HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1387 篇文章,第 46 / 47 頁

2026-04-14Ars Technica
UK Government Mythos AI Tests Cut Cybersecurity Hype, Identify Real Threats

The UK Cabinet Office’s Emerging Technology Cybersecurity Division (ETCD), in close collaboration with the National Cyber Security Centre (NCSC), has publicly released results from...

AI SecurityThreat Intel
Read More → Use Tool →
2026-04-14KrebsOnSecurity
Microsoft Fixes 167 Vulnerabilities, Including SharePoint Zero‑Day

Microsoft released its April 2026 Patch Tuesday updates today, delivering fixes for a record 167 security vulnerabilities across the Windows ecosystem, SharePoint Server, and relat...

VulnerabilityZero-Day
Read More → Use Tool →
2026-04-07KrebsOnSecurity
Russia Exploits Router Flaws to Harvest Microsoft Office Tokens

Security researchers have linked a new wave of cyber‑attacks to Russia’s military intelligence, specifically the APT groups tied to the GRU, which are actively exploiting known vul...

APTVulnerabilityAuthentication
Read More → Use Tool →
2026-04-06KrebsOnSecurity
Germany Doxes 'UNKN', Head of REvil & GandCrab Ransomware Gangs

German authorities have publicly exposed the identity of the notorious hacker known as "UNKN", linking the alias to 31‑year‑old Russian national Daniil Maksimov. Maksimov is allege...

RansomwareThreat IntelPrivacy
Read More → Use Tool →
2026-03-23KrebsOnSecurity
CanisterWorm Worm Targets Iran via Cloud Services, Wipes Data

Security researchers at SecureSphere Labs have uncovered a new file‑wiping worm they have named CanisterWorm, attributed to a financially motivated threat actor tracked under the a...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-03-20KrebsOnSecurity
Feds Dismantle Four IoT Botnets Behind Massive DDoS Attacks

The U.S. Department of Justice, together with the Royal Canadian Mounted Police (RCMP) and the German Federal Criminal Police Office (BKA), has dismantled the command‑and‑control (...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-03-19Ars Technica
DarkSWord iPhone Exploit Exposes Millions to Attack

Security researchers have identified a new iPhone-hacking toolkit, dubbed DarkSWord, that is being actively deployed by Russian-linked threat actors. The toolkit exploits a previou...

Zero-DayAPTVulnerability
Read More → Use Tool →
2026-03-17Ars Technica
World ID Iris Tokens to Secure AI Agents, Prevent Swarms

Worldcoin’s World ID initiative, built by Tools for Humanity, is deploying a biometric authentication system based on iris scanning to assign a unique human identity to every AI ag...

AI SecurityPrivacyAuthentication
Read More → Use Tool →
2026-03-17Ars Technica
Critical IP KVM Flaws Expose Thousands to Remote BIOS Attacks

Security researchers have disclosed critical vulnerabilities affecting IP KVM (Keyboard, Video, Mouse) devices from four major manufacturers, potentially exposing thousands of ente...

VulnerabilityZero-DaySupply Chain
Read More → Use Tool →
2026-03-11KrebsOnSecurity
Iran-Backed Hackers Claim Wiper Attack on Stryker Medtech

A threat actor with documented links to Iran’s Ministry of Intelligence and the Islamic Revolutionary Guard Corps (IRGC) has claimed responsibility for a destructive data‑wiping op...

APTMalware
Read More → Use Tool →
2026-03-11KrebsOnSecurity
Microsoft Patches 77 Vulnerabilities in March 2026 Patch Tuesday

Microsoft released its March 2026 Patch Tuesday security updates today, addressing 77 vulnerabilities across Windows operating systems, Microsoft Office, Azure, and other enterpris...

VulnerabilityZero-DayIncident Response
Read More → Use Tool →
2026-03-08KrebsOnSecurity
AI Assistants Redefine Cybersecurity Landscape

AI assistants, often marketed as autonomous "agents", are rapidly becoming a staple in developer toolchains, promising to automate everything from code generation to system configu...

AI SecurityAI ThreatsPrivacy
Read More → Use Tool →
2026-03-03Ars Technica
Google Tightens Android Developer Verification: Security vs Open Access

Google has announced significant changes to its Android app distribution model, implementing mandatory developer verification for all apps published on Google Play Store. The new r...

RegulationPrivacyAuthentication
Read More → Use Tool →
2026-02-26Ars Technica
New AirSnitch Attack Bypasses Wi‑Fi Encryption in Homes and Offices

Security researchers at CyberEdge Labs have disclosed a new wireless attack they call AirSnitch that can circumvent WPA2‑ and WPA3‑based encryption in residential, office, and ente...

Zero-DayVulnerabilityEncryption
Read More → Use Tool →
2026-01-21Ars Technica
SMS Sign-In Links Expose Millions of Users' Sensitive Data

Even major online services that pride themselves on seamless login experiences are quietly exposing sensitive user data through SMS sign‑in links. Security researchers analyzing th...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2026-01-15Ars Technica
Google Fast Pair Flaw Exposes Bluetooth Devices to WhisperPair Attack

Security researchers at NCC Group have disclosed a new Bluetooth pairing attack, dubbed WhisperPair, that exploits Google’s Fast Pair protocol to silently pair a malicious device w...

VulnerabilityPrivacyZero-Day
Read More → Use Tool →
2025-12-15Ars Technica
Google Ends Dark Web Report Service: Leaked Data Alerts Stop

Google announced on Monday that it will retire the Dark Web Report feature from its Google Account dashboard, ending a service that warned users when their personal information app...

Data BreachPrivacy
Read More → Use Tool →
2025-10-30Ars Technica
Pixel Devices Exposed: Which Pixels Are Vulnerable to Cellebrite?

A leaked document published by the dark‑web user W1ckedG0pher has disclosed the full roster of Google Pixel phones that can be compromised by Cellebrite’s Universal Forensic Extrac...

VulnerabilityPrivacyEncryption
Read More → Use Tool →
2025-10-03Ars Technica
AI-Designed Protein Threat: DNA Screening Misses Biological Zero-Days

Security researchers at MIT Lincoln Laboratory have demonstrated that current DNA‑synthesis screening tools can miss proteins generated by state‑of‑the‑art AI models, effectively c...

Zero-DayAI ThreatsSupply Chain
Read More → Use Tool →
2025-10-03Ars Technica
Google Confirms Android Developer Verification Tiers: Free and Paid Options

Google has officially announced its Android developer verification program will feature both free and paid tiers, marking a significant shift in how developers are authenticated be...

Supply ChainAuthenticationPrivacy
Read More → Use Tool →
2025-09-08Ars Technica
WhatsApp Security Boss Sues Meta Over 'Cult' Culture, User Growth Over Safety

Former WhatsApp security chief filed a lawsuit against Meta Platforms Inc., alleging that the company consistently placed user‑acquisition targets ahead of critical security measur...

PrivacyVulnerability
Read More → Use Tool →
2025-09-02Ars Technica
Google Defends Gmail Security Amid Breach Claims

Google on Monday rebuffed recent reports—published by Ars Technica—that claimed a massive breach exposing all 2.5 billion Gmail accounts, asserting that its security controls are r...

Cloud SecurityPrivacyData Breach
Read More → Use Tool →
2025-07-23Ars Technica
Clorox Sues Vendor After $380M Hack Exposes Password Failures

Clorox has filed a lawsuit against a service desk vendor following a 2023 cybersecurity breach that cost the company approximately $380 million. The legal action centers on allegat...

Data BreachSupply ChainAuthentication
Read More → Use Tool →
2025-07-09Ars Technica
Browser Extensions Hijack 1M Browsers for Scraping Bots

Cisco Talos researchers have uncovered a coordinated campaign that weaponized four Chrome and Edge extensions—PDF Merger, WebScrap, FastFill, and ReadableView—collectively installe...

MalwarePrivacySupply Chain
Read More → Use Tool →
2025-07-07Ars Technica
Android Gemini Access to Third‑Party Apps: Privacy Risks in 2024

Starting Monday, Google began rolling out a platform update for Android 14 (API level 34) that expands the capabilities of its on‑device AI assistant, Gemini. The change introduces...

PrivacyAI Security
Read More → Use Tool →
2025-06-05Ars Technica
Nintendo Warns Switch 2 GameChat Records Chats, Shares Data on Request

Nintendo has alerted owners of its upcoming Switch 2 console that the built‑in GameChat feature creates temporary local copies of voice and text conversations, and that those recor...

PrivacyData BreachVulnerability
Read More → Use Tool →
2025-05-30Ars Technica
Spy-catcher saw “stupid” tech errors others made. FBI says he then made his own.

The wrong way to get out of Trump's America....

Read More → Use Tool →
2022-08-31Threatpost
Student Loan Data Breach Exposes 2.5M Records

Over the weekend, Nelnet Servicing, a major U.S. student‑loan servicer operating under contract with the Department of Education’s Federal Student Aid (FSA) office, disclosed a dat...

Data BreachPrivacyVulnerability
Read More → Use Tool →
2022-08-30Threatpost
Watering Hole Attacks Spread ScanBox Keylogger via APT TA423

Security researchers have uncovered a sophisticated watering‑hole campaign attributed to the advanced persistent threat group TA423, which leverages compromised websites to deliver...

APTMalwareThreat Intel
Read More → Use Tool →
2022-08-29Threatpost
0ktapus Phishing Attacks Compromised 130 Firms, Bypassed MFA

A coordinated phishing operation attributed to the threat group 0ktapus has ensnared more than 130 organizations across multiple industries, according to researchers at Threatpost....

PhishingThreat IntelAuthentication
Read More → Use Tool →