HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1359 篇文章,第 41 / 46 頁

2026-05-04BleepingComputer
Progress Warns of Critical MOVEit Automation Auth Bypass (CVE-2025-2025)

Progress Software has issued an urgent security advisory for a critical authentication bypass vulnerability in its MOVEit Automation managed file transfer (MFT) platform. Tracked a...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-05-04BleepingComputer
MSPs: Strengthen Security & Backup with SaaS BCDR

Kaseya announced a live webinar titled “Why MSPs must rethink security and backup strategies” scheduled for June 15, 2026 at 2:00 PM ET. The session, hosted by Kaseya’s Product Mar...

Cloud SecurityIncident ResponseRansomware
Read More → Use Tool →
2026-05-04BleepingComputer
CISA Warns: Copy Fail Linux Flaw Exploited for Root Access

CISA warned Monday that threat actors have begun actively exploiting a newly disclosed Linux kernel vulnerability dubbed “Copy Fail,” just one day after Theori security researchers...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Windows April Updates Trigger Backup Application Failures

Microsoft has confirmed that the security updates released on April 2026 for Windows are causing serious failures in third‑party backup applications that rely on the psmounterex.sy...

VulnerabilityIncident Response
Read More → Use Tool →
2026-05-03The Hacker News
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-31431, a critical Linux kernel privilege escalation vulnerability, to its Known Exploited Vulner...

VulnerabilityZero-DayCloud Security
Read More → Use Tool →
2026-05-03BleepingComputer
Instructure Data Breach: ShinyHunters Claim 4.5M Records Stolen

Instructure, the educational technology company behind the popular Canvas learning‑management system, confirmed on March 5 2026 that unauthorized actors had accessed its internal n...

Data BreachThreat IntelPrivacy
Read More → Use Tool →
2026-05-03BleepingComputer
Microsoft Defender Flags DigiCert Certs as Trojan, Causing False Positives

On March 24, 2026, Microsoft Defender began flagging legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha after a signature update. The detection impacted multiple...

VulnerabilitySupply ChainIncident Response
Read More → Use Tool →
2026-05-03BleepingComputer
Telegram Mini Apps Abused for Crypto Scams, Android Malware

Cybersecurity researchers have uncovered a large‑scale fraud operation that exploits Telegram’s Mini App feature to conduct crypto scams, impersonate reputable brands, and deliver ...

MalwarePhishing
Read More → Use Tool →
2026-05-02The Hacker News
Trellix Confirms Source Code Breach After Unauthorized Repository Access

Trellix has officially acknowledged a security incident in which an unauthorized party gained access to a portion of its source code repositories. The company said it identified th...

Data BreachSupply Chain
Read More → Use Tool →
2026-05-02BleepingComputer
Critical cPanel Flaw CVE-2026-41940 Fueling 'Sorry' Ransomware Attacks

A newly disclosed vulnerability in cPanel, tracked as CVE-2026-41940, is being actively exploited in the wild as part of a coordinated ransomware campaign dubbed "Sorry." Security ...

RansomwareZero-DayVulnerability
Read More → Use Tool →
2026-05-02BleepingComputer
ConsentFix v3: Automated OAuth Abuse Targets Azure

Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-05-02BleepingComputer
Microsoft Unveils Faster Windows 11 Run Dialog with Dark Mode

Microsoft has begun rolling out a preview of a modernized Run dialog for Windows 11, promising a noticeable boost in responsiveness and the addition of a native dark mode. The upda...

VulnerabilityPrivacy
Read More → Use Tool →
2026-05-01The Hacker News
Vietnamese Hackers Hijack 30K Facebook Accounts via Google AppSheet Phishing

A newly uncovered Vietnamese‑linked phishing campaign has compromised roughly 30,000 Facebook accounts by abusing Google’s low‑code AppSheet platform as a covert relay. Researchers...

PhishingData BreachAPT
Read More → Use Tool →
2026-05-01The Hacker News
Vishing & SSO Abuse Power Rapid SaaS Extortion Attacks

Cybersecurity researchers have identified two distinct cybercrime groups orchestrating rapid, high‑impact extortion campaigns that operate almost entirely within Software‑as‑a‑Serv...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-01The Hacker News
China-Linked Hackers Target Asian Governments, NATO State, Activists

Cybersecurity researchers have uncovered a sophisticated espionage operation linked to Chinese state actors, targeting a broad spectrum of victims across Asia and a NATO member sta...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-01The Hacker News
Top 5 Sales Challenges Costing MSPs Cybersecurity Revenue

Managed security services are on a steep ascent, with the market expected to swell from $38.31 billion in 2025 to $69.16 billion by 2030, making cybersecurity the fastest‑growing s...

Cloud SecurityThreat Intel
Read More → Use Tool →
2026-05-01The Hacker News
Cybersecurity Pros Sentenced 4 Years for BlackCat Ransomware Role

The U.S. Department of Justice announced that two former cybersecurity professionals have each been sentenced to four years in federal prison for their roles in enabling BlackCat r...

RansomwareIncident ResponseMalware
Read More → Use Tool →
2026-05-01The Hacker News
Poisoned Ruby Gems and Go Modules Hijack CI Pipelines for Credential Theft

Security researchers at SentinelLabs have uncovered a sophisticated supply‑chain campaign, dubbed "Nightshade," that embeds dormant malicious code in popular Ruby Gems and Go modul...

Supply ChainMalware
Read More → Use Tool →
2026-05-01Dark Reading
North Korean APTs Dominate 2026 Crypto Theft, AI in the Mix

North Korean advanced persistent threat (APT) groups have consolidated their dominance over the cryptocurrency threat landscape in 2026, accounting for an estimated 76 % of all dig...

APTAI ThreatsThreat Intel
Read More → Use Tool →
2026-05-01Dark Reading
Why AI Integrations Are Deleting Production Databases

The rapid adoption of AI agents in production environments has uncovered a troubling trend: systems that are supposed to enhance operational efficiency are instead causing catastro...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-05-01Dark Reading
Join Our Caption Contest: Celebrate 20 Years of Cybersecurity Progress

Dark Reading is inviting security professionals and enthusiasts to take part in a caption contest that reflects on two decades of cybersecurity evolution. The competition, titled "...

VulnerabilityPrivacy
Read More → Use Tool →
2026-05-01Dark Reading
Dark Reading Celebrates 20 Years of Cybersecurity Coverage

Dark Reading marks its 20th anniversary this month, reflecting on two decades of delivering timely cybersecurity news, analysis, and insights to professionals worldwide. Launched o...

Threat IntelPrivacyRegulation
Read More → Use Tool →
2026-05-01BleepingComputer
Instructure Discloses Cyber Incident, Investigates Impact on Canvas Platform

Instructure, the company behind the widely used Canvas learning management system, disclosed on March 2 2026 that it had identified a cyber incident affecting its internal infrastr...

Data BreachIncident Response
Read More → Use Tool →
2026-05-01BleepingComputer
15-Year-Old Detained Over France Titres Data Breach

French police (the Direction centrale de la police judiciaire, DCPJ) and the Paris Prosecutor’s Office have detained a 15‑year‑old, known by the alias "M4L", on suspicion of sellin...

Data BreachPrivacy
Read More → Use Tool →
2026-05-01BleepingComputer
BleepingComputer Retracts Instructure Data Breach Story After Review

BleepingComputer published a story on March 5, 2026 claiming that Instructure, the education‑technology company behind the Canvas learning‑management platform, had suffered a new d...

Data BreachPrivacy
Read More → Use Tool →
2026-05-01BleepingComputer
Criminal IP and Securonix ThreatQ Team Up to Boost Threat Intel

Criminal IP, a provider of exposure‑based threat intelligence, announced a partnership with Securonix to embed its rich contextual data directly into the Securonix ThreatQ platform...

Threat IntelIncident Response
Read More → Use Tool →
2026-05-01BleepingComputer
Microsoft Fixes Windows Remote Desktop Security Warning Display Issue

Microsoft has resolved a long‑standing rendering bug that caused newly added Remote Desktop Protocol (RDP) file security warnings to appear malformed on Windows 10 (versions 20H2, ...

VulnerabilityIncident Response
Read More → Use Tool →
2026-05-01BleepingComputer
Microsoft Lets Admins Uninstall Pre-installed Store Apps in Windows 11

Microsoft has expanded its Windows 11 in‑box app removal policy by adding a dynamic list that lets IT administrators select exactly which pre‑installed Microsoft Store applications...

PrivacyVulnerability
Read More → Use Tool →
2026-05-01BleepingComputer
Windows 11 KB5083631 Security Update Adds Xbox Mode, 34 Fixes

Microsoft released the optional cumulative update KB5083631 for Windows 11 22H2, delivering 34 changes that span new functionality, performance tweaks, and critical security patche...

VulnerabilityPrivacy
Read More → Use Tool →
2026-05-01BleepingComputer
Former Employees Sentenced 4 Years for BlackCat Ransomware Attacks

A federal court has sentenced two former cybersecurity incident response professionals to four years in prison each for their roles in conducting BlackCat (ALPHV) ransomware attack...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →