unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Vulnerability / Enterprise SecurityWindows Plug and Play can be abused to fetch signed vendor soft...
2026-8-11 10:48:26 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
windows
microsoft
remote
redirection
sierra
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
AI Security / Cyber AttackA malicious tool server connected to an AI coding assistant can quietly...
2026-8-11 10:24:0 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
mcp
asset
malicious
claude
sonnet
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware at...
2026-8-11 09:16:24 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
ransomware
gunra
network
security
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined hea...
2026-8-11 06:55:45 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
apn
attacker
plant
network
ssh
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Supply Chain Attack / VulnerabilityCybersecurity researchers have warned of a supply chain comprom...
2026-8-11 05:48:44 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
wordpress
elementor
c2
addons
bdthemes
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has...
2026-8-10 16:38:37 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
ransomware
1175
microsoft
security
medusa
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo...
2026-8-10 15:0:29 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
2026
security
phishing
remote
mcp
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Cyber Espionage / Artificial IntelligenceNorth Korea's state hackers are no longer content to type...
2026-8-10 13:19:58 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
genians
korean
firm
database
rag
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without b...
2026-8-10 12:25:4 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
windows
microsoft
passkey
entra
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
Software Supply Chain / DevSecOpsAI is helping development teams produce far more code, far faste...
2026-8-10 11:52:16 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
security
software
development
machine
webinar
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched True...
2026-8-10 11:33:41 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
trueconf
attackers
vipnet
loader
malicious
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension...
2026-8-10 07:38:23 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
solidity
malicious
stealer
github
clipboard
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial...
2026-8-10 05:50:3 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
security
openai
astra
network
frontier
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence dat...
2026-8-8 08:54:50 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
rovo
atlassian
attacker
promptarmor
jira
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Email Security / VulnerabilityNew research shows content inside an email can escape its message bo...
2026-8-8 08:3:57 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
attacker
victim
fastmail
yahoo
proton
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and d...
2026-8-8 06:58:31 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
metabase
security
advised
attacker
database
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Vulnerability / Enterprise SecurityN-able has released a fresh round of hotfixes for N‑central as...
2026-8-8 06:57:43 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
2026
hotfix
235
security
249
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Vulnerability / Network SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) o...
2026-8-8 06:52:16 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
2026
security
loadmaster
injection
attacker
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new...
2026-8-7 18:48:17 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
payload
windows
wel1
remote
malicious
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Malware / Social EngineeringClickFix-style attacks are being used to deliver a Go-based malware ca...
2026-8-7 18:29:8 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
clickfix
stealer
payload
malicious
victim
Previous
1
2
3
4
5
6
7
8
Next