HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 1290 篇文章,第 9 / 43 頁

2026-06-08BleepingComputer
Check Point links VPN zero-day attacks to Qilin ransomware gang

Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in z...

Read More → Use Tool →
2026-06-08Dark Reading
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud

The latest attacks, which hit 37 PyPI wheels and 19 code packages, show a continued evolution of the persistent software supply chain threat....

Read More → Use Tool →
2026-06-08SecurityWeek
A Security Raises $37 Million for Autonomous Offensive Security Platform

The company founded by Yossi Torati, Omer Gull, and Yuval Itzchakov has emerged from stealth mode. The post A Security Raises $37 Million for Autonomous Offensive Security Platform...

Read More → Use Tool →
2026-06-08SecurityWeek
Everybody Is Vibe Coding But Nobody Told the Security Team

AI-driven development is not something organizations can or should block. But it must be governed. The post Everybody Is Vibe Coding But Nobody Told the Security Team appeared firs...

Read More → Use Tool →
2026-06-08SecurityWeek
WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order

The Meta-owned communications app is filing a federal court contempt order against NSO. The post WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order appeared first on ...

Read More → Use Tool →
2026-06-08SecurityWeek
Cybersecurity M&A Roundup: 26 Deals Announced in May 2026

Significant cybersecurity M&A deals announced by Akamai, Check Point, Cisco, Cyera, Dragos, WatchGuard and Zscaler. The post Cybersecurity M&A Roundup: 26 Deals Announced...

Read More → Use Tool →
2026-06-08SecurityWeek
Everest Forms Vulnerability Exploited to Hack WordPress Sites

The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sit...

Read More → Use Tool →
2026-06-08The Record
Armenia’s pro-Europe party wins election despite Russia-linked disinformation

Pashinyan's Civil Contract party won nearly 50% of Sunday's vote, defeating the pro-Russian Strong Armenia party led by Russian-Armenian billionaire Samvel Karapetyan, which receiv...

Read More → Use Tool →
2026-06-08The Record
WhatsApp says NSO targeted users with spearfishing attacks in violation of court order

WhatsApp said it is filing a federal court contempt order against NSO for violating a permanent injunction that bars it from mounting attacks against its users....

Read More → Use Tool →
2026-06-08The Record
Russia upgrades rules for its digital spy system to better track citizens online

New regulations published by Russia's Ministry of Digital Development at the end of May updated the technical standards governing SORM, formally known as the System for Operative I...

Read More → Use Tool →
2026-06-08The Hacker News
VerdantBamboo APT Deploys BSD BRICKSTORM Backdoor on Linux Appliances

A China-linked cyber espionage group tracked as VerdantBamboo has been observed deploying a BSD variant of the BRICKSTORM backdoor alongside two new malware families, PLENET (aka G...

APTMalwareSupply Chain
Read More → Use Tool →
2026-06-08The Hacker News
VS Code Adds 2-Hour Auto-Update Delay to Thwart Supply Chain Attacks

Microsoft has rolled out a new protective measure in Visual Studio Code (VS Code) 1.123 that delays automatic extension updates by two hours, aiming to curb the rising tide of soft...

Supply ChainVulnerabilityMalware
Read More → Use Tool →
2026-06-08The Hacker News
UNC3753 Hackers Combine Vishing and Physical Intrusions in U.S. Data Theft Spree

Google Mandiant and the Google Threat Intelligence Group (GTIG) have detailed a financially motivated data theft extortion campaign by threat actor UNC3753—also tracked as Chatty S...

PhishingAPTData Breach
Read More → Use Tool →
2026-06-08BleepingComputer
Oxford University discloses data breach after careers platform hack

The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been...

Read More → Use Tool →
2026-06-08BleepingComputer
Over 20,000 Instagram accounts stolen in Meta AI support hack

Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]...

Read More → Use Tool →
2026-06-08SecurityWeek
174,000 Impacted by Lansing Community College Data Breach

Hackers accessed personal information stored on certain Lansing Community College systems in February 2025. The post 174,000 Impacted by Lansing Community College Data Breach appea...

Read More → Use Tool →
2026-06-08SecurityWeek
Silent Ransom Group Uses DNS Fast Flux in Attacks

Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure. The post Silent Ransom Group Uses DNS Fast Flux in Attacks ap...

Read More → Use Tool →
2026-06-08SecurityWeek
OpenAI Rolling Out ChatGPT Account Security Controls

The Active Sessions and Lockdown Mode features are being made more broadly available by the AI giant. The post OpenAI Rolling Out ChatGPT Account Security Controls appeared first o...

Read More → Use Tool →
2026-06-08SecurityWeek
Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow

The proposed coordination would let advanced AI labs verify that global rivals have actually stopped or slowed their work. The post Anthropic Urges Industry Coordination to Allow f...

Read More → Use Tool →
2026-06-08SecurityWeek
SolarWinds Serv-U Vulnerability Exploited in the Wild

Unauthenticated attackers can exploit the flaw via specially crafted POST requests that crash the Serv-U service. The post SolarWinds Serv-U Vulnerability Exploited in the Wild app...

Read More → Use Tool →
2026-06-08SecurityWeek
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse

The social media giant has informed authorities about the impact of the recent attack involving an account recovery support tool. The post Meta Says 20,000 Instagram Accounts Hacke...

Read More → Use Tool →
2026-06-07BleepingComputer
Microsoft's Intelligent Terminal Brings AI Agents to Windows Command Line

Microsoft has released Intelligent Terminal, an open-source fork of Windows Terminal that embeds AI agents directly into the command-line workflow without disrupting the active she...

AI SecurityLLM Security
Read More → Use Tool →
2026-06-07BleepingComputer
C0XMO Botnet Exploits DD-WRT Flaw to Wipe Rival Malware

Fortinet researchers have uncovered a new variant of the Gafgyt botnet, dubbed C0XMO, which exploits a long-known buffer overflow vulnerability in DD-WRT router firmware (CVE-2021-...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-07BleepingComputer
Silent Ransom Group Targets Law Firms With Fake IT Support Calls

The Silent Ransom Group, tracked by Mandiant as UNC3753 (also known as Luna Moth and Chatty Spider), is actively targeting U.S. law firms and professional services organizations wi...

PhishingThreat IntelData Breach
Read More → Use Tool →
2026-06-07SecurityWeek
Emphere Raises $2.1M to Fix Open-Source Vulnerabilities With AI

Seattle-based cybersecurity startup Emphere has secured $2.1 million in pre-seed funding from AI2 Incubator and Outsiders Fund to advance its AI-driven vulnerability remediation pl...

AI SecurityVulnerabilitySupply Chain
Read More → Use Tool →
2026-06-06BleepingComputer
Critical Everest Forms Pro Flaw Actively Exploited to Hijack WordPress Sites

Hackers are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin to seize full control of vulnerable w...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-06The Hacker News
OpenAI Rolls Out ChatGPT Lockdown Mode to Block Data Exfiltration

OpenAI has begun deploying a new Lockdown Mode for ChatGPT, targeting personal accounts on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The feature is designed for u...

AI SecurityLLM SecurityPrivacy
Read More → Use Tool →
2026-06-06The Hacker News
Bright Data SDK Quietly Turns Smart TVs Into AI Scraping Proxies

A reverse-engineering analysis published June 5 by Include Security and independent researcher Buchodi has exposed how Bright Data, the successor to Luminati and operator of what i...

PrivacyAI ThreatsSupply Chain
Read More → Use Tool →
2026-06-06The Hacker News
CISA Adds SolarWinds Serv-U DoS Flaw CVE-2026-28318 to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity denial-of-service vulnerability in SolarWinds Serv-U to its Known Exploited Vulnerabiliti...

VulnerabilityIncident ResponseRansomware
Read More → Use Tool →
2026-06-06The Hacker News
AI Agent Finds 21 FFmpeg Zero-Days as Chrome 149 Patches Record 429 Bugs

A security startup called depthfirst reported 21 previously unknown vulnerabilities in FFmpeg, the ubiquitous open-source media library, all uncovered by an autonomous AI agent. Th...

Zero-DayVulnerabilityAI Security
Read More → Use Tool →