unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploita...
2026-9-15 11:52:28 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
ssh
marimo
bastion
sysdig
skilled
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
IntroductionSecurity teams have gotten pretty good at testing against what can hurt them. Can thi...
2026-9-15 11:26:36 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
chaining
gap
security
stage
phishing
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Vulnerability / Cloud SecurityCybersecurity researchers have disclosed details of a mass-scanning...
2026-9-15 11:12:32 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
vite
cloud
deny
attackers
security
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
Vulnerability / Web SecurityA critical vulnerability in LiteSpeed Web Server Enterprise could let...
2026-9-15 06:52:16 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
litespeed
cpanel
security
neither
exploited
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Vulnerability / Network SecurityCisco has warned that a new critical vulnerability impacting Asy...
2026-9-15 06:11:11 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
malicious
2026
attacker
privileges
security
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patc...
2026-9-15 05:31:5 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
chrome
windows
c2
volexity
uta0560
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Network Security / Cyber AttackAn attacker was operating inside the network of 3BB, one of Thailan...
2026-9-14 18:1:49 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
attacker
3bb
meshcentral
hunt
recovered
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users ex...
2026-9-14 17:58:16 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
chats
buttons
publication
shipped
escaping
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection i...
2026-9-14 16:58:42 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
memory
ddrop
machine
interposer
tdx
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Cyber Espionage / VulnerabilityA suspected Chinese threat actor tracked as Red Heron has been attr...
2026-9-14 16:56:30 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
heron
gitea
2026
network
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
Web Security / VulnerabilityWordPress has announced it's launching an automated security review f...
2026-9-14 16:0:4 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
security
wordpress
cooldown
malicious
perez
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defens...
2026-9-14 14:40:34 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
2026
security
anthropic
agents
microsoft
AI Changed the Exposure Problem. Validation Needs to Change With It.
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simp...
2026-9-14 11:58:0 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
security
exposure
picus
exposures
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Malware / Browser SecurityA malicious cross-store Twitch browser extension has leaked OAuth tokens...
2026-9-14 07:24:39 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
twitch
followers
proxy
jeetbot
developer
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party ema...
2026-9-13 10:11:48 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
microsoft
passkey
phishing
victim
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Vulnerability / Enterprise SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA...
2026-9-12 15:54:45 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
2026
routeros
artifactory
mikrotik
When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations cente...
2026-9-12 10:24:44 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
agents
noise
benign
security
claude
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI...
2026-9-12 09:7:56 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
agents
rubygems
2026
wiki
openai
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Vulnerability / Web SecurityGitLab has released patches to address multiple flaws, including a max...
2026-9-11 16:30:18 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
gitlab
2026
repository
attackers
watchtowr
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Artificial Intelligence / CybercrimeAnthropic on Thursday said it identified and disrupted industr...
2026-9-11 16:15:29 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
claude
exchanges
anthropic
gtg
Previous
-1171
-1170
-1169
-1168
-1167
-1166
-1165
-1164
Next