Aggregator
iRhythm 确认数据在黑客攻击中被盗
信息安全漏洞周报(2026年第24期)
人工智能重要安全漏洞的通报-OpenClaw多个安全漏洞
145 Mastra npm Packages Compromised via Hijacked Contributor Account
Novo Nordisk Cyberattack: Clinical Trial Data Breach
Novo Nordisk recently fell victim to a sophisticated cyberattack. Consequently, this incident compromised a segment of patient data from clinical trials. Fortunately, the company asserted that names and direct identifiers remained unexposed. Therefore, unauthorized...
The post Novo Nordisk Cyberattack: Clinical Trial Data Breach appeared first on Information Security News.
Полмиллиона евро, Магнус Карлсен и обязательные любители в составе. В Гонконге стартовал необычный командный чемпионат мира по шахматам
SQL Server 2025 AI Features Enable Data Exfiltration
Databases have long evolved beyond mere tabular repositories. However, new functionalities within SQL Server 2025 illustrate the inherent dangers of this progression. Recently, SpecterOps researchers discovered significant vulnerabilities. They detailed how attackers can abuse...
The post SQL Server 2025 AI Features Enable Data Exfiltration appeared first on Information Security News.
恶意 JetBrains Marketplace 插件窃取开发者的 AI API 密钥
Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection
A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows attackers to bypass authentication mechanisms under specific conditions by exploiting improper handling of the Host header. The issue affects LiteLLM versions before 1.84.0 and has been assigned a […]
The post Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection appeared first on Cyber Security News.
OptinMonster Supply Chain Attack Hits 1.2M Sites
Popular WordPress plugins have found themselves at the center of a supply chain attack, where the products themselves were not compromised directly. Instead, attackers targeted the infrastructure responsible for distributing them. Three plugins from...
The post OptinMonster Supply Chain Attack Hits 1.2M Sites appeared first on Information Security News.
Payroll Pirate Hijacks Sessions to Steal Paychecks
Payroll systems rarely attract attention until a single edited bank detail quietly turns a routine paycheck into a direct transfer to criminals. Researchers at BushidoToken Threat Intel have detailed a new financially motivated campaign...
The post Payroll Pirate Hijacks Sessions to Steal Paychecks appeared first on Information Security News.
地下真菌网络长度超过 10 万万亿公里
Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now!
Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Users are strongly advised to update immediately as several flaws impact core browser components. The latest Chrome Stable channel has been updated to version 149.0.7827.155/.156 for Windows and macOS, […]
The post Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now! appeared first on Cyber Security News.
Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices
A newly discovered Android banking trojan called Rokarolla is making waves in the cybersecurity world, and it is more dangerous than most threats we have seen lately. This malware is built to take full control of an infected device while staying completely hidden from the user. Its reach is staggering, with over 217 banking and […]
The post Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices appeared first on Cyber Security News.
紧急AI安全情报 | 热门AI智能体开发框架Mastra近140个NPM组件遭受供应链投毒
Kodak confirms data breach claimed by ShinyHunters extortion gang
雷神众测漏洞周报2026.6.08-2026.6.14
Deno-Based RAT Uses Microsoft Teams Impersonation and Mailbombing to Target Employees
A new strain of malware has emerged that combines two well-known social engineering tactics into one effective attack chain. Researchers have uncovered a Remote Access Trojan built on Deno, an unconventional JavaScript runtime, being deployed against employees through email flooding and fake Microsoft Teams calls. The attack overwhelms targets and then offers a false sense […]
The post Deno-Based RAT Uses Microsoft Teams Impersonation and Mailbombing to Target Employees appeared first on Cyber Security News.