Need to Know

Cybersecurity firm Trellix has disclosed a significant data breach after threat actors gained unauthorized access to a portion of its source code repository. The incident, discover...

Data BreachSupply ChainThreat Intel
Read More → Use Tool →
2026-05-03BleepingComputer
Instructure Data Breach: ShinyHunters Claim 4.5M Records Stolen

Instructure, the educational technology company behind the popular Canvas learning‑management system, confirmed on March 5 2026 that unauthorized actors had accessed its internal n...

Data BreachThreat IntelPrivacy
Read More → Use Tool →
2026-05-02The Hacker News
Trellix Confirms Source Code Breach After Unauthorized Repository Access

Trellix has officially acknowledged a security incident in which an unauthorized party gained access to a portion of its source code repositories. The company said it identified th...

Data BreachSupply Chain
Read More → Use Tool →
2026-05-01The Hacker News
Vietnamese Hackers Hijack 30K Facebook Accounts via Google AppSheet Phishing

A newly uncovered Vietnamese‑linked phishing campaign has compromised roughly 30,000 Facebook accounts by abusing Google’s low‑code AppSheet platform as a covert relay. Researchers...

PhishingData BreachAPT
Read More → Use Tool →
2026-05-01BleepingComputer
Instructure Discloses Cyber Incident, Investigates Impact on Canvas Platform

Instructure, the company behind the widely used Canvas learning management system, disclosed on March 2 2026 that it had identified a cyber incident affecting its internal infrastr...

Data BreachIncident Response
Read More → Use Tool →
2026-05-01BleepingComputer
15-Year-Old Detained Over France Titres Data Breach

French police (the Direction centrale de la police judiciaire, DCPJ) and the Paris Prosecutor’s Office have detained a 15‑year‑old, known by the alias "M4L", on suspicion of sellin...

Data BreachPrivacy
Read More → Use Tool →
2026-05-01BleepingComputer
BleepingComputer Retracts Instructure Data Breach Story After Review

BleepingComputer published a story on March 5, 2026 claiming that Instructure, the education‑technology company behind the Canvas learning‑management platform, had suffered a new d...

Data BreachPrivacy
Read More → Use Tool →
2026-04-30The Hacker News
SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks: Threat Report

Law enforcement agencies in the United States and Europe have dismantled a sprawling SMS phishing campaign that leveraged fake cellular base stations, known as IMSI catchers, to bl...

PhishingVulnerabilityData Breach
Read More → Use Tool →
2026-04-29Dark Reading
AI Finds 38 Security Flaws in OpenEMR, Threatening 100K Providers

Security researchers using an AI‑driven code analysis platform identified 38 distinct vulnerabilities in the OpenEMR electronic health record (EHR) system, including 12 rated criti...

VulnerabilityAI SecurityData Breach
Read More → Use Tool →
2026-04-28Dark Reading
Vidar Infostealer Dominates Market After Law Enforcement Takedowns

Vidar has emerged as the dominant infostealer in the cybercriminal ecosystem, filling the vacuum left by last year's coordinated law enforcement operations against Lumma Stealer an...

MalwareThreat IntelData Breach
Read More → Use Tool →
2026-04-28The Hacker News
Secure Data Movement: The Zero Trust Bottleneck You're Ignoring

In the rush to hybrid cloud adoption, many organizations treat data movement as a simple connectivity chore. Open a ticket, spin up an SFTP gateway, push the data across, and consi...

Data BreachCloud SecurityVulnerability
Read More → Use Tool →
2026-04-27The Hacker News
Checkmarx Data Leaked on Dark Web After Supply Chain Attack

Checkmarx has confirmed that the data stolen during the March 23 supply‑chain intrusion has been publicly posted on a Tor‑based dark‑web leak site. The company’s incident response ...

Supply ChainData BreachThreat Intel
Read More → Use Tool →
2026-04-21KrebsOnSecurity
Scattered Spider Member Tylerb Pleads Guilty to Wire Fraud, ID Theft

Tyler Robert Buchanan, a 24‑year‑old British national known in the cybercrime underground as “Tylerb,” pleaded guilty on June 5 2024 in a U.S. District Court to one count of wire‑f...

APTPhishingData Breach
Read More → Use Tool →
2026-04-20Dark Reading
Vercel Employee AI Tool Access Triggered Data Breach via OAuth Tokens

On March 5, 2026, Vercel's security operations center (SOC) detected anomalous activity stemming from an OAuth token tied to a senior developer's account. The token, scoped to the ...

Data BreachAI SecuritySupply Chain
Read More → Use Tool →
2026-04-20Dark Reading
WhatsApp Metadata Leak Exposes User Info to Attackers

WhatsApp has patched a critical flaw that allowed attackers to harvest user metadata simply by knowing a victim's phone number, according to a Dark Reading analysis published this ...

PrivacyVulnerabilityData Breach
Read More → Use Tool →
2026-01-21Ars Technica
SMS Sign-In Links Expose Millions of Users' Sensitive Data

Even major online services that pride themselves on seamless login experiences are quietly exposing sensitive user data through SMS sign‑in links. Security researchers analyzing th...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2025-12-15Ars Technica
Google Ends Dark Web Report Service: Leaked Data Alerts Stop

Google announced on Monday that it will retire the Dark Web Report feature from its Google Account dashboard, ending a service that warned users when their personal information app...

Data BreachPrivacy
Read More → Use Tool →
2025-09-02Ars Technica
Google Defends Gmail Security Amid Breach Claims

Google on Monday rebuffed recent reports—published by Ars Technica—that claimed a massive breach exposing all 2.5 billion Gmail accounts, asserting that its security controls are r...

Cloud SecurityPrivacyData Breach
Read More → Use Tool →
2025-07-23Ars Technica
Clorox Sues Vendor After $380M Hack Exposes Password Failures

Clorox has filed a lawsuit against a service desk vendor following a 2023 cybersecurity breach that cost the company approximately $380 million. The legal action centers on allegat...

Data BreachSupply ChainAuthentication
Read More → Use Tool →
2025-06-05Ars Technica
Nintendo Warns Switch 2 GameChat Records Chats, Shares Data on Request

Nintendo has alerted owners of its upcoming Switch 2 console that the built‑in GameChat feature creates temporary local copies of voice and text conversations, and that those recor...

PrivacyData BreachVulnerability
Read More → Use Tool →
2022-08-31Threatpost
Student Loan Data Breach Exposes 2.5M Records

Over the weekend, Nelnet Servicing, a major U.S. student‑loan servicer operating under contract with the Department of Education’s Federal Student Aid (FSA) office, disclosed a dat...

Data BreachPrivacyVulnerability
Read More → Use Tool →
2022-08-24Threatpost
Twitter Security Lapses: Whistleblower Alleges National Risk

Peiter “Mudge” Zatko, Twitter’s former head of security, filed a whistleblower complaint in July 2022 with the Federal Trade Commission (FTC) and the Senate Select Committee on Int...

PrivacyData BreachRegulation
Read More → Use Tool →