HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1333 篇文章,第 25 / 45 頁

2026-05-21The Hacker News
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS...

Read More → Use Tool →
2026-05-21BleepingComputer
Flipper One project needs community help to build open Linux platform

Flipper Devices, the maker of the Flipper Zero pentesting tool, is asking the community to help build Flipper One, an open Linux platform for connected devices. [...]...

Read More → Use Tool →
2026-05-21BleepingComputer
Microsoft warns of new Defender zero-days exploited in attacks

On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. [...]...

Read More → Use Tool →
2026-05-21BleepingComputer
GitHub links repo breach to TanStack npm supply-chain attack

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week's TanStack npm ...

Read More → Use Tool →
2026-05-21SecurityWeek
Ocean Emerges From Stealth With $28M for Agentic Email Security Platform

The company has developed a platform that uses specialized AI agents to inspect every incoming message. The post Ocean Emerges From Stealth With $28M for Agentic Email Security Pla...

Read More → Use Tool →
2026-05-21SecurityWeek
Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions. The post Apple Rejected 2 Million App Store Submissions in 2025 for Security ...

Read More → Use Tool →
2026-05-21SecurityWeek
Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking

CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution. The post Drupal Patches Highly Critical Vulnerabi...

Read More → Use Tool →
2026-05-21SecurityWeek
Socket Raises $60 Million at $1 Billion Valuation

The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion. The post Socket Raises $60 Million at $1 Billion Valuation appe...

Read More → Use Tool →
2026-05-21SecurityWeek
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition. The post Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Da...

Read More → Use Tool →
2026-05-21SecurityWeek
Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI

More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’. The post Google’s Surge in Chrome Vulnerability Discoveries Likely Driven ...

Read More → Use Tool →
2026-05-21SecurityWeek
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking. The post Supply Chain Security Crisis: To...

Read More → Use Tool →
2026-05-21The Hacker News
GitHub Breached via Malicious Nx Console Extension: 3,800 Repos Stolen

GitHub has officially confirmed that the breach of its internal repositories resulted from a compromise of an employee device involving a poisoned version of the Nx Console Microso...

Supply ChainData BreachMalware
Read More → Use Tool →
2026-05-21The Hacker News
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks

Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege ...

Read More → Use Tool →
2026-05-21Dark Reading
Enterprises Boost AI Agent Identity Security Budgets as Omdia Reveals Shifting Priorities

Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-05-20Dark Reading
Processes & Culture Top Reasons Behind Data Breaches

Government leaders revealed that, in spite of state laws meant to improve cyber hygiene, an analysis of incidents showed issues persist and visibility falls short....

Read More → Use Tool →
2026-05-20Dark Reading
Fake Android Apps Commit Carrier Billing Fraud for Premium Services

The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions....

Read More → Use Tool →
2026-05-20The Record
Europe dismantles VPN service used by cybercriminals to hide ransomware attacks

The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way for criminals to evade la...

Read More → Use Tool →
2026-05-20The Record
Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems

In a lengthy joint statement, Moscow and Beijing pledged closer cooperation on satellite internet technologies and joint work on software development and open-source initiatives — ...

Read More → Use Tool →
2026-05-20BleepingComputer
Ukraine Nabs 18-Year-Old Hacker Behind 28K Account Thefts

Ukrainian cyberpolice, working in coordination with U.S. law enforcement, have identified an 18-year-old male from Odesa suspected of orchestrating an infostealer malware operation...

MalwareData BreachThreat Intel
Read More → Use Tool →
2026-05-20BleepingComputer
Hackers bypass SonicWall VPN MFA due to incomplete patching

Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. [...]...

Read More → Use Tool →
2026-05-20Dark Reading
Cyber Pros Can't Decide If AI Is a Good or a Bad Thing

There is nothing cybersecurity professionals are more excited about, and nothing they fear more, than AI....

Read More → Use Tool →
2026-05-20Dark Reading
GitHub Confirms Breach, 4K Internal Repos Stolen

Open source software giant GitHub confirmed a data breach this week involving the theft of thousands of repos. One threat actor — TeamPCP — took credit....

Read More → Use Tool →
2026-05-20Dark Reading
Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs.

The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions....

Read More → Use Tool →
2026-05-20Dark Reading
Processes and Culture Top Reasons Behind Data Breaches

Government leaders revealed that, in spite of state laws meant to improve cyber hygiene, an analysis of incidents showed issues persist and visibility falls short....

Read More → Use Tool →
2026-05-20The Hacker News
Microsoft Open-Sources RAMPART and Clarity for AI Agent Security Testing

Microsoft has unveiled two new open-source security tools—RAMPART and Clarity—to help developers identify and mitigate vulnerabilities in AI agents during the development lifecycle...

AI SecurityLLM Security
Read More → Use Tool →
2026-05-20The Hacker News
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks

Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malicious code and conduct ...

Read More → Use Tool →
2026-05-20The Hacker News
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph...

Read More → Use Tool →
2026-05-20The Hacker News
Agent AI is Coming. Are You Ready?

New Industry Data Just Released Suggests Not. On May 19th, 2026, Orchid Security released the results of our Identity Gap: Snapshot 2026. Among the findings, "identity dark matter...

Read More → Use Tool →
2026-05-20BleepingComputer
Grafana breach caused by missed token rotation after TanStack attack

The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. [...]...

Read More → Use Tool →
2026-05-20BleepingComputer
Identity Alone Isn't Enough: Why Device Security Has to Share the Load

Identity checks alone can't stop attackers using stolen session tokens and compromised devices. Specops Software outlines why Zero Trust strategies increasingly depend on continuou...

Read More → Use Tool →