HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1348 篇文章,第 32 / 45 頁

2026-05-14SecurityWeek
Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million

The acquisition enables Akamai to expand its Zero Trust portfolio to add protection directly into the browser. The post Akamai to Acquire AI and Browser Security Firm LayerX for $2...

Read More → Use Tool →
2026-05-14SecurityWeek
Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns

Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT. The post Chinese APTs Expand Targets, Update Backdoors in Recent...

Read More → Use Tool →
2026-05-14The Hacker News
New Fragnesia Linux Kernel Flaw Grants Root via Page Cache Corruption

Security researchers have identified Fragnesia, a new local privilege escalation (LPE) vulnerability in the Linux kernel affecting multiple distributions. Tracked as CVE-2026-46300...

VulnerabilityZero-Day
Read More → Use Tool →
2026-05-14The Hacker News
Windows Zero-Days Expose BitLocker Bypass and CTFMON Privilege Escalation

Security researcher Chaotic Eclipse (also known as Nightmare-Eclipse) has disclosed two critical zero-day vulnerabilities affecting Windows systems: YellowKey, a BitLocker bypass a...

Zero-DayVulnerabilityEncryption
Read More → Use Tool →
2026-05-14The Hacker News
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years. The...

Read More → Use Tool →
2026-05-14BleepingComputer
Dell confirms its SupportAssist software causes Windows BSOD crashes

Dell confirmed that its SupportAssist software is causing blue-screen crashes on some Windows systems following a wave of user reports about random reboots affecting Dell devices s...

Read More → Use Tool →
2026-05-14BleepingComputer
US charges suspected Dream Market admin arrested in Germany

The alleged main administrator of Dream Market Incognito Market, one of the largest dark web marketplaces before its shutdown, has been indicted in the United States on money laund...

Read More → Use Tool →
2026-05-14BleepingComputer
New Fragnesia Linux flaw lets attackers gain root privileges

Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to...

Read More → Use Tool →
2026-05-14Dark Reading
Foxconn Attack Highlights Manufacturing's Cyber Crisis

A Nitrogen ransomware attack on Foxconn's North American facilities is one of 600 hits on manufacturers this year, as gangs increasingly target the sector for its low tolerance for...

Read More → Use Tool →
2026-05-14SecurityWeek
G7 Countries Release AI SBOM Guidance

The goal of the guidance, which outlines minimum elements, is to help organizations enhance transparency in AI systems and supply chains.  The post G7 Countries Release AI SBOM Gui...

Read More → Use Tool →
2026-05-14SecurityWeek
F5 Patches Over 50 Vulnerabilities

The company’s latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX. The post F5 Patches Over 50 Vulnerabilities appeared first on Securi...

Read More → Use Tool →
2026-05-14SecurityWeek
Hackers Targeted PraisonAI Vulnerability Hours After Disclosure

The first exploitation attempts were observed less than four hours after the authentication bypass was publicly disclosed. The post Hackers Targeted PraisonAI Vulnerability Hours A...

Read More → Use Tool →
2026-05-14SecurityWeek
High-Severity Vulnerability Patched in VMware Fusion

The patch was announced as Broadcom is attending the Pwn2Own hacking competition in Berlin this week. The post High-Severity Vulnerability Patched in VMware Fusion appeared first o...

Read More → Use Tool →
2026-05-14SecurityWeek
Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

YellowKey is a BitLocker bypass that requires physical access. GreenPlasma enables elevation of privileges to System. The post Researcher Drops YellowKey, GreenPlasma Windows Zero-...

Read More → Use Tool →
2026-05-13Dark Reading
Checkbox Assessments Aren't Fit to Measure Risk

Security governance needs to be more than an annual compliance exercise. New companies are emerging to address risk-management gaps in current audit tools....

Read More → Use Tool →
2026-05-13BleepingComputer
West Pharma Cyberattack: Data Stolen, Systems Encrypted

West Pharmaceutical Services, a $3 billion S&P 500 drug‑packaging firm, disclosed on May 13, 2026 that it was hit by a material cyberattack. The company detected the intrusion on M...

Data BreachRansomware
Read More → Use Tool →
2026-05-13BleepingComputer
Iranian hackers targeted major South Korean electronics maker

The Iran-linked hacking group MuddyWater (a.k.a. Seedworm, Static Kitten) launched a broad cyber-espionage campaign targeting at least nine high-profile organizations across multip...

Read More → Use Tool →
2026-05-13BleepingComputer
New critical Exim mailer flaw allows remote code execution

A critical vulnerability affecting certain configurations of the Exim open-source mail transfer agent could be exploited by an unauthenticated remote attacker to execute arbitrary ...

Read More → Use Tool →
2026-05-13Dark Reading
Checkbox Assessments Aren't Fit to Measure to Risk

Security governance needs to be more than an annual compliance exercise. New companies are emerging to address risk-management gaps in current audit tools....

Read More → Use Tool →
2026-05-13Dark Reading
Attackers Weaponize RubyGems for Data Dead Drops

Threat actors are publishing RubyGems packages that include scrapers targeting public-facing UK government servers, but with no clear objective....

Read More → Use Tool →
2026-05-13Dark Reading
Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak

An OPSEC failure provides a window into what helped the ransomware group rise: a generous affiliate model, opportunistic TTPs, and an effective organizational structure....

Read More → Use Tool →
2026-05-13Dark Reading
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape

Informa TechTarget's flagship cybersecurity media brand launches a special content series to mark two decades as a trusted source for cybersecurity professionals....

Read More → Use Tool →
2026-05-13The Record
Alleged Dream Market admin arrested in Germany after US indictment

Court documents said Dream Market was launched in 2013 by Owe Martin Andresen and others before becoming one of the biggest criminal marketplaces online....

Read More → Use Tool →
2026-05-13The Hacker News
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's be...

Read More → Use Tool →
2026-05-13The Hacker News
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

A threat actor with affiliations to China has been linked to a "multi-wave intrusion" targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late Febru...

Read More → Use Tool →
2026-05-13The Hacker News
[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud

TL;DR: Stop chasing thousands of "toast" alerts. Join experts from Wiz to learn how hackers connect tiny flaws to build a "Lethal Chain" to your data—and how to break it. Register ...

Read More → Use Tool →
2026-05-13The Hacker News
Most Remediation Programs Never Confirm the Fix Actually Worked

Security teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed. Mandiant's M-Trends 2026 report puts the mean ...

Read More → Use Tool →
2026-05-13The Hacker News
Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active atta...

Read More → Use Tool →
2026-05-13BleepingComputer
Windows BitLocker zero-day gives access to protected drives, PoC released

A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker ...

Read More → Use Tool →
2026-05-13BleepingComputer
Webinar tomorrow: Why security alone won't stop modern attacks

Tomorrow's webinar examines why prevention alone is no longer enough against modern cyberattacks. The session explores how organizations combine security, backups, and recovery pla...

Read More → Use Tool →