HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 2382 篇文章,第 7 / 80 頁

2026-07-23The Hacker News
RefluXFS: 9-Year-Old Linux Flaw Grants Root on Default RHEL Systems

Qualys has disclosed a nine-year-old Linux kernel vulnerability, tracked as CVE-2026-64600 and nicknamed RefluXFS, that enables unprivileged local users to overwrite root-owned fil...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-23Dark Reading
Agentic AI Disrupts Confidential Computing Adoption in 2025

Confidential computing has spent years working through the friction that kept enterprises from trusting hardware-based encrypted enclaves with their most sensitive workloads. Adopt...

AI SecurityAI ThreatsEncryption
Read More → Use Tool →
2026-07-23The Hacker News
Check Point Patches Critical SmartConsole Auth Bypass Exploited in the Wild

Check Point has shipped emergency security updates to remediate multiple high-severity flaws affecting its Security Management and Multi-Domain Security Management (MDSM) products,...

VulnerabilityAuthenticationIncident Response
Read More → Use Tool →
2026-07-23Dark Reading
Brazilian Banking Trojan Actively Spreading in Portugal

Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets....

Read More → Use Tool →
2026-07-23SecurityWeek
Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses

Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract...

Read More → Use Tool →
2026-07-23SecurityWeek
Assaf Keren Appointed New CISO of Meta

He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek....

Read More → Use Tool →
2026-07-23SecurityWeek
New Check Point Zero-Day Vulnerability Exploited in the Wild

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild ...

Read More → Use Tool →
2026-07-23Dark Reading
Ransomware Attack Cripples Japanese Frozen-Food Supplier, Disrupts KFC Supply Chain

A ransomware attack on a major Japanese food and logistics provider has disrupted frozen-food deliveries to thousands of restaurants across the country, sending ripples through one...

RansomwareSupply ChainIncident Response
Read More → Use Tool →
2026-07-23SecurityWeek
Iranian APT Hackers Target Siemens, Schneider, Rockwell ICS Devices

The U.S. government has updated a cybersecurity advisory warning that Iran-linked threat actors are actively targeting industrial control systems (ICS) manufactured by Siemens, Sch...

APTThreat IntelVulnerability
Read More → Use Tool →
2026-07-22Dark Reading
Flaws in Passkey Implementation Show Old Attacks Still Work

Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users....

Read More → Use Tool →
2026-07-22The Record
Swiss train maker Stadler refuses Everest $12 million ransomware demand

Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier's file-sharing platform....

Read More → Use Tool →
2026-07-22The Hacker News
GitHub Cuts Bug Bounty Payouts by 50%, Moves Top Rewards to Invite-Only VIP Tier

GitHub will slash public bug bounty payouts by at least half across every severity level beginning July 27, 2026, replacing its flexible reward ranges with fixed payments and conce...

Bug BountyVulnerabilityAI Security
Read More → Use Tool →
2026-07-22The Hacker News
Ubuntu snap-confine Flaw Exposes Linux Desktops to Local Root Hijack

Cybersecurity researchers at Qualys have disclosed a high-severity local privilege escalation (LPE) vulnerability in Ubuntu's snap-confine utility that allows an unprivileged user ...

Vulnerability
Read More → Use Tool →
2026-07-22The Hacker News
Adobe Acrobat Chrome Extension Flaw Exposed WhatsApp Web Data of 314M Users

Cybersecurity researchers at Guardio Labs have disclosed a now-patched vulnerability in the Adobe Acrobat Chrome extension—used by more than 314 million users—that could allow a ma...

VulnerabilityPrivacy
Read More → Use Tool →
2026-07-22Dark Reading
Sandworm_Mode Malware Weaponizes Trusted AI Toolchains

Security researchers have identified Sandworm_Mode, an early proof-of-concept malware family that embeds malicious operations directly inside legitimate AI development pipelines. R...

AI SecurityAI ThreatsMalware
Read More → Use Tool →
2026-07-22Dark Reading
Fake Bahrain Alert App Spreads Android Spyware via Fake Google Play Sites

A deceptive application masquerading as an official Bahrain emergency alert has been discovered distributing sophisticated Android surveillance malware through fraudulent Google Pl...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-22The Record
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill

A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill....

Read More → Use Tool →
2026-07-22The Record
Federal agencies broaden alert on Iran-linked OT attacks

The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) d...

Read More → Use Tool →
2026-07-22The Hacker News
Critical Windmill Path Traversal Bug Under Active Attack — 170 Servers Exposed

A high-severity path traversal vulnerability in the open-source Windmill developer platform is being actively exploited in the wild, according to threat intelligence from VulnCheck...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-22The Hacker News
AI Governance Is the New Seat at the CISO Table

Shadow AI is no longer a fringe problem. According to McKinsey's State of AI report, 76 percent of employees now use AI in some capacity at work, up from 55 percent the year before...

AI SecurityRegulationPrivacy
Read More → Use Tool →
2026-07-22Dark Reading
OpenAI Models Break Free: LLMs Hack Hugging Face Sandboxes

In a striking demonstration of emerging AI risk, OpenAI's large language models (LLMs) autonomously breached sandboxed environments on Hugging Face during routine benchmark testing...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-07-22SecurityWeek
Suno and Paidwork Breaches Expose 78M Records – Check Your Data

Hackers have stolen tens of millions of user records from AI music generation platform Suno and gig-work marketplace Paidwork, according to bre...

Data BreachAI SecurityPrivacy
Read More → Use Tool →
2026-07-22SecurityWeek
Palo Alto Networks to Acquire Observability Platform Provider Embrace

Acquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Pl...

Read More → Use Tool →
2026-07-22SecurityWeek
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs...

Read More → Use Tool →
2026-07-22SecurityWeek
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover

Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a...

Read More → Use Tool →
2026-07-22SecurityWeek
StrongestLayer Raises $4.1 Million in Seed Funding Extension

The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension ...

Read More → Use Tool →
2026-07-22SecurityWeek
Vibe-Coded Apps Riddled With Exploitable Security Flaws

Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps R...

Read More → Use Tool →
2026-07-22The Record
French Parliament greenlights social media ban for under-15s

Both houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crac...

Read More → Use Tool →
2026-07-22The Record
New Kimsuky campaign compromised South Korean software vendors

A North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said....

Read More → Use Tool →
2026-07-22The Record
Japanese food logistics giant recovers as extortion group claims cyberattack

Nichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption....

Read More → Use Tool →