Aggregator
Singapore, US warn of latest Fortinet bug being exploited in wild
Akira
You must login to view this content
Akira
You must login to view this content
Alleged Breach of KBank Vietnam Exposes 10.1 Million Credit Registration Records With National IDs, Salaries, Credit Scores, and Employer Details
CVE-2025-50286
CVE-2026-28289
CVE-2025-20741
CVE-2025-70951
CISA orders feds to patch exploited Fortinet EMS flaw by Friday
Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations
The financially motivated cybercriminal threat actor Storm-1175 operates high-velocity ransomware campaigns that weaponize recently disclosed vulnerabilities to obtain initial access, exfiltrate data, and deploy Medusa ransomware.
The post Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations appeared first on Microsoft Security Blog.
Купил билет в Лувр — и попал в базу данных хакеров. Добро пожаловать в эпоху культурного туризма
SecWiki News 2026-04-06 Review
更多最新文章,请访问SecWiki
eCapture v2 来了,AI Agent 写了 90% 的代码
Танки вместо паролей. Армия США решила сыграть в опасную игру с хакерами из Ирана.
Automated Credential Harvesting Campaign Exploits React2Shell Flaw
德国公开俄罗斯勒索软件组织 REvil 头目的身份
Trojanized PyPI AI Proxy Uses Stolen Claude Prompt to Exfiltrates Data
A malicious Python package has been discovered on PyPI that disguises itself as a privacy-focused AI inference tool while quietly stealing sensitive user data in the background. Named hermes-px, the package marketed itself as a “Secure AI Inference Proxy” that routes all AI requests through the Tor network to protect user anonymity. In reality, it hijacked […]
The post Trojanized PyPI AI Proxy Uses Stolen Claude Prompt to Exfiltrates Data appeared first on Cyber Security News.
GandCrab和REvil勒索软件团伙头目被锁定
Hackers Drain $286 Million From Drift Protocol in Suspected North Korea-Linked Exploit
The largest decentralized perpetual futures exchange on the Solana blockchain — became the target of a massive and well-orchestrated theft on April 1, 2026, Drift Protocol. Unknown attackers managed to drain $286 million in digital assets from the platform’s core liquidity vaults in less than an hour, causing widespread panic across the decentralized finance community. […]
The post Hackers Drain $286 Million From Drift Protocol in Suspected North Korea-Linked Exploit appeared first on Cyber Security News.