HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1290 篇文章,第 12 / 43 頁

2026-06-04The Record
Five Eyes warn Chinese spies are using job sites to recruit insiders

The alert warned that Chinese intelligence officers are posing as recruiters and consultants for front companies based outside China in order to target Five Eyes government and mil...

Read More → Use Tool →
2026-06-04The Hacker News
Fake Open-Source Tool Sites Poison Google Results to Deliver Malware

Cybersecurity researchers at Check Point have uncovered a large-scale SEO poisoning operation that impersonates popular open-source and freeware projects to distribute malware thro...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-04The Hacker News
APT Spied on Stock Exchange Exec's Outlook Mailbox for 5 Months

Unknown attackers maintained undetected access to the Outlook mailbox of a senior executive at a major global stock exchange for at least five months, systematically exfiltrating c...

APTThreat IntelData Breach
Read More → Use Tool →
2026-06-04The Hacker News
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to...

Read More → Use Tool →
2026-06-04The Hacker News
DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabl...

Read More → Use Tool →
2026-06-04BleepingComputer
Cisco warns of critical Unified CM flaw with PoC exploit code

Cisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges. [...]...

Read More → Use Tool →
2026-06-04SecurityWeek
Chinese Cybercrime Group in Spotlight for Record Campaign Pace

Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities. The post Chinese Cybercrime Group in Spotlight for Reco...

Read More → Use Tool →
2026-06-04SecurityWeek
Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown

Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia. The post Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown...

Read More → Use Tool →
2026-06-04SecurityWeek
Cisco Warns of Available PoC for Critical Unified CM Vulnerability

The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks. The post Cisco Warns of Available PoC for Critical Unified ...

Read More → Use Tool →
2026-06-04SecurityWeek
VS Code Vulnerability Allows One-Click GitHub Token Theft

A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance. The post VS Code Vulnerability Allows One-Click GitHub T...

Read More → Use Tool →
2026-06-04The Record
CISA to Issue Binding AI Directive This Week, Acting Director Says

The Cybersecurity and Infrastructure Security Agency (CISA) will release a binding operational directive (BOD) to federal agencies by the end of the week, directing them on how to ...

AI SecurityRegulationVulnerability
Read More → Use Tool →
2026-06-04Dark Reading
Pakistan Deploys Xeno RAT to Spy on Afghan Finance Ministry

A state-sponsored cyber-espionage campaign attributed to Pakistan-linked threat actors has been uncovered targeting Afghanistan's Ministry of Finance, leveraging the open-source Xe...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-03The Hacker News
Google DoubleClick Abused in New Malspam Campaign to Deliver .NET Loader

Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver an unidentified .NET-...

Read More → Use Tool →
2026-06-03The Hacker News
Microsoft Fixes One-Click GitHub Dev Attack That Let Attackers Steal OAuth Tokens

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a l...

Read More → Use Tool →
2026-06-03BleepingComputer
U.S. sanctions Nobitex crypto exchange used by Iranian ransomware actors

The U.S. Treasury's Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments related to te...

Read More → Use Tool →
2026-06-03The Hacker News
Poisoned Notifications Could Hijack Google Gemini on Android

A single malicious notification pushed through WhatsApp, Slack, SMS, Signal, Instagram, or Messenger was enough to hijack Google Gemini's voice assistant on Android, according to r...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-03The Hacker News
Google DoubleClick Abused to Deliver DesckVB RAT in Malspam Campaign

Cybersecurity researchers at Huntress have uncovered a sophisticated malspam campaign that exploits Google's DoubleClick domain to bypass security filters and deliver a remote acce...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-03The Hacker News
Microsoft 365 Android Bug Let Any App Steal User Account Tokens

A single leftover debug flag in production builds of several Microsoft 365 Android applications disabled a critical security check, allowing any app installed on the same device to...

VulnerabilityAuthentication
Read More → Use Tool →
2026-06-03The Hacker News
Autonomous AI Uncovers 2-Year-Old Redis RCE Flaw (CVE-2026-23479)

Redis has patched a use-after-free vulnerability in its blocking-client code that allows an authenticated user to execute arbitrary OS commands on the host running the database. Tr...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-06-03BleepingComputer
Chinese hackers use new Atlas RAT malware in European cyberattacks

A Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor. [...]...

Read More → Use Tool →
2026-06-03BleepingComputer
The U.S. sanctions Nobitex crypto exchange used by ransomware

The U.S. Treasury's Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments related to te...

Read More → Use Tool →
2026-06-03BleepingComputer
CISA warns of cyberattacks targeting fuel tank monitoring systems

CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used t...

Read More → Use Tool →
2026-06-03BleepingComputer
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute

A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds. [...]...

Read More → Use Tool →
2026-06-03Dark Reading
Attackers Use AI to Automate EDR Evasion Testing

Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender....

Read More → Use Tool →
2026-06-03Dark Reading
Tropical Blend: Cyber & Politics Ramp Up Across Latin America

China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests....

Read More → Use Tool →
2026-06-03Dark Reading
Cyber Insurance Rates Are Dropping, but Exclusions Widen

Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix....

Read More → Use Tool →
2026-06-03Dark Reading
Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover

A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and dat...

Read More → Use Tool →
2026-06-03The Record
DHS chief signals efforts to reshape CISA

In his first appearance before the panel since being confirmed in March, Mullin said that CISA probably needs “somewhere around” 2,800 employees, despite its ability to hire up to ...

Read More → Use Tool →
2026-06-03The Hacker News
One-Click GitHub.dev Attack Steals Full OAuth Tokens via VS Code

Cybersecurity researchers have disclosed a critical one-click attack chain that abuses Microsoft Visual Studio Code (VS Code) webviews to steal fully scoped GitHub OAuth tokens. Di...

VulnerabilityAuthenticationSupply Chain
Read More → Use Tool →
2026-06-03The Hacker News
IVIP: Closing the Identity Dark Matter Gap in Enterprise IAM

Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...

AuthenticationAI SecurityCloud Security
Read More → Use Tool →