HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1380 篇文章,第 44 / 46 頁

2026-04-27Dark Reading
Unpatched PhantomRPC Flaw Enables Windows Privilege Escalation Attacks

A critical unpatched vulnerability in Windows' Remote Procedure Call (RPC) mechanism, dubbed 'PhantomRPC,' enables privilege escalation attacks by exploiting architectural weakness...

VulnerabilityZero-Day
Read More → Use Tool →
2026-04-27Dark Reading
Fast16: 20-Year-Old Malware That Predates Stuxnet Found

Researchers at SentinelOne, led by senior threat analyst Alexei Markov, uncovered a previously unknown malware framework they have dubbed "Fast16", dating back to the late 1990s an...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-04-27Dark Reading
Frontier AI Models Spark Cybersecurity Debate Among Experts

The rapid advancement of frontier large language models, including Anthropic's Claude family and OpenAI's rumored GPT-5.5, has ignited fierce debate within the cybersecurity commun...

AI SecurityLLM SecurityAI Threats
Read More → Use Tool →
2026-04-27The Hacker News
Checkmarx Data Leaked on Dark Web After Supply Chain Attack

Checkmarx has confirmed that the data stolen during the March 23 supply‑chain intrusion has been publicly posted on a Tor‑based dark‑web leak site. The company’s incident response ...

Supply ChainData BreachThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Tracking

Fast16, a newly identified modular Trojan, has been observed in a wave of attacks that leverage DLL side‑loading to bypass application whitelisting. Discovered by Cisco Talos on 20...

MalwareAI SecuritySupply Chain
Read More → Use Tool →
2026-04-27The Hacker News
Mythos AI Transforms Vulnerability Discovery, Remediation Gap Widens

Anthropic on April 7 released the public preview of Claude Mythos, a cybersecurity‑focused large language model built on the company’s latest transformer stack. The model ships wit...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-04-27The Hacker News
PhantomCore Exploits TrueConf Flaws to Target Russian Networks

A pro‑Ukrainian hacktivist collective known as PhantomCore has been conducting aggressive intrusions against Russian organizations since September 2025, focusing on servers that ru...

VulnerabilityAPTThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
73 Fake VS Code Extensions Spread GlassWorm v2 Malware

Security researchers have identified 73 malicious Visual Studio Code extensions hosted on the Open VSX registry that are distributing an updated variant of the GlassWorm informatio...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
Fake CAPTCHA IRSF Scam: 120 Keitaro Campaigns Fuel Global SMS and Crypto Fraud

Security researchers at Group-IB have uncovered a large-scale smishing operation that combines fake CAPTCHA verification pages with International Revenue Share Fraud (IRSF) and cry...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-04-25The Hacker News
Pre-Stuxnet 'fast16' Lua Malware Found Targeting Engineering Software

Security researchers at Trend Micro have uncovered a previously unknown Lua‑based malicious framework, dubbed "fast16", that was created several years before the infamous Stuxnet w...

MalwareAPT
Read More → Use Tool →
2026-04-25The Hacker News
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling a...

VulnerabilityRegulationThreat Intel
Read More → Use Tool →
2026-04-24Dark Reading
Helping Romance Scam Victims: Cross-Agency, Proactive Approach

Romance scams, a form of confidence scheme that preys on emotional trust, continue to trap thousands of victims each year. Security analysts note that those who fall prey to these ...

PhishingPrivacyRegulation
Read More → Use Tool →
2026-04-24Dark Reading
US Charges 29 in Myanmar Investment Fraud Ring, Seizes 500+ Domains

The US Department of Justice has announced the indictment of 29 individuals linked to a cyber fraud syndicate operating from Myanmar, charging them with conspiracy to commit wire f...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-04-24Dark Reading
Glasswing Secures Code, But Your Stack Still Exposed

Glasswing’s recent announcement that it has secured the core code of its platform is a welcome step toward reducing software vulnerabilities, but security experts warn that the bro...

Supply ChainAI SecurityCloud Security
Read More → Use Tool →
2026-04-24Dark Reading
AI Phishing Surges: Hackers Shift to 1-to-1 Personalized Attacks

In the past six months, a surge of AI‑powered phishing campaigns has reshaped the threat landscape, according to an analysis published by Dark Reading. Threat actors are moving awa...

PhishingAI ThreatsThreat Intel
Read More → Use Tool →
2026-04-24Dark Reading
North Korea's Lazarus Targets macOS Users via ClickFix

Lazarus, the state‑sponsored advanced persistent threat (APT) group linked to North Korea, has launched a new campaign that specifically targets macOS users in organizations that r...

APTMalwarePhishing
Read More → Use Tool →
2026-04-24Dark Reading
Tropic Trooper APT Targets Home Routers and Japanese Entities

Tropic Trooper, the Chinese state‑sponsored threat group also tracked as KeyBoy and Pirate Panda, has broadened its operational scope with a fresh wave of attacks aimed at consumer...

APTVulnerabilityThreat Intel
Read More → Use Tool →
2026-04-24Dark Reading
Chinese APT Exploits Outlook, Slack, Discord & file.io to Spy on Mongolia

Security researchers at Secureworks’ Counter Threat Unit (CTU) have uncovered a sophisticated espionage operation conducted by a Chinese state‑sponsored APT that targeted Mongolian...

APTCloud SecurityMalware
Read More → Use Tool →
2026-04-24The Hacker News
CISA: FIRESTARTER Backdoor Compromises Federal Cisco Firepower Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that an unidentified federal civilian executive branch agency fell victim to the FIRESTARTER backdoor...

MalwareZero-DayAPT
Read More → Use Tool →
2026-04-24The Hacker News
NASA Employees Targeted by Chinese Phishing Campaign Against Defense Software

NASA's Office of Inspector General (OIG) has disclosed a sophisticated spear‑phishing campaign orchestrated by a Chinese national who masqueraded as a U.S. defense researcher. The ...

PhishingAPTSupply Chain
Read More → Use Tool →
2026-04-24The Hacker News
Bridging AI Agent Authority Gaps: Continuous Observability for Enterprise Security

Enterprise organizations deploying AI agents are confronting a critical security gap that traditional governance frameworks fail to address: the AI Agent Authority Gap. As autonomo...

AI SecurityLLM Security
Read More → Use Tool →
2026-04-24The Hacker News
Fake Apple Crypto Wallet Apps Steal Seed Phrases – 26 Apps Detected

Cybersecurity researchers at CleverSight Threat Intelligence have uncovered a cluster of 26 malicious iOS applications that masquerade as popular cryptocurrency wallets such as Tru...

MalwarePhishingPrivacy
Read More → Use Tool →
2026-04-24The Hacker News
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

Tropic Trooper, a Chinese‑speaking threat actor tracked by several threat‑intel firms, has launched a new campaign that weaponizes a trojanized version of the popular open‑source P...

APTMalwareSupply Chain
Read More → Use Tool →
2026-04-24The Hacker News
LMDeploy CVE-2026-33626 Flaw Active Exploitation After 13 Hours

A critical vulnerability in LMDeploy, the open‑source toolkit used to compress, deploy and serve large language models (LLMs), was publicly disclosed by the vendor on March 2026. T...

Zero-DayVulnerabilityLLM Security
Read More → Use Tool →
2026-04-23Dark Reading
China-Backed Hackers Industrializing Botnets for Covert Attacks

China's state-sponsored threat actors are increasingly leveraging automated botnets comprised of compromised IoT devices, routers, and servers to conduct large-scale cyber operatio...

APTMalwareThreat Intel
Read More → Use Tool →
2026-04-23Dark Reading
Cisco Patches Memory Handling Flaw in Anthropic AI Agents

Cisco’s Talos threat intelligence unit has disclosed a critical memory‑handling vulnerability in Anthropic’s AI agent platform, tracked as CVE‑2024‑51432. The flaw resides in the m...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-04-23Dark Reading
Zealot AI Attack Exposes Cloud Security Risks

In a live demonstration at the Dark Reading CyberStorm conference, researchers from Sentinel Labs unveiled 'Zealot', a proof‑of‑concept AI framework designed to autonomously compro...

AI ThreatsCloud Security
Read More → Use Tool →
2026-04-23Dark Reading
Africa Cyberattack Volume Falls 22% as Hackers Target Latin America

According to the latest Dark Reading analysis, the weekly number of cyberattacks directed at African organizations dropped by 22 % over the past year, falling from roughly 5,400 in...

Threat IntelAPTRansomware
Read More → Use Tool →
2026-04-23The Hacker News
UNC6692 Spoofs IT Help Desk via Microsoft Teams to Deploy SNOW Malware

The previously undocumented threat cluster UNC6692 has been observed conducting a social‑engineering campaign that masquerades as an internal IT help desk on Microsoft Teams. The a...

MalwarePhishingAPT
Read More → Use Tool →
2026-04-23The Hacker News
Bitwarden CLI Supply Chain Attack: Checkmarx Campaign Steals Credentials

Bitwarden CLI versions 2024.1.0 and earlier have been compromised as part of a supply‑chain campaign linked to the Checkmarx name. Security researcher Alex Petrov of XYZ Security L...

Supply ChainMalwareVulnerability
Read More → Use Tool →