HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1314 篇文章,第 22 / 44 頁

2026-05-25SecurityWeek
Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack. The post Ghost CMS Vulnerability Exploited to Hack Ove...

Read More → Use Tool →
2026-05-25SecurityWeek
Oncology Institute Discloses Data Breach

The affected third-party vendor has not been named, but one possible candidate is TriZetto. The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek....

Read More → Use Tool →
2026-05-25SecurityWeek
Radiology Associates of Richmond Data Breach: 266,000 Affected

Radiology Associates of Richmond (RAR), a Richmond, Virginia-based medical imaging services provider, has disclosed a significant data breach affecting 266,183 individuals. The bre...

Data BreachPrivacy
Read More → Use Tool →
2026-05-25The Hacker News
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financia...

Read More → Use Tool →
2026-05-25The Hacker News
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed Tr...

Read More → Use Tool →
2026-05-25SecurityWeek
Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.  The post Anthropic: Mythos Detected 23,000 Potential Vu...

Read More → Use Tool →
2026-05-25SecurityWeek
Laravel-Lang Packages Poisoned for Malware Delivery

Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first o...

Read More → Use Tool →
2026-05-25SecurityWeek
DocketWise Data Breach Impacts 143,000

Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories. The post DocketWise Data Breach Impacts 1...

Read More → Use Tool →
2026-05-25SecurityWeek
Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub Repositories Infected in...

Read More → Use Tool →
2026-05-24BleepingComputer
Ghost CMS CVE-2026-26980 SQL Injection Powers ClickFix Campaign

A coordinated campaign is actively exploiting a critical SQL injection flaw (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript that drives a ClickFix attack flow. Discove...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-05-23BleepingComputer
Laravel Lang Supply Chain Attack Deploys Credential-Stealing Malware

A sophisticated supply chain attack has compromised the Laravel Lang localization packages, affecting four repositories and potentially hundreds of historical versions. Security re...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-05-23The Hacker News
Anthropic's Claude Mythos Finds 10,000 High-Severity Flaws in Software

Anthropic's Project Glasswing initiative has uncovered more than 10,000 high- or critical-severity vulnerabilities across systemically important software globally since its launch ...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-05-23The Hacker News
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the package...

Read More → Use Tool →
2026-05-23The Hacker News
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases U...

Read More → Use Tool →
2026-05-23BleepingComputer
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes

Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spoti...

Read More → Use Tool →
2026-05-23The Hacker News
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive c...

Read More → Use Tool →
2026-05-23The Hacker News
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS scor...

Read More → Use Tool →
2026-05-23The Hacker News
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (K...

Read More → Use Tool →
2026-05-23SecurityWeek
‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability ...

Read More → Use Tool →
2026-05-23The Record
CISA Launches Form for Researchers to Report Exploited Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new nomination form enabling security researchers, vendors, and industry partners to submit vulnerabiliti...

VulnerabilityThreat IntelBug Bounty
Read More → Use Tool →
2026-05-22The Hacker News
Operation Saffron Takes Down First VPN Used by 25 Ransomware Groups

Authorities in Europe and North America have successfully dismantled First VPN, a criminal VPN service specifically designed to anonymize ransomware operations and other cyberattac...

RansomwareThreat IntelPrivacy
Read More → Use Tool →
2026-05-22The Record
FBI Warns of Kali365 Phishing Service Targeting Microsoft 365

The FBI has issued a critical advisory regarding Kali365, a Telegram-based Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to compromise Microsoft 365 accounts b...

PhishingCloud SecurityAuthentication
Read More → Use Tool →
2026-05-22The Record
Meta settles school district lawsuit claiming addictive design harmed students' mental health

The bellwether lawsuit was the first of at least 1,200 to be brought by a school district against Meta, Snap, YouTube and TikTok for similar alleged harms. The other cases have not...

Read More → Use Tool →
2026-05-22The Hacker News
Ghostwriter APT Targets Ukraine Gov with Prometheus Phishing Malware

The Belarus-aligned threat actor Ghostwriter, also tracked as UAC-0057 and UNC1151, has been observed conducting sophisticated phishing campaigns against Ukrainian government entit...

APTPhishingMalware
Read More → Use Tool →
2026-05-22The Hacker News
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour...

Read More → Use Tool →
2026-05-22The Hacker News
Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective

1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed fo...

Read More → Use Tool →
2026-05-22BleepingComputer
Netherlands seizes 800 servers of hosting firm enabling cyberattacks

Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, ...

Read More → Use Tool →
2026-05-22BleepingComputer
Former US execs plead guilty to aiding tech support scammers

Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]...

Read More → Use Tool →
2026-05-22BleepingComputer
Trend Micro warns of Apex One zero-day exploited in the wild

Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. [...]...

Read More → Use Tool →
2026-05-22BleepingComputer
Drupal: Critical SQL injection flaw now targeted in attacks

Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. [...]...

Read More → Use Tool →