unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension...
2026-8-10 07:38:23 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
solidity
malicious
stealer
github
clipboard
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial...
2026-8-10 05:50:3 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
security
openai
astra
network
frontier
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence dat...
2026-8-8 08:54:50 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
rovo
atlassian
attacker
promptarmor
jira
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Email Security / VulnerabilityNew research shows content inside an email can escape its message bo...
2026-8-8 08:3:57 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
attacker
victim
fastmail
yahoo
proton
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and d...
2026-8-8 06:58:31 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
metabase
security
advised
attacker
database
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Vulnerability / Enterprise SecurityN-able has released a fresh round of hotfixes for N‑central as...
2026-8-8 06:57:43 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
2026
hotfix
235
security
249
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Vulnerability / Network SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) o...
2026-8-8 06:52:16 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
2026
security
loadmaster
injection
attacker
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new...
2026-8-7 18:48:17 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
payload
windows
wel1
remote
malicious
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Malware / Social EngineeringClickFix-style attacks are being used to deliver a Go-based malware ca...
2026-8-7 18:29:8 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
clickfix
stealer
payload
malicious
victim
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional servi...
2026-8-7 18:16:13 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
2026
phishing
extortion
unc6671
security
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Web Security / VulnerabilityWordPress has fixed a pre-authentication reflected cross-site scripti...
2026-8-7 12:56:23 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
wordpress
php
attacker
security
Growing Up The Hard Way
Open Source had a great childhood.For two decades it got to be a kid. It ran around barefoot, gav...
2026-8-7 11:55:26 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
maintainers
subset
maintainer
software
puppy
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Te...
2026-8-7 11:10:33 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
sctp
machine
neither
exposure
sctphantom
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active "widespread email-driven phishing camp...
2026-8-7 10:38:27 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
microsoft
phishing
wolf
arctic
payroll
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
Web Security / VulnerabilityPortSwigger says HTTP Terminator, an artificial intelligence (AI)-assi...
2026-8-7 10:9:54 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
kettle
rqp
terminator
portswigger
desync
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Network Security / VulnerabilitySecurity researcher Malcolm Stagg has disclosed a new attack class...
2026-8-7 09:32:57 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
windows
natjack
network
stagg
2026
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Endpoint Security / VulnerabilityEntra ID researcher Dirk-jan Mollema demonstrated that malware al...
2026-8-7 08:52:11 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
windows
mollema
microsoft
attacker
entra
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Artificial Intelligence / VulnerabilityA GitHub issue opened by an account with no repository priv...
2026-8-7 08:18:35 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
gemini
claude
codex
openai
repository
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Cybercrime / VulnerabilityA new analysis has uncovered that the threat actor tracked as TeamPCP ha...
2026-8-7 06:50:5 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
teampcp
operational
security
oligo
kubernetes
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Virtualization Security / LinuxZapscape, a new Linux kernel vulnerability, could allow an attacker...
2026-8-6 17:58:30 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
kim
mmu
shadow
2026
stale
Previous
1
2
3
4
5
6
7
8
Next