HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1271 篇文章,第 5 / 43 頁

2026-06-10BleepingComputer
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. [...]...

Read More → Use Tool →
2026-06-10Dark Reading
CISA Rewrites Federal Patching Requirements for AI Threat Era

The new directive gives federal agencies three days to fix the most dangerous flaws, while less severe issues can be deferred....

Read More → Use Tool →
2026-06-10Dark Reading
Bug Bounty Research Triggers ServiceNow Security Alert

Bug bounty research inadvertently led organizations to believe they were being breached through their ServiceNow instances....

Read More → Use Tool →
2026-06-10Dark Reading
AI Risk Worries Insurers and Businesses Alike

As companies adopt AI, many insurance firms are explicitly excluding AI risks, while others are forging ahead to create the right framework. What risks can firms reasonably manage?...

Read More → Use Tool →
2026-06-10The Record
CISA to require federal agencies to patch some cyber vulnerabilities within 3 days

CISA is giving agencies 180 days to adopt the new patching time frame, according to a directive released Wednesday....

Read More → Use Tool →
2026-06-10The Hacker News
China-Linked JDY Botnet Grows to 1,500+ Devices for Mass Reconnaissance

Cybersecurity researchers at Lumen's Black Lotus Labs have identified a significant resurgence of JDY, a covert China-linked botnet that has expanded to over 1,500 compromised smal...

APTThreat IntelMalware
Read More → Use Tool →
2026-06-10The Hacker News
Ivanti, Fortinet, SAP Patch Critical RCE and Auth Bypass Flaws

Fortinet, Ivanti, and SAP have rolled out urgent security updates addressing multiple critical vulnerabilities that could enable arbitrary code execution, authentication bypass, an...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-06-10The Hacker News
Langflow CVE-2026-5027 Exploited: Unauthenticated RCE via Path Traversal

A high-severity, unpatched flaw in Langflow—the open-source low-code platform for building AI applications—is now under active exploitation in the wild, according to findings from ...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-06-10The Hacker News
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports ...

Read More → Use Tool →
2026-06-10BleepingComputer
China-linked JDY botnet expands targeting of U.S. military networks

The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. [.....

Read More → Use Tool →
2026-06-10BleepingComputer
The 5 Best Practices for Secure Identity Verification

Attackers are increasingly bypassing weak authentication through phishing, MFA fatigue, and service desk social engineering. Specops Software breaks down five best practices for st...

Read More → Use Tool →
2026-06-10BleepingComputer
Microsoft patches Exchange Server zero-day exploited in attacks

Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targe...

Read More → Use Tool →
2026-06-10KrebsOnSecurity
Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive...

Read More → Use Tool →
2026-06-10Dark Reading
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet

The disgruntled researcher released yet another PoC for a Windows Defender bug that allows for system takeover, showing no signs of abandoning their ongoing feud with Microsoft....

Read More → Use Tool →
2026-06-10SecurityWeek
Infostealers Turn Millions of Devices Into Credential Theft Machines

As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations. The post Infos...

Read More → Use Tool →
2026-06-10SecurityWeek
Cyera Raises $600 Million at $12 Billion Valuation

Cyera is positioned as one of the most valuable privately held cybersecurity firms in the world with total funding topping $2 billion. The post Cyera Raises $600 Million at $12 Bil...

Read More → Use Tool →
2026-06-10SecurityWeek
Aryon Security Raises $29 Million in Series A Funding

In the post-Mythos era, the company’s platform helps organizations enforce security controls across environments. The post Aryon Security Raises $29 Million in Series A Funding app...

Read More → Use Tool →
2026-06-10SecurityWeek
Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers

Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller. The post Critical HVAC and UPS Vulnerabilities Could Let Hacker...

Read More → Use Tool →
2026-06-10SecurityWeek
CISO Forum Webinar Today: 2026 Mid-Year Review

Learn more about protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks. The post CISO Forum Webinar ...

Read More → Use Tool →
2026-06-10The Record
Cyberattack shuts down major Australian sugar mills, disrupting harvest

Australia's second-largest sugar producer said on Wednesday that it was responding to a cybersecurity incident affecting parts of its operations and had engaged cybersecurity exper...

Read More → Use Tool →
2026-06-10The Record
Microsoft ships largest Patch Tuesday on record, with one bug under active attack

The release comes after Microsoft’s security leadership acknowledged last month that AI tools are driving a surge in vulnerability discovery across the industry....

Read More → Use Tool →
2026-06-10The Hacker News
Automated Pentest Blind Spots: What Your Security Report Is Missing

A clean penetration test report may look reassuring, but security leaders should read it as a warning sign, not a victory lap. According to Autumn Stambaugh and Can Yüceel of Picus...

VulnerabilityCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-10The Hacker News
Microsoft Patches Record 206 Flaws Including 3 Zero-Days and Critical RCE Bugs

Microsoft released fixes for a record 206 security vulnerabilities on Tuesday as part of its June 2026 Patch Tuesday cycle, including three publicly disclosed zero-day flaws. Of th...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-06-10The Hacker News
Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards

On June 9, Anthropic released Claude Fable 5, the most capable model it has ever made, generally available. It also did something unusual: it shipped one model as two products, spl...

Read More → Use Tool →
2026-06-10The Hacker News
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances

ServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to susceptible instances. "On June 5, 2026, Se...

Read More → Use Tool →
2026-06-10The Hacker News
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-da...

Read More → Use Tool →
2026-06-10BleepingComputer
Microsoft: Some Windows PCs fail to install latest monthly updates

Microsoft warned customers on Tuesday that they may have issues installing the latest monthly updates on some Windows devices that were upgraded to Windows 11 24H2 or 25H2. [...]...

Read More → Use Tool →
2026-06-10BleepingComputer
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days

On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLock...

Read More → Use Tool →
2026-06-10BleepingComputer
Ivanti: Max severity Sentry flaw allows code execution as root

Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with r...

Read More → Use Tool →
2026-06-10SecurityWeek
New Windows Zero-Day Exploit ‘RoguePlanet’ Released

Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM. The post New Windows Zero-Day Exploit ‘RoguePlanet’ Releas...

Read More → Use Tool →