HackMyIP

網路安全資訊

來自頂級安全媒體的最新動態

共 2391 篇文章,第 9 / 80 頁

2026-07-21Dark Reading
Hacker Turns AI Jailbreaks Into Offensive Attack Platform

A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools....

Read More → Use Tool →
2026-07-21The Record
DNI nominee Clayton wins Senate panel’s approval

By a party-line vote, the Senate Intelligence Committee sent the nomination of Jay Clayton to lead ODNI to the Senate floor....

Read More → Use Tool →
2026-07-21The Hacker News
AWS Kiro Flaw Lets Poisoned Web Pages Run Code on Developer Machines

Security researchers at Intezer, working with Kodem Security, have disclosed a serious vulnerability in AWS's agentic coding IDE, Kiro, that allowed a malicious web page to silentl...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-07-21The Hacker News
Google's Gemini 3.5 Flash Cyber AI Hunts Vulnerabilities in Chrome & Safari

Google DeepMind has launched Gemini 3.5 Flash Cyber, a specialized AI model built atop Gemini 3.5 Flash, engineered to autonomously discover, validate, and patch software vulnerabi...

AI SecurityVulnerability
Read More → Use Tool →
2026-07-21The Hacker News
Critical SharePoint RCE CVE-2026-50522 Actively Exploited After PoC Drop

Microsoft has confirmed that a third SharePoint Server vulnerability patched in its July 2026 Patch Tuesday cycle is now under active exploitation in the wild. Tracked as CVE-20...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-07-21The Hacker News
Qilin Ransomware Exploits PAN-OS Authentication Bypass Vulnerability

Threat actors affiliated with the Qilin (also known as Agenda) ransomware-as-a-service (RaaS) operation have been weaponizing a now-patched high-severity flaw in Palo Alto Networks...

RansomwareVulnerabilityAuthentication
Read More → Use Tool →
2026-07-21The Hacker News
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. ...

Read More → Use Tool →
2026-07-21The Hacker News
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more s...

Read More → Use Tool →
2026-07-21The Hacker News
N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn...

Read More → Use Tool →
2026-07-21The Hacker News
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. ...

Read More → Use Tool →
2026-07-21Dark Reading
Choose Wisely: AI-Generated Coding Risk Varies, a Lot

AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used....

Read More → Use Tool →
2026-07-21The Record
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 milli...

Read More → Use Tool →
2026-07-21The Record
Taiwan to slow mobile data during national resilience drills

The speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military exercises....

Read More → Use Tool →
2026-07-21The Record
Kenya probes hack of president's website after bitcoin ransom demand

The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information abou...

Read More → Use Tool →
2026-07-21The Hacker News
wp2shell: Critical WordPress RCE Flaws Fuel Mass Exploitation

Attackers are actively exploiting two critical vulnerabilities in WordPress—tracked as CVE-2026-63030 and CVE-2026-60137 and collectively codenamed "wp2shell"—to achieve unauthenti...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-07-21The Hacker News
ENCFORGE Ransomware Hits AI Model Files via Langflow RCE Flaw

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, an AI-agent-driven operator first documented earlier this month. The same threat actor ...

RansomwareVulnerabilityAI Security
Read More → Use Tool →
2026-07-21The Hacker News
Critical ServiceNow AI Sandbox Escape Flaw Actively Exploited for RCE

Threat actors are weaponizing a severe sandbox escape vulnerability in the ServiceNow AI Platform, enabling unauthenticated attackers to execute arbitrary code on vulnerable instan...

VulnerabilityAI SecurityCloud Security
Read More → Use Tool →
2026-07-21SecurityWeek
HollowGraph Malware Uses Microsoft 365 Calendar as Dead-Drop C&C Channel

HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-07-21SecurityWeek
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG

Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to ...

Read More → Use Tool →
2026-07-21SecurityWeek
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-D...

Read More → Use Tool →
2026-07-21SecurityWeek
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Suppo...

Read More → Use Tool →
2026-07-21SecurityWeek
Clover Health Investments Discloses Data Breach

Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared fi...

Read More → Use Tool →
2026-07-21SecurityWeek
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disc...

Read More → Use Tool →
2026-07-21SecurityWeek
Zimbra Update Patches Critical Vulnerabilities

The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on ...

Read More → Use Tool →
2026-07-20Dark Reading
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security

Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today....

Read More → Use Tool →
2026-07-20Dark Reading
WP2Shell Flaw Exposes Millions of WordPress Sites to Remote Takeover

Threat actors are actively chaining two newly disclosed vulnerabilities in the WP2Shell management plugin to achieve unauthenticated remote code execution on WordPress sites at sca...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-20Dark Reading
Ivanti Taps Frontier LLMs to Automate Vulnerability Remediation: Inside the Push

Ivanti is betting that frontier large language models can take the drudgery out of one of cybersecurity's most persistent challenges: patching known vulnerabilities at scale. Chief...

AI SecurityVulnerabilityLLM Security
Read More → Use Tool →
2026-07-20The Hacker News
FakeGit Malware Hits 7,600 GitHub Repos to Target AI Agents

Cybersecurity researchers at Island have uncovered a sprawling malware distribution operation dubbed FakeGit that has flooded GitHub with nearly 7,600 malicious repositories, more ...

MalwareAI ThreatsSupply Chain
Read More → Use Tool →
2026-07-20Dark Reading
CISOs Feel the Heat Over AI Risk

Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position....

Read More → Use Tool →
2026-07-20Dark Reading
Attackers Combo Up Evasion Tactics for BEC Phishing

"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger....

Read More → Use Tool →