unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.The phishing kit...
2026-8-5 11:43:19 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
kali365
microsoft
phishing
tier
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hos...
2026-8-5 11:4:23 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
gitea
2026
markup
repository
anonymous
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commi...
2026-8-5 10:35:29 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
n8n
workflows
github
attacker
gitguardian
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate dev...
2026-8-5 09:23:3 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
vscode
security
developer
repository
machine
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged...
2026-8-5 07:53:50 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
aisi
github
openai
agents
mythos
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Vulnerability / Patch ManagementThe U.S. Cybersecurity and Infrastructure Security Agency (CISA),...
2026-8-5 07:40:39 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
2026
autonomous
langflow
exploited
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain a...
2026-8-5 05:47:19 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
firebase
fdmtp
compat
quickfox
malicious
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest cri...
2026-8-4 17:27:39 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
greatness
phaas
ringcentral
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in
[email protected]
spread beyond the Keyv and Cacheab...
2026-8-4 13:30:23 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
safedep
keyv
github
mjs
claude
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs soc...
2026-8-4 13:11:22 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
stealer
remote
payload
victim
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
The cybersecurity industry has spent decades assuming that offensive capability scales with technic...
2026-8-4 11:30:0 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
security
attackers
attacker
exposure
expertise
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pil...
2026-8-4 11:16:23 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
adk
repository
pillar
pat
privileged
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Vulnerability / Database SecuritycPanel has patched a flaw that let an authenticated hosting custo...
2026-8-4 10:36:27 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
cpanel
database
exim
2026
58048
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way...
2026-8-4 09:3:23 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
payload
doublecup
c2
clickfix
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
Vulnerability / Enterprise SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA...
2026-8-4 07:0:13 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
2026
249
security
18577
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of...
2026-8-3 18:43:53 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
payload
malicious
aone
alibaba
maintainer
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected...
2026-8-3 16:24:47 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
chrome
attacker
chromium
victim
uv
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
Vulnerability / CybercrimeThe INC Ransomware operation has emerged as the "dominant threat actor"...
2026-8-3 16:15:13 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
ransomware
2026
rapid7
resecurity
lateral
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomn...
2026-8-3 14:3:11 | 阅读: 35 |
收藏
|
The Hacker News - thehackernews.com
2026
microsoft
security
phishing
cloud
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up.AI pla...
2026-8-3 11:30:0 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
security
claude
autonomous
mdr
Previous
3
4
5
6
7
8
9
10
Next