HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1314 篇文章,第 17 / 44 頁

2026-05-31The Hacker News
Dutch Police Takedown 17M Device Botnet Linked to Asocks Proxy Service

Dutch authorities have successfully dismantled a massive botnet infrastructure responsible for enslaving approximately 17 million compromised devices, including computers, tablets,...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-05-31BleepingComputer
Critical WP Maps Pro Zero-Day Allows Admin Account Creation

Security researchers have identified active exploitation of a critical zero-day vulnerability in the WP Maps Pro WordPress plugin, tracked as CVE-2026-8732 with a severity rating o...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-05-30BleepingComputer
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate...

Read More → Use Tool →
2026-05-30BleepingComputer
New CIFSwitch Linux flaw gives root on multiple distributions

A newly discovered local privilege escalation vulnerability dubbed 'CIFSwitch' in the Linux kernel could allow attackers to forge CIFS authentication key descriptions, abuse the ke...

Read More → Use Tool →
2026-05-30SecurityWeek
Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say

Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key infrastructure. The ...

Read More → Use Tool →
2026-05-30SecurityWeek
Exploit Code Published for Critical Flowise RCE Vulnerability

The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow. The post Exploit Code P...

Read More → Use Tool →
2026-05-30The Hacker News
CVE-2026-0257: PAN-OS GlobalProtect Bypass Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a medium-severity authentication bypass vulnerability (CVSS 7.8) affecting PAN-OS and Prisma Access GlobalPro...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-05-29The Hacker News
New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 20...

Read More → Use Tool →
2026-05-29BleepingComputer
California AG Sues 23andMe Over 2023 Data Breach Exposing 7M Customers

California Attorney General Rob Bonta has filed a lawsuit against 23andMe (now Chrome Holding Co.) for failing to protect sensitive customer genetic and personal information during...

Data BreachPrivacyRegulation
Read More → Use Tool →
2026-05-29The Hacker News
ChatGPhish Vulnerability Exposes ChatGPT to Phishing Attacks

Security researchers at Permiso Security have uncovered a critical vulnerability in OpenAI's ChatGPT, dubbed ChatGPhish, that transforms the AI assistant's web summarization featur...

VulnerabilityLLM SecurityPhishing
Read More → Use Tool →
2026-05-29BleepingComputer
ChatGPT share links abused to host fake outage pages to deliver malware

Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. ...

Read More → Use Tool →
2026-05-29Dark Reading
Name That Toon: Mark of (Cybersecurity) Progress

As part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry's last two decades....

Read More → Use Tool →
2026-05-29The Hacker News
LLM Agent Used in Post-Exploitation After Marimo CVE-2026-39987 Exploit

Sysdig researchers have documented a sophisticated cyberattack where threat actors deployed a large language model (LLM) agent to automate post-exploitation activities following th...

LLM SecurityVulnerabilityCloud Security
Read More → Use Tool →
2026-05-29The Hacker News
New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 20...

Read More → Use Tool →
2026-05-29BleepingComputer
From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market

DDoS attacks are increasingly being sold like subscription services, complete with pricing tiers, support, and reseller programs. Flare explores how the DDoS-as-a-Service market ha...

Read More → Use Tool →
2026-05-29BleepingComputer
Dutch govt disrupts malware botnet with 17 million infected devices

Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. [...]...

Read More → Use Tool →
2026-05-29BleepingComputer
Google Chrome adds session cookie theft protection for all users

Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers. [...]...

Read More → Use Tool →
2026-05-29Dark Reading
Asia's Cyber Insurance Market Shows Signs of Life

The cyber insurance industry has made relatively weak inroads into Asia due to a a variety of factors, but that could be changing....

Read More → Use Tool →
2026-05-29Dark Reading
With Complex Cloud Integrations, Small Errors Lead to Major Compromises

Researchers discover an exploit chain combining over-permissioned roles, secrets discovery, and non-human identities that could have compromised a popular automation service....

Read More → Use Tool →
2026-05-29SecurityWeek
In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks

Noteworthy stories that might have slipped under the radar: Trump Mobile exposes customer data, phishers target the 2026 FIFA World Cup, CISA responds to recent supply chain attack...

Read More → Use Tool →
2026-05-29SecurityWeek
Charter Communications Data Breach Could Impact Nearly 5 Million

The notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April. The post Charter Communications Data Breach Could Impact Nearly 5 ...

Read More → Use Tool →
2026-05-29SecurityWeek
MokN Raises $15 Million for Phish-Back Platform

MokN's platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse occurs. The post MokN...

Read More → Use Tool →
2026-05-29SecurityWeek
Gogs Zero-Day Exposes Servers to Remote Code Execution

The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch na...

Read More → Use Tool →
2026-05-29The Record
Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more

Each vulnerability was published with working proof-of-concept code to the Microsoft-owned code repository GitHub, making them immediately available to both attackers and security ...

Read More → Use Tool →
2026-05-29The Hacker News
Shadow Builders: 2,000+ Vibe-Coded Apps Expose Corporate Data

Security researchers at Red Access have uncovered a alarming trend in enterprise data exposure through what they term the 'Shadow Builders' phenomenon. In a comprehensive investiga...

AI SecurityData BreachVulnerability
Read More → Use Tool →
2026-05-29The Hacker News
Malicious Sicoob NuGet Package Steals Banking Credentials from Developers

Cybersecurity researchers have uncovered a malicious NuGet package disguised as an official C# software development kit for Sicoob, one of Brazil's largest cooperative financial sy...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-05-29The Hacker News
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corpora...

Read More → Use Tool →
2026-05-29BleepingComputer
Man sent to prison for selling data of 7 millions elderly Americans

A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers. [...]...

Read More → Use Tool →
2026-05-29BleepingComputer
US charges Google security engineer with Polymarket insider trading

A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentra...

Read More → Use Tool →
2026-05-29BleepingComputer
Charter Communications data breach affects 4.9 million accounts

The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data b...

Read More → Use Tool →