網路安全資訊
來自頂級安全媒體的最新動態
共 2382 篇文章,第 7 / 80 頁
Qualys has disclosed a nine-year-old Linux kernel vulnerability, tracked as CVE-2026-64600 and nicknamed RefluXFS, that enables unprivileged local users to overwrite root-owned fil...
Confidential computing has spent years working through the friction that kept enterprises from trusting hardware-based encrypted enclaves with their most sensitive workloads. Adopt...
Check Point has shipped emergency security updates to remediate multiple high-severity flaws affecting its Security Management and Multi-Domain Security Management (MDSM) products,...
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets....
Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract...
He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek....
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild ...
A ransomware attack on a major Japanese food and logistics provider has disrupted frozen-food deliveries to thousands of restaurants across the country, sending ripples through one...
The U.S. government has updated a cybersecurity advisory warning that Iran-linked threat actors are actively targeting industrial control systems (ICS) manufactured by Siemens, Sch...
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users....
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier's file-sharing platform....
GitHub will slash public bug bounty payouts by at least half across every severity level beginning July 27, 2026, replacing its flexible reward ranges with fixed payments and conce...
Cybersecurity researchers at Qualys have disclosed a high-severity local privilege escalation (LPE) vulnerability in Ubuntu's snap-confine utility that allows an unprivileged user ...
Cybersecurity researchers at Guardio Labs have disclosed a now-patched vulnerability in the Adobe Acrobat Chrome extension—used by more than 314 million users—that could allow a ma...
Security researchers have identified Sandworm_Mode, an early proof-of-concept malware family that embeds malicious operations directly inside legitimate AI development pipelines. R...
A deceptive application masquerading as an official Bahrain emergency alert has been discovered distributing sophisticated Android surveillance malware through fraudulent Google Pl...
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill....
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) d...
A high-severity path traversal vulnerability in the open-source Windmill developer platform is being actively exploited in the wild, according to threat intelligence from VulnCheck...
Shadow AI is no longer a fringe problem. According to McKinsey's State of AI report, 76 percent of employees now use AI in some capacity at work, up from 55 percent the year before...
In a striking demonstration of emerging AI risk, OpenAI's large language models (LLMs) autonomously breached sandboxed environments on Hugging Face during routine benchmark testing...
Hackers have stolen tens of millions of user records from AI music generation platform Suno and gig-work marketplace Paidwork, according to bre...
Acquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Pl...
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs...
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a...
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension ...
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps R...
Both houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crac...
A North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said....
Nichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption....