新聞一般而言,駭客針對瀏覽器用戶發動攻擊,多半會針對用戶比例最高的Chrome而來,其中一種是在Chrome Web Store上架惡意延伸套件,如今有專門針對Edge用戶的攻擊行動。微軟揭露大規模攻擊行動StegoAd,有人於2024年初至2026年4月,於Microsoft Edge Add-ons Store使用超過90個帳號,上架119個惡意套件,這些套件標榜擋廣告、VPN服務、翻譯工具,…
業界新聞
新聞6月26日微軟(Microsoft)宣布,Windows Server 2022 Datacenter: Azure Edition的熱修補(Hotpatch)支援期限,將從原本的2026年10月延長至2027年10月。這項調整即日起生效,已啟用此功能的伺服器不需要額外採取行動,仍會依照既有的每月更新週期,接收以熱修補形式發布的安全更新。熱修補是微軟提供的作業系統安全性更新機制,目前於Wind…
新聞資安公司Blackpoint近日指出,他們發現有人利用SimpleHelp滿分重大漏洞CVE-2026-48558,對一家偵測與回應代管(MDR)廠商散布惡意程式TaskWeaver與Djinn Stealer,現在美國政府也確認該漏洞遭到利用的現象。6月29日美國網路安全與基礎設施安全局(CISA)表示,他們將CVE-2026-48558列入已遭利用的漏洞列表(KEV),並要求聯邦機構在7月…
新聞6月26日美國司法部(DOJ)宣布,他們發現近400個被用於未經授權轉播世界盃足球賽(FIFA World Cup)的網域,根據該國的版權法將其查封。這些被查封的網域被用來非法向用戶提供受版權保護的內容,以即時串流播放2026年世界盃足球賽。為了支持查封權限的申請,美國國土安全局(HSI)證實,被查封的網域確實在未經授權的情況下,積極轉播比賽內容。這些被查封的網域在FIFA協助下被確認,並由b…
新聞物聯網與遠端連線設備業者Lantronix旗下序列埠轉IP設備EDS5000存在重大漏洞CVE-2025-67038,屬於身分驗證失敗竟可透過root權限執行的命令注入弱點,CVSS分數達9.8。美國網路安全暨基礎設施安全局(CISA)於6月23日將其列入已遭利用漏洞(KEV)名單。網路資產管理與資安業者Forescout旗下研究團隊Vedere Labs隨後於6月25日發布研究,揭露這項漏洞…
新聞上個月遠端監控與管理軟體SimpleHelp發布5.5.16與6.0 RC2更新,修補CVSS風險評分達到滿分10分的重大漏洞CVE-2026-48558,該漏洞源自OpenID Connect(OIDC)身分驗證流程未正確驗證身分權杖(Identity Token)的加密簽章。如今此漏洞已出現實際攻擊。根據資安新聞網站Bleeping Computer報導,資安公司Blackpoint提出警…
新聞AI加快漏洞發現與利用速度,也大幅壓縮企業部署修補的防禦空窗期。Linux基金會旗下金融服務開源組織FINOS(Fintech Open Source Foundation)於6月25日在Open Source in Finance Forum宣布,計畫成立開源企業韌性聯盟(Open Source Enterprise Resiliency Alliance,OSERA),協助金融機構與其他受…
新聞2026年世界盃足球賽(FIFA World Cup)於6月11日展開,在此之前,相關的網路詐騙呈現爆炸性增長,繼外部數位風險防護業者CTM360提出警告後,有資安公司提出警告,駭客已透過網路詐騙生態系統,藉此牟取不法利益。上週威脅情報公司Cyble揭露Operation FanTrap活動,駭客利用詐騙網域、社群媒體、即時通訊平臺、盜版球賽轉播,以及暗網活動等管道,建立經過協調的生態系統,該…
Four years into the Kremlin’s illegal invasion of its neighboring country, Russian influence operations have moved beyond their near-exclusive focus on Ukraine to their former favorite targets: the US…
Researchers say that machine learning models cannot reliably distinguish between authorized and unauthorized input, ensuring that prompt injection will continue to present a threat until developers fi…
新聞去年勒索軟體駭客組織Clop曾大規模攻擊企業組織與大學,利用零時差漏洞CVE-2025-61882,該弱點存在於Oracle的ERP系統E-Business Suite(EBS),因此,一旦出現利用EBS漏洞的情況,格外受到研究人員的注意。6月29日威脅情報公司Defused Cyber於社群網站X提出警告,他們首度偵測到有人試圖利用另一個EBS漏洞CVE-2026-46817的情況,由於該漏…
South Korea Plans To Train Entire Military As 'Drone Warriors' https://tech.slashdot.org/story/26/06/29/0228207/south-korea-plans-to-train-entire-military-as-drone-warriors?utm_source=rss1.0mainlinkan…
US offers $10 million for info on group behind Signal and WhatsApp hacking spree Operation by two Russia-state groups has been ongoing since at least March. https://arstechnica.com/information-technol…
The end has come for CERN’s Large Hadron Collider (LHC), but it’s not being turned off for fear of the world being sucked into some sort of cosmic anomaly - it’s getting a major upgrade. Physicists at…
The US Supreme Court on Monday ruled that people have a reasonable expectation of privacy with regard to mobile phone geolocation data, a decision privacy advocates have sought for years. The Court's …
Not everyone is willing to follow responsible disclosure of vulns. An anonymous researcher has dumped what they say is working exploit code for zero-day vulnerabilities across 15 software products and…
Sony erases digital content from libraries; we're reminded we don’t own what we buy Sony has been scaling down its digitial store for a few years. https://arstechnica.com/gadgets/2026/06/sony-erases-d…
Wine 11.12 Released With Wayland Fractional Scaling & Other Wayland Enhancements Wine 11.12 fell off the bi-weekly release rhythm with not making it out last Friday, but it managed to ship today. Wine…
South Korea to spend $1T on more memory chip production and humanoid robots South Korea targets physical AI lead and commercial humanoid robots by 2028. https://arstechnica.com/ai/2026/06/south-korea-…
Supreme Court ruling guts government’s use of geofence warrants SCOTUS falls short of deeming geofence warrants unconstitutional, though. https://arstechnica.com/tech-policy/2026/06/supreme-court-ruli…