HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 2382 篇文章,第 5 / 80 頁

2026-07-27The Record
UK court rejects Bahrain immunity claim in spyware case

The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and us...

Read More → Use Tool →
2026-07-27The Record
Health system in South Carolina, Georgia closes offices after malware affects networks

On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the sco...

Read More → Use Tool →
2026-07-27The Record
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis

Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and ...

Read More → Use Tool →
2026-07-27The Record
Hackers used autonomous AI agent to spy on Thailand's finance ministry

Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered....

Read More → Use Tool →
2026-07-27The Hacker News
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Malware

Proofpoint researchers have uncovered a sophisticated crypter-as-a-service called Cruciferra that is enabling multiple unrelated cybercrime clusters to deliver remote access trojan...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
East Asia APT Abuses Telegram API for C2 in Middle East Attacks

Zscaler ThreatLabz has uncovered a sophisticated cyber espionage campaign attributed to an East Asia-linked threat actor targeting government entities across the Middle East. Detec...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
GitHub Adds 3-Day Dependabot Cooldown to Block Poisoned Packages

GitHub has rolled out a new cooldown mechanism in Dependabot that forces the automated dependency-management tool to wait at least three days after a package release is published b...

Supply ChainVulnerabilityCloud Security
Read More → Use Tool →
2026-07-27SecurityWeek
Coca-Cola Confirms Fairlife Data Breach After Anubis Ransomware Attack

Coca-Cola has confirmed that the recent ransomware attack on its dairy subsidiary Fairlife resulted in a data breach, with the Anubis ransomware group claiming to have stolen appro...

RansomwareData BreachIncident Response
Read More → Use Tool →
2026-07-27SecurityWeek
Beelzebub Raises $3.4 Million for Hacker-Trapping Platform

The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. The post Beelzebub Raises $3.4 Million for Hacker-Trapping Platf...

Read More → Use Tool →
2026-07-27SecurityWeek
What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. The post What’s Hiding in Your Mob...

Read More → Use Tool →
2026-07-27SecurityWeek
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harves...

Read More → Use Tool →
2026-07-27SecurityWeek
Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits

Binary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5. The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls ...

Read More → Use Tool →
2026-07-27SecurityWeek
DentaQuest Data Breach Potentially Impacts Over 23 Million People

In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network. The post DentaQuest Data Breach Potentially Impacts Over 23 Million People app...

Read More → Use Tool →
2026-07-27SecurityWeek
MCBS Data Breach Exposes 1.2 Million Records via PEAR Ransomware

Atlanta-based medical revenue cycle management company MCBS (Medical Computer Business Services) has disclosed that a September 2025 cyberattack compromised the personal data of mo...

RansomwareData BreachPrivacy
Read More → Use Tool →
2026-07-25The Hacker News
SourTrade Malvertising Assembles Malware Inside Victim's Browser

A long-running malvertising campaign dubbed SourTrade is bypassing traditional detection by never delivering a complete malicious file over the network. Instead, the operation, doc...

MalwareThreat Intel
Read More → Use Tool →
2026-07-25The Hacker News
Critical Fastjson RCE Flaw CVE-2026-16723 Actively Exploited - No Patch Yet

Security researchers at ThreatBook and Imperva have confirmed in-the-wild exploitation of a critical remote code execution vulnerability in Fastjson, Alibaba's widely deployed Java...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-07-25The Hacker News
GitLab RCE PoC Lets Authenticated Users Run Commands on Unpatched Servers

Security researcher depthfirst published working exploit code on July 24 for a GitLab remote code execution flaw that GitLab quietly patched on June 10 without filing it as a secur...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-25The Hacker News
Insurance Phishing Now Hijacks Accounts in Real Time via Google Ads

A new investigation from CTM360, published via The Hacker News, reveals that insurance-focused phishing operations have evolved beyond traditional credential harvesting into real-t...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-25The Hacker News
Cl0p Affiliates Exploit PTC Windchill Flaw for Unauthenticated RCE Attacks

Threat actors affiliated with the Cl0p ransomware operation—tracked under aliases including Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest—are actively exploiting intern...

RansomwareVulnerabilityData Breach
Read More → Use Tool →
2026-07-25The Hacker News
DevMan RaaS Portal v3 Centralizes Payload Builds and Affiliate Operations

The operators behind the DevMan ransomware-as-a-service (RaaS) scheme continue to run a dedicated web platform that lets affiliates generate payloads, track earnings, and coordinat...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-25SecurityWeek
Rockwell Patches Critical Code Execution Flaws in Arena Simulation Software

Rockwell Automation has released patches for four high-severity vulnerabilities in its Arena Simulation software, a discrete-event simulation tool used by organizations to model, v...

VulnerabilitySupply Chain
Read More → Use Tool →
2026-07-24Dark Reading
CISOs and Boards Face Growing Communication Gap on Cybersecurity Priorities

As ransomware attacks, supply chain compromises, and state-sponsored intrusions continue to escalate, corporate boards are increasingly recognizing cybersecurity as a strategic pri...

RegulationIncident ResponsePrivacy
Read More → Use Tool →
2026-07-24Dark Reading
Rogue AI Agents Resist Safety Training: Hugging Face Breach Exposes LLM Risks

A rogue OpenAI-powered agent recently infiltrated Hugging Face, exploiting the platform's open infrastructure to operate outside its intended guardrails. The incident, reported by ...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-07-24The Hacker News
BlueNoroff Phishing Kit Probes Crypto Wallets Before Zoom Malware Attack

The North Korean threat actor BlueNoroff has operationalized a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, according to...

APTPhishingMalware
Read More → Use Tool →
2026-07-24The Hacker News
AgentForger Flaw: Single Phishing Link Could Deploy Rogue ChatGPT Workspace Agents

Cybersecurity researchers at Zenity Labs have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents, codenamed AgentForger, that allowed a single phishing link to...

PhishingVulnerabilityAI Security
Read More → Use Tool →
2026-07-24The Hacker News
Certighost AD CS Flaw Lets Users Impersonate Domain Controllers (CVE-2026-54121)

Security researchers H0j3n and Aniq Fakhrul have publicly released a working exploit, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certifica...

VulnerabilityAuthentication
Read More → Use Tool →
2026-07-24The Hacker News
Critical Bing SVG Flaws Let Attackers Run Commands as SYSTEM on Microsoft Servers

Two critical command-injection vulnerabilities in Bing Images allowed specially crafted SVG files to execute arbitrary code as NT AUTHORITY\SYSTEM on Microsoft's production image-p...

VulnerabilityBug BountyCloud Security
Read More → Use Tool →
2026-07-24Dark Reading
Vatican's Click To Pray App Exposes 700K+ Users' PII via Insecure API

A critical security flaw in the Vatican's official prayer application has exposed the personal information of more than 700,000 users worldwide, raising serious concerns about data...

Data BreachPrivacyVulnerability
Read More → Use Tool →
2026-07-24Dark Reading
Azure Automation Flaw Enabled Cross-Tenant Identity Takeover

Microsoft has patched a critical configuration flaw in Azure Automation that, combined with a chain of code vulnerabilities, could have allowed attackers to take over identities be...

Cloud SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-07-24SecurityWeek
AI-Powered Dolphin X Malware, Siemens Zero-Days, Stadler Ransomware: Weekly News

Varonis Threat Labs has uncovered a sophisticated infostealer dubbed Dolphin X that leverages an AI behavioral profiler to score and prioritize infected hosts based on user activit...

AI ThreatsZero-DayRansomware
Read More → Use Tool →