HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1271 篇文章,第 4 / 43 頁

2026-06-11BleepingComputer
Coupang hit with record $409 million data breach fine in Korea

​​The Personal Information Protection Commission (PIPC), South Korea's data protection regulator, has fined e-commerce giant Coupang a record 624.6 billion won (roughly $409 millio...

Read More → Use Tool →
2026-06-11BleepingComputer
CISA tells govt agencies to patch critical exploited flaws in 3 days

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Execut...

Read More → Use Tool →
2026-06-11Dark Reading
Segmentation Works for OT If Operators Are Paying Attention

Operational technology security remains as difficult as ever, with even the best practice recommendation falling short....

Read More → Use Tool →
2026-06-11SecurityWeek
Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks

Oracle has released mitigations for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses PeopleSoft Vulnerabilit...

Read More → Use Tool →
2026-06-11SecurityWeek
Alert Fatigue Is Becoming a Security Threat of Its Own

As alert volumes outpace human capacity, organizations are turning to AI, automation, and deeper context to separate real threats from the noise. The post Alert Fatigue Is Becoming...

Read More → Use Tool →
2026-06-11SecurityWeek
CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk

The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries. The post CISA Directs Federal Agencies to Prioritize...

Read More → Use Tool →
2026-06-11SecurityWeek
OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month

Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution te...

Read More → Use Tool →
2026-06-11The Record
Cyber Force not included in Senate defense policy roadmap

An amendment by Sen. Kirsten Gillibrand (D-NY) to the chamber’s fiscal 2027 national defense authorization bill that would have created the digital-focused service was defeated 14-...

Read More → Use Tool →
2026-06-11The Record
British high school sends students home following cyberattack

Great Marlow School, which has 1,428 pupils according to the Department for Education (DfE), said it was set to remain closed while it works with specialist IT and cybersecurity pr...

Read More → Use Tool →
2026-06-11The Record
Hacker linked to Void Blizzard faces charges over cyberespionage campaign

Denis Obrezko, 36, made his initial appearance in federal court in Boston on Tuesday after being transferred to U.S. custody from Thailand, where he was arrested last November....

Read More → Use Tool →
2026-06-11The Record
University of Nottingham confirms cyber incident as Shiny Hunters group claims data theft

According to the university’s statement, it is still working to understand what data has been accessed and said it had already directly contacted affected students and alumni, pote...

Read More → Use Tool →
2026-06-11The Hacker News
OceanLotus APT Targets Vietnam with SPECTRALVIPER in FireAnt Supply Chain Attack

Vietnam-aligned threat actor OceanLotus has been linked to two parallel cyber-espionage campaigns targeting domestic entities, leveraging its signature SPECTRALVIPER backdoor in a ...

APTSupply ChainThreat Intel
Read More → Use Tool →
2026-06-11The Hacker News
GitHub npm v12 Disables Install Scripts to Block Supply Chain Attacks

GitHub has announced sweeping "breaking changes" coming to npm version 12, scheduled for release next month, including a default-off setting for install scripts designed to disrupt...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-06-11The Hacker News
AI Compressed Time-to-Exploit to 24 Hours: Why CISOs Are Switching to BAS

For three decades, vulnerability management depended on a buffer: the months between disclosure and weaponization. Triage by severity, schedule remediation, validate, and move on. ...

AI ThreatsVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-11BleepingComputer
Microsoft fixes BitLocker recovery bug on Windows Server 2025

Microsoft has resolved a known issue causing some Windows Server 2025 devices to boot into BitLocker recovery after installing the April 2026 security update. [...]...

Read More → Use Tool →
2026-06-11BleepingComputer
Nottingham University data breach affects over 450,000 students

The University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums. [...]...

Read More → Use Tool →
2026-06-11BleepingComputer
Max severity Ivanti Sentry vulnerability now exploited in attacks

Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways...

Read More → Use Tool →
2026-06-11SecurityWeek
Hackers Exploit Langflow Vulnerability for Remote Code Execution

Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for R...

Read More → Use Tool →
2026-06-11SecurityWeek
Siemens Says Desigo CC Files Flagged as Malware by Security Engines

A PowerShell script included in patch files appears to be triggering false positives by multiple security engines. The post Siemens Says Desigo CC Files Flagged as Malware by Secur...

Read More → Use Tool →
2026-06-11SecurityWeek
FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers

The 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances The post FBI Seizes 13 Websi...

Read More → Use Tool →
2026-06-11SecurityWeek
Splunk, Palo Alto Networks Patch Severe Vulnerabilities

The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources. The post Splunk, Palo Alto Networks Patch Severe Vulnerabi...

Read More → Use Tool →
2026-06-11SecurityWeek
‘GreatXML’ Zero-Day Exploit Bypasses BitLocker

The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appe...

Read More → Use Tool →
2026-06-11SecurityWeek
University of Nottingham Confirms Breach After Hackers Leak Data

The ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information. The post University of Nottingham Confirms Breach Af...

Read More → Use Tool →
2026-06-11SecurityWeek
Microsoft Patches Exploited Exchange Server Vulnerability

The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.  The post Microsoft Patches Exploited Exchange Server Vulnerability...

Read More → Use Tool →
2026-06-11Dark Reading
Chinese and North Korean APT Groups Expand After Asia-Pacific Success

State-sponsored threat actors from China and North Korea are scaling up cyber operations across the Asia-Pacific region, leveraging tactical gains to pursue higher-value targets in...

APTThreat Intel
Read More → Use Tool →
2026-06-10The Hacker News
Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE

A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, acco...

Read More → Use Tool →
2026-06-10Dark Reading
AI Risk Worries Insurers & Businesses Alike

As companies adopt AI, many insurance firms are explicitly excluding AI risks, while others are forging ahead to create the right framework. What risks can firms reasonably manage?...

Read More → Use Tool →
2026-06-10BleepingComputer
Hackers Actively Exploit Path Traversal Flaw in AI Platform Langflow

Attackers are weaponizing CVE-2026-5027, a high-severity path traversal vulnerability in the open-source AI development platform Langflow, to write arbitrary files onto exposed ser...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-06-10BleepingComputer
The ‘Miasma’ worm source code briefly leaked on GitHub

The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain attacks, was briefly open-sourced on GitHub. [...]...

Read More → Use Tool →
2026-06-10BleepingComputer
GitHub announces npm security changes to tackle supply-chain attacks

GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the 'n...

Read More → Use Tool →