דלג לתוכן
צC

צוות CyberHub

הצטרף לפני 2 חודשים

0 נקודות🌱 מתחיל

0 עוקבים · 0 עוקב/ת

החשבון הרשמי של צוות CyberHub — מדריכים, חדשות וניתוחים בעולם הסייבר.

0
נקודות
📝
310
מאמרים
💬
7
נושאים
🚩
0
אתגרים
❤️
0
לייקים

🎖️ תגים (3)

🎉 ברוך הבא✍️ כותב💬 קול בקהילה

מאמרים (310)

Metabase SQLi zero-day exploited in customer data-theft attacksUnlimited Technology Systems breach impacts 3.8 million peopleNearly 800 Malicious npm Packages Deliver Cross-Platform RAT and InfostealerClickFix Attacks Deliver macOS Stealer That Can Drain Crypto WalletsUNC6671 Vishing Attacks Target Personal Phones to Steal SaaS DataLevi Strauss & Co. says hackers stole corporate data in cyberattackOpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for itClickFix attack pushes macOS infostealer for crypto theft attacksHedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion groupNew Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsCisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score BugsCanadian Man Pleads Guilty in Snowflake ExtortionsNew Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUsSnowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million PeopleRansom Cartel ransomware creator sentenced to 16 years in prisonCanadian pleads guilty to Snowflake cloud data-theft attacksHackers run khunt post-exploitation toolkit from Oracle databaseOver 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware LuresOpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud SchemesQuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows InstallerOpenAI, Anthropic AI agents targeted real people and systems in cyber testsTP-Link patches Omada ZTP flaws allowing hackers to breach networksPhishing service spoofs RingCentral to steal Microsoft 365 accountsGreatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal TokensKeyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code HooksHotel Wi-Fi attacks use custom malware to breach Microsoft 365 accountsNew Pass-ta-key attacks let malware hijack Google-synced passkeysNew DOUBLECUP ClickFix service hides malware in browser cache images18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool UsersGoogle Password Manager Attacks Could Let Malware Hijack Passkey-Protected AccountsINC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 FlawsOpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problemsCOLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftGoogle Chrome may soon block New Tab hijacker extensions by defaultColdcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 MinutesRails patches critical Active Storage flaw with RCE potentialHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionAmgen says cloud data breach exposed patient health, proprietary infoArch Linux disables AUR package adoption to stop malware floodOnline ad firm Adform’s script compromised to steal cryptocurrencySuspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into ProxiesAnthropic's Claude breached 3 orgs, uploaded PyPI malware during testsSouth Korea fines telco giant KT $39 million for customer data breachJetBrains warns of critical TeamCity remote code execution flawDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing MalwareRead This Before You Buy That TV Streaming StickThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesAzure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any DatabaseCisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataRussian hackers exploit Exchange OWA zero-day for long-term mailbox accessAnthropic confirms Claude is down worldwideCisco warns of FMC static credential flaw exploited in zero-day attacksCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsRuflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryOpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face BreachTwo Compromised joyfill npm Packages Run RAT When Imported Into Node.jsCubePilot drone software dev hit by DNS hijacking to intercept trafficOpenAI models used Artifactory zero-days to escape to the internetClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackCISA shares advice on isolating vital systems during cyberattacksMicrosoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostAttackers Exploit Arista VeloCloud Orchestrator Command Injection FlawHackers target US firms in FastJson RCE zero-day attacksArista patches VeloCloud Orchestrator zero-day exploited in attacksNew Dysphoria DDoS botnet spreads to 200k devices worldwideNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA FrameworkGitHub, PyPI add time-based defenses against supply chain attacksSteam forum ClickFix attacks infect gamers with XMRig cryptominersMalvertising Sends Malware in Pieces, Then Makes the Browser Build the ExecutableMalicious sites use JavaScript to build malware in browser memoryShinyHunters data leaks fuel $2,000 sextortion email scamFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitOnTrac notifies customers of data breach after network hackHermes AI agent used to automate attack on Thai Finance MinistryHackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountsBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware DeliveryCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkNew Dolphin X malware uses AI to rank high-value targetsAustralian energy provider Origin says data breach exposes client dataFake Claude app promoted by Bing ads pushes SectopRAT malwareRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesUpbound says hack caused $13 million in fraudulent Acima leasesSouth Korea discloses data breach impacting diplomats worldwideGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP TierUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackAdobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web DataChick-fil-A discloses data breach after credential stuffing attacksTrojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working LibraryOpenAI says its AI models hacked Hugging Face during testingMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkLG to Ban Residential Proxies from Smart TV AppsPolice dismantle Kratos phishing platform, arrest developerEstée Lauder discloses data breach via Oracle E-Business flawSonicWall SMA1000 flaws exploited as zero-days to push custom malwareHackers steal $23.7 million in crypto from Ostium in off-chain attackFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader MalwareExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050World's Largest AI Model Repository Hugging Face Breached by Autonomous AI AgentSleeperGem Uses Three Malicious RubyGems Packages to Target Developer MachinesCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionHackers abuse ViPNet software to target Russian govt agenciesUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archivesWordPress Core "wp2shell" RCE flaws get public exploits, patch nowMicrosoft warns of surge in ACR Stealer attacks on customersNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeAbbott probes two cyber incidents amid extortion claimsOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS RequestsSeven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RATHollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payloadErnst & Young discloses data breach after support system hackNew ClickLock macOS malware traps users into revealing login passwordCoca-Cola says Fairlife ransomware attack halts US dairy productionClaude Chrome extension flaw lets malicious extensions trigger AI actionsTwo Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL HackThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Storiesn8n Token Exchange Flaw Could Let Attackers Log In as Users From Another IssuerDutch police bust investment fraud ring stealing over €100 millionZoom warns of critical account takeover vulnerabilityTuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet DevelopmentGoogle Gemini CLI abused as a hacking agent, malware botnet operatorOkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor AppsFirefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security FlawsTwo SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin CommandsSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch nowMicrosoft Patches Record 622 Flaws, Including Two Zero-Days Under Active AttackSpanish Police take down €140 million cyber fraud ring, arrest fourMicrosoft Patches a Record 570 Security FlawsNearly 300 GitHub repos pose as legit software to push malwareSAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify DataMicrosoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three PathsJapan's largest taxi operator shuts systems after cyberattackHackers backdoor Jscrambler npm package with infostealer malwareNew CrashStealer malware poses as Apple crash reporting toolCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper ChecksGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector FoundLessons Learned from CISA’s Recent GitHub LeakOpenAI temporarily relaxes GPT-5.6 Sol usage limitsClaude Fable 5 stays free for paid users until July 19 as Anthropic buys more timeRedHook Android malware now uses Wireless ADB for shell accessCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During InstallHackers Weaponize Balochistan Police Portal in Multi-Group Espionage CampaignsAustralia warns of global campaign targeting vulnerable CMS platforms'Ghostcommit' hides prompt injection in images to fool AI agents, steal secretsCritical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsNew U-Boot flaws could enable stealthy firmware attacksRyuk ransomware member pleads guilty in the US, faces 15 years in prisonPolice suspects Dutch hackers were involved in Odido breachURGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security ThreatInjective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm PackagesSix New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at BootOpenMandriva Linux says contributor tried to sabotage the projectInjective SDK on npm infected with cryptocurrency wallet stealerDormant GitHub Accounts Help Attackers Blend In While Mapping Corporate OrgsNew GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and SpywareNew Helix vishing group emerges in SharePoint data theft attacksnpm 12 Disables Install Scripts by Default to Reduce Supply Chain RiskMicrosoft patches RoguePlanet Defender zero-day vulnerabilityTop AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItGhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding AgentsFake 7-Zip Installers Turn Devices Into Residential Proxy NodesMount Royal University confirms breach as hackers claim attackFake Paysafe, Skrill SDKs on NPM and PyPi steal credentialsFelons, Fraudsters Flog Offensive Cybersecurity Startup15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux DistrosCISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVAccenture confirms breach after hacker offers stolen data for saleChinese hackers develop LONGLEASH malware to expand ORB networkHidden backdoor in Tenda router firmware grants admin accessRedWing MaaS Packages Android Bank Fraud as a Telegram Rental ServiceBeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRAPhishing poses as big-brand job interview to steal Google accountsFake IT support calls on Microsoft Teams push EtherRAT malwareIran-Linked Hackers Use New Cavern C2 Framework to Target Israeli OrganizationsVietnam arrests suspects behind HiAnime anime piracy service16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsFlipper Zero firmware development continues with community helpJadePuffer ransomware used AI agent to automate entire attackU.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion CaseNorth Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider CampaignUnpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded DevicesNew "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidNew Avalon Malware Framework Packs CrownX Ransomware CapabilitiesNetNut proxy network disrupted, 2 million infected devices cut offARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkitClaude Fable 5 isn’t permanently leaving subscriptions, Anthropic saysClaude Fable relaunch disappoints users with nerfed performanceFBI Seizes NetNut Proxy Platform, Popa BotnetGoogle Disrupts NetNut Residential Proxy Network Spanning 2 Million Home DevicesRansomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 StoriesGoogle loses final appeal to overturn €4.1 billion EU fineSharePoint RCE CVE-2026-45659 Added to CISA KEV After Active ExploitationMedtronic notifies customers impacted by ShinyHunters data breachFortiBleed credential-theft campaign linked to Lynx ransomwareKubota says hackers had month-long access to network systemsUnpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking ChargesAzure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ AttemptsResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware DeliveryCitrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-ServiceAnthropic to restore Claude Fable access on WednesdayAnthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower priceNew BioShocking attack manipulates AI browser into data theftOracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the WildNissan discloses employee data breach linked to Oracle zero-day attacksNAIC says public data stolen in ShinyHunters' PeopleSoft breachMalicious Perplexity Chrome Extension Intercepted Searches and Address Bar InputWhatsApp rolls out usernames to help users hide their phone numberWhatsApp is Finally Getting Usernames to Help Keep Phone Numbers PrivateHijacked npm and Go Packages Use VS Code Tasks to Deploy Python InfostealerData breach exposes up to 14.2 million email logins at six ISPsUkraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging CredentialsClean GitHub repo tricks AI coding agents into running malwareOpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber SafeguardsFBI: Russian hackers now target Signal backup recovery keysCISA sets urgent deadline to fix Cisco flaw exploited in attacksFBI Warns Russian Intelligence Hackers Target Signal Backup Recovery KeysNew SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksPolymarket customers lose $3 million in supply-chain attackChinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia CampaignScattered Spider Hackers Plead Guilty on Day 1 of Trial‘Popa’ Botnet Linked to Publicly-Traded Israeli FirmShinyHunters ניצלו חולשה ב-Oracle PeopleSoft — אוניברסיטאות נפגעו במיוחדאתיקה והאקינג חוקי — הקווים האדומיםRed Team מול Blue Team — מי נגד מי בעולם הסייבראיך מזהים מייל פישינג (Phishing) ב-30 שניותכ-30,000 חומות אש של Fortinet נמצאו חשופות לפריצהDefense in Depth — למה הגנה אחת אף פעם לא מספיקהאיפה לתרגל פריצה בצורה חוקית — משאבי תרגולחולשה קריטית ב-Palo Alto PAN-OS מנוצלת באופן פעיל (CVE-2026-0257)מה זה בעצם CTF ואיך מתחילים?CISA הוסיפה חולשה קריטית (CVSS 10) ב-Joomla JCE לקטלוג ה-KEVאבטחת API — הדלת האחורית של אפליקציות מודרניותהסמכות סייבר — מאיפה מתחילים ומה שווהCyber Kill Chain — איך נראית מתקפה משלב לשלבקמפיין פישינג בהתחזות לרשת Boots — כ-9 מיליון נמעניםמיקרוסופט מתקנת חולשת Zero-Day ב-Defender (CVE-2026-50656, 'RoguePlanet')אבטחת ענן — מודל האחריות המשותפתמפת דרכים ללימוד סייבר — מאיפה מתחילים ב-2026כלל 3-2-1 לגיבויים — ההגנה הכי טובה מפני כופרהThreat Intelligence — מודיעין איומים בפשטותאיך מקימים מעבדת סייבר בבית (חינם)Europol שיבשה את שירות הלבנת-הקריפטו AudiA6 ששירת כנופיות כופרהמגמה: התקפות פישינג מבוססות-AI נעשות משכנעות יותרסיסמאות חזקות ו-2FA: ההגנה שכל אחד חייבMITRE ATT&CK — מילון הטקטיקות של התוקפיםMetasploit — מבוא למסגרת הניצולActive Directory תחת מתקפה — Kerberoasting, Pass-the-Hash והגנהVPN, Proxy ו-Tor — מה ההבדל ומתי להשתמשCyberChef — הסכין השוויצרי לפענוח וקידודמנהלי סיסמאות — למה אתם חייבים אחדKali Linux — מערכת ההפעלה של בודקי החדירותSQL Injection מוסבר בפשטותWho Runs the Ransomware Group ‘The Gentlemen?’אימות רב-שלבי (MFA) — סוגים ולמה FIDO2 הכי חזקNmap למתחילים — מיפוי רשתות ופורטיםמבוא להנדסה הפוכה (Reverse Engineering) של תוכנהמגמה: עלייה במתקפות על שרשרת האספקה (Supply Chain)Hardening — הקשחת מערכות לצמצום משטח התקיפהNetwork Segmentation — חלוקת הרשת כדי לעצור התפשטותZero Trust — למה 'לא לסמוך על אף אחד' זה גישת אבטחהPatch Management — למה עדכונים הם ההגנה הכי משתלמתלמה אתם שומעים על CVE כל הזמן?Incident Response — מה עושים כשפורצים? 6 השלביםLogging ו-Monitoring — אי אפשר להגן על מה שלא רואיםניתוח אירוע: Log4Shell — החולשה ששיתקה את האינטרנט (CVE-2021-44228)XSS מוסבר — כשאתר מריץ קוד של תוקף בדפדפן שלכםSOC ו-SIEM — חדר הבקרה של אבטחת המידעארגז הכלים של CyberHub — מה יש ולמהBotnets — צבא המחשבים המודבקיםOSINT למתחילים — מודיעין ממקורות גלוייםBrute Force ו-Credential Stuffing — ניחוש סיסמאות בקנה מידהMan-in-the-Middle — כשמישהו מקשיב באמצעWireshark למתחילים — לראות את הרשת בעינייםCookies, Sessions ו-Tokens — איך אתרים זוכרים שאתם מחובריםהנדסה חברתית — הפריצה הכי מסוכנת היא דרך בני אדםSecurity Headers — הגנות שמופעלות בכותרת אחתניתוח אירוע: מתקפת SolarWinds — כשהעדכון עצמו היה הנשקSSRF — כשמשכנעים את השרת לפנות למקום אסורIDOR — כשמספר ב-URL פותח דלת לנתונים של אחריםVPN — מה זה באמת עושה (ומה לא)Broken Authentication — כשמנגנון ההתחברות שביראיך אתרים שומרים סיסמאות נכון — Salt, bcrypt ו-Argon2TLS Handshake ו-PKI — איך באמת נוצר המנעול בדפדפןDDoS — מתקפת מניעת שירות בפשטותניתוח אירוע: הדלת האחורית ב-XZ Utils (CVE-2024-3094) — איך כמעט נפרץ כל לינוקסMalware 101 — מדריך לסוגי הנוזקותCSRF — איך אתר זדוני מבצע פעולות בשמכםOWASP Top 10 — מפת הסיכונים של אבטחת WebHashing — טביעת האצבע הדיגיטלית (ולמה זו לא הצפנה)הצפנה למתחילים — סימטרית מול אסימטריתFirewall — איך חומת אש מגינה על הרשתשורת הפקודה (Terminal) — הפקודות שחייבים להכירמבוא ללינוקס לאנשי סייבר — למה כולם משתמשים בוכתובות IP, פורטים ופרוטוקולים — אוצר המילים של הרשתHTTP מול HTTPS — למה המנעול בדפדפן כל כך חשובDNS — ספר הטלפונים של האינטרנט (ואיך תוקפים אותו)איך עובד האינטרנט? מבוא ל-TCP/IP למתחיליםשלישיית ה-CIA — שלושת עמודי התווך של אבטחת מידעמה זה בעצם סייבר? מבוא לעולם אבטחת המידע

נושאים בפורום (7)