HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1290 篇文章,第 10 / 43 頁

2026-06-06The Hacker News
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repos...

Read More → Use Tool →
2026-06-06SecurityWeek
Opal Security Raises $23 Million for AI-Native Identity Governance

Raising $59 million to date, Opal also announced five senior leadership appointments. The post Opal Security Raises $23 Million for AI-Native Identity Governance appeared first on ...

Read More → Use Tool →
2026-06-06The Hacker News
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available

Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a C...

Read More → Use Tool →
2026-06-05BleepingComputer
Toshiba and Muji Sites Hit by Fake Login Prompts from Revived Polyfill Domain

Japanese tech giant Toshiba and retail chain Muji are warning visitors that suspicious sign-in screens appearing on their websites may be harvesting credentials, in a supply chain ...

Supply ChainPhishingIncident Response
Read More → Use Tool →
2026-06-05BleepingComputer
CISA Warns: SolarWinds Serv-U Flaw Actively Exploited to Crash Servers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting a recently patched high-severity vulnerability in SolarWin...

VulnerabilityIncident ResponseThreat Intel
Read More → Use Tool →
2026-06-05The Hacker News
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust...

Read More → Use Tool →
2026-06-05BleepingComputer
Chinese APT deploys new malware to keep access to hacked networks

A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentP...

Read More → Use Tool →
2026-06-05Dark Reading
Exposed Fuel Tank Gauges Under Attack in the US

Threat actors are taking advantage of Internet-exposed tank gauges by breaching gas stations, opening the door to disruption....

Read More → Use Tool →
2026-06-05The Hacker News
Asin Android Spyware Targets Arabic Users via Fake News, PDF, and War Map Apps

ESET researchers have uncovered a new Android spyware strain dubbed "Asin" that has been actively targeting Arabic-speaking users through a series of malicious apps disguised as le...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-05The Hacker News
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been observed targeting Microsoft In...

Read More → Use Tool →
2026-06-05The Hacker News
Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver

Eighteen months ago, the AI SOC was a marketing line. Today it's a budget item. The category has crossed over from interesting to inevitable, with billions of dollars now flowing i...

Read More → Use Tool →
2026-06-05BleepingComputer
Dark web Nemesis Market vendor gets 26 years for selling drugs

A California man was sentenced to more than 26 years in federal prison for trafficking fentanyl and methamphetamine through Nemesis Market, one of the world's largest dark web mark...

Read More → Use Tool →
2026-06-05BleepingComputer
Over 900 US gas station tank gauge systems exposed to attacks

Over 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been foun...

Read More → Use Tool →
2026-06-05BleepingComputer
What 2026 DBIR Confirms: Attacks Are Living in the Browser

Phishing, shadow AI, malicious extensions, and credential theft increasingly happen inside the browser. Keep Aware explains what the 2026 Verizon DBIR reveals about browser-layer s...

Read More → Use Tool →
2026-06-05Dark Reading
Adaptive, Agentic AI Worms Loom as Next Enterprise Threat

AI worms, or "viruses with wings and brains," adapt to new environments, seek out vulnerabilities, and will likely strike within a year, researchers say....

Read More → Use Tool →
2026-06-05Dark Reading
Trump AI Order Seeks Voluntary Frontier Model Testing

The White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security....

Read More → Use Tool →
2026-06-05SecurityWeek
OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds

CVE Lite CLI is a free, open-source command line tool that scans your projects in seconds and tells you exactly which included packages contain a vulnerability. The post OWASP Incu...

Read More → Use Tool →
2026-06-05SecurityWeek
In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA

Other noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner. The post In Other News: Anthr...

Read More → Use Tool →
2026-06-05The Record
EU unveils tech sovereignty package to cut reliance on US, Chinese suppliers

The package bundles two draft laws — a Chips Act 2.0 and a Cloud and AI Development Act (CADA) — alongside an Open Source Strategy and a roadmap for digitalizing the energy system....

Read More → Use Tool →
2026-06-05The Hacker News
Hackers Exploit Critical Everest Forms Pro RCE Flaw to Hijack WordPress Sites

Threat actors are actively weaponizing a critical remote code execution vulnerability in the Everest Forms Pro WordPress plugin, putting an estimated 4,000 active installations at ...

VulnerabilityThreat IntelMalware
Read More → Use Tool →
2026-06-05The Hacker News
FIFA World Cup 2026 Scams: 4,300 Phishing Domains Exposed Before Kickoff

Cybersecurity researchers and the FBI are sounding the alarm on a massive wave of FIFA-themed fraud targeting World Cup 2026 fans, just days before the June 11 opening match. With ...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-06-05BleepingComputer
Cisco warns of unpatched SD-WAN zero-day exploited in attacks

On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privil...

Read More → Use Tool →
2026-06-05SecurityWeek
Hackers Leak DentaQuest Information Impacting 2.6 Million

The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Information Impacting 2.6 M...

Read More → Use Tool →
2026-06-05SecurityWeek
Chrome 149 Patches 429 Vulnerabilities

Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared fi...

Read More → Use Tool →
2026-06-05SecurityWeek
Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday

Experts commented on the EO’s voluntary nature, the balance between innovation and security, and potential implementation gaps. The post Industry Reactions to New Trump AI Cybersec...

Read More → Use Tool →
2026-06-05SecurityWeek
Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities

Posing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information. The post Five Eyes: Chinese Spies Targ...

Read More → Use Tool →
2026-06-05SecurityWeek
Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals

The company detected a network intrusion in March and an investigation showed that some files were stolen during the attack. The post Nightclub Giant RCI Says Data Breach Affects 4...

Read More → Use Tool →
2026-06-05The Hacker News
PCPJack Hijacks 230 Cloud Servers to Build Covert SMTP Relay Network

The threat actor tracked as PCPJack has compromised at least 230 cloud servers across Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure, converting them into a ...

Cloud SecurityThreat IntelMalware
Read More → Use Tool →
2026-06-05SecurityWeek
Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026

The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026...

Read More → Use Tool →
2026-06-04The Record
Apple removes Russia’s state-backed messaging app Max from its store

Russian authorities have promoted Max as a domestic alternative to foreign messaging platforms such as Telegram and WhatsApp....

Read More → Use Tool →