unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has...
2026-8-10 16:38:37 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
ransomware
1175
microsoft
security
medusa
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo...
2026-8-10 15:0:29 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
2026
security
phishing
remote
mcp
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Cyber Espionage / Artificial IntelligenceNorth Korea's state hackers are no longer content to type...
2026-8-10 13:19:58 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
genians
korean
firm
database
rag
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without b...
2026-8-10 12:25:4 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
windows
microsoft
passkey
entra
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
Software Supply Chain / DevSecOpsAI is helping development teams produce far more code, far faste...
2026-8-10 11:52:16 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
security
software
development
machine
webinar
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched True...
2026-8-10 11:33:41 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
trueconf
attackers
vipnet
loader
malicious
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension...
2026-8-10 07:38:23 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
solidity
malicious
stealer
github
clipboard
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial...
2026-8-10 05:50:3 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
security
openai
astra
network
frontier
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence dat...
2026-8-8 08:54:50 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
rovo
atlassian
attacker
promptarmor
jira
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Email Security / VulnerabilityNew research shows content inside an email can escape its message bo...
2026-8-8 08:3:57 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
attacker
victim
fastmail
yahoo
proton
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and d...
2026-8-8 06:58:31 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
metabase
security
advised
attacker
database
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Vulnerability / Enterprise SecurityN-able has released a fresh round of hotfixes for N‑central as...
2026-8-8 06:57:43 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
2026
hotfix
235
security
249
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Vulnerability / Network SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) o...
2026-8-8 06:52:16 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
2026
security
loadmaster
injection
attacker
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new...
2026-8-7 18:48:17 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
payload
windows
wel1
remote
malicious
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Malware / Social EngineeringClickFix-style attacks are being used to deliver a Go-based malware ca...
2026-8-7 18:29:8 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
clickfix
stealer
payload
malicious
victim
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional servi...
2026-8-7 18:16:13 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
2026
phishing
extortion
unc6671
security
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Web Security / VulnerabilityWordPress has fixed a pre-authentication reflected cross-site scripti...
2026-8-7 12:56:23 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
wordpress
php
attacker
security
Growing Up The Hard Way
Open Source had a great childhood.For two decades it got to be a kid. It ran around barefoot, gav...
2026-8-7 11:55:26 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
maintainers
subset
maintainer
software
puppy
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Te...
2026-8-7 11:10:33 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
sctp
machine
neither
exposure
sctphantom
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active "widespread email-driven phishing camp...
2026-8-7 10:38:27 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
microsoft
phishing
wolf
arctic
payroll
Previous
-8
-7
-6
-5
-4
-3
-2
-1
Next