HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1333 篇文章,第 24 / 45 頁

2026-05-22The Hacker News
Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known a...

Read More → Use Tool →
2026-05-22The Hacker News
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabili...

Read More → Use Tool →
2026-05-22BleepingComputer
US and Canada arrest and charge suspected Kimwolf botnet admin

U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices ...

Read More → Use Tool →
2026-05-22Dark Reading
China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.

The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker....

Read More → Use Tool →
2026-05-22SecurityWeek
‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested

The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. The post ‘First VPN’ Cybercrime Service Disrupted, Admini...

Read More → Use Tool →
2026-05-22SecurityWeek
TrendAI Patches Apex One Zero-Day Exploited in the Wild

CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appe...

Read More → Use Tool →
2026-05-22SecurityWeek
Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. The post Grafana Says Codebase and Other Data Stolen via TanStack S...

Read More → Use Tool →
2026-05-22The Hacker News
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked ...

Read More → Use Tool →
2026-05-21The Record
Belarus-linked hackers use fake training certificates to target Ukrainian officials

A Belarus-linked hacking group known as GhostWriter has launched a new espionage campaign against Ukrainian government officials using fake emails disguised as messages from a popu...

Read More → Use Tool →
2026-05-21The Record
Hackers steal patient and billing data from German hospitals via third-party provider

The large-scale data breach reportedly hit Unimed, a company that handles billing services for privately insured and self-paying patients on behalf of numerous German hospitals....

Read More → Use Tool →
2026-05-21BleepingComputer
Google Leaks Unfixed Chromium Flaw Enabling Silent JS Botnet

Google inadvertently exposed technical details of an unfixed Chromium vulnerability that allows JavaScript to persist in the background after the browser is closed, effectively giv...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-05-21KrebsOnSecurity
Kimwolf Botnet Operator 'Dort' Arrested in Canada, Charged in US

Jacob Butler, known in cybercrime circles as "Dort," has been arrested in Canada and faces criminal charges in both the United States and Canada for allegedly operating the Kimw...

MalwareThreat Intel
Read More → Use Tool →
2026-05-21Dark Reading
How CISOs Should Prep for Agentic-Ready AI BOMs

Finding ways to document both component and execution attributes for AI bill of materials (AI BOM)....

Read More → Use Tool →
2026-05-21Dark Reading
Google API Keys Remain Active After Deletion

A security researcher discovered the API keys can still be used for 23 minutes after deletion, even though the cloud provider claims deletion is immediate....

Read More → Use Tool →
2026-05-21The Record
Tech giants promise British regulator they will tweak platforms to protect kids online

The regulator, Ofcom, had required Roblox, Snapchat, Instagram, Facebook, YouTube and TikTok to answer questions about their efforts to remove harmful algorithms, check kids’ ages ...

Read More → Use Tool →
2026-05-21The Record
Two Americans plead guilty to assisting India-based tech support scam centers

Adam Young, 42, and Harrison Gevirtz, 33, pleaded guilty to misprision of a felony after they were accused of offering phone numbers, call routing services, call tracking tools and...

Read More → Use Tool →
2026-05-21The Hacker News
Showboat Linux Malware Targets Middle East Telecom with SOCKS5 Backdoor

Cybersecurity researchers from Lumen Technologies Black Lotus Labs have uncovered a sophisticated Linux malware campaign targeting a telecommunications provider in the Middle East ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-05-21The Hacker News
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: a...

Read More → Use Tool →
2026-05-21BleepingComputer
Apple blocked over $11 billion in App Store fraud in 6 years

Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transaction...

Read More → Use Tool →
2026-05-21BleepingComputer
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet

Modern crypto drainers don't hack wallets. They trick users into approving malicious transactions. Flare explores how the Lucifer DaaS platform scales wallet theft through phishin...

Read More → Use Tool →
2026-05-21BleepingComputer
Chinese hackers target telcos with new Linux, Windows malware

A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively. [....

Read More → Use Tool →
2026-05-21BleepingComputer
Max severity Cisco Secure Workload flaw gives Site Admin privileges

Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin privileges. [...]...

Read More → Use Tool →
2026-05-21BleepingComputer
Police seize “First VPN” service used in ransomware, data theft attacks

A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcement operation. [...]...

Read More → Use Tool →
2026-05-21Dark Reading
AI Agents Are Shifting Identity Security Budget Dynamics

AI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent ide...

Read More → Use Tool →
2026-05-21Dark Reading
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks

"Showboat" doesn't show off, but clearly it doesn't need to, as it's long helped China spy on small market communications providers....

Read More → Use Tool →
2026-05-21Dark Reading
Content Delivery Exploit Opens Websites to Brand Hijacking

The Underminr domain-fronting attack allows threat actors to modify Web requests and leverage trusted websites to cloak malicious activity....

Read More → Use Tool →
2026-05-21SecurityWeek
Cisco Patches Critical Vulnerability in Secure Workload

Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges. The post Cisco Patches Critical Vulnerability in ...

Read More → Use Tool →
2026-05-21The Record
UK plans for cybercrime law reform would protect almost no one, experts warn

The proposals would require researchers to cease activity the moment a vulnerability is identified, meaning they could not confirm it was real, assess its severity or determine its...

Read More → Use Tool →
2026-05-21The Hacker News
Microsoft Defender Zero-Days Actively Exploited; Added to CISA KEV

Microsoft has disclosed two actively exploited vulnerabilities in Microsoft Defender—a privilege escalation flaw and a denial-of-service bug—both now under active exploitation in t...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-21The Hacker News
Identity is the Attack Path: Cloud Security Risks in 2025

A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...

Cloud SecurityAuthenticationAI Security
Read More → Use Tool →