unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Vulnerability / Cloud SecurityMicrosoft has released fixes for a maximum-severity security flaw in...
2026-9-18 12:47:4 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
windows
microsoft
privileges
2026
attacker
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The C...
2026-9-18 11:1:16 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
security
hostnames
analysis
hostile
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Vulnerability / Artificial IntelligenceA flaw in four widely used AI coding agents lets someone wh...
2026-9-18 11:1:1 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
github
agents
gemini
repository
anthropic
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deli...
2026-9-18 10:40:6 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
biz44
client
ottercookie
beavertail
contagious
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaS...
2026-9-18 09:18:3 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
stealer
security
crowdstrike
remote
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Mobile Security / MalwareCybersecurity researchers have flagged a new Android malware called RatHa...
2026-9-18 06:17:25 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
rathat
frp
analysis
reverse
zimperium
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attack...
2026-9-17 18:8:28 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
2026
security
hotfix
jumbo
r82
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them...
2026-9-17 17:32:22 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
2026
windows
software
payload
ransomware
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Vulnerability / Artificial IntelligenceMalicious code running inside a Docker Sandboxes virtual ma...
2026-9-17 15:37:56 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
machine
2026
79994
catalog
repository
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based...
2026-9-17 14:3:13 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
heavygram
windows
c2
iran
stage
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Vulnerability / DNS SecurityEvery release of the Unbound DNS resolver before 1.26.1 has a critical...
2026-9-17 12:30:0 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
2026
nlnet
81642
remote
security
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
Security Operations / Artificial IntelligenceA new CVE drops. Your scanner finds it. The severity...
2026-9-17 11:50:0 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
security
prove
matters
mythos
gap
CISO's Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). Th...
2026-9-17 10:50:53 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
agentic
2026
attackers
annual
engagement
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
Malware / Cyber EspionageThe China-aligned state-sponsored threat actor known as FamousSparrow ha...
2026-9-17 10:5:45 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
sparrowocky
eset
america
latin
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
Artificial Intelligence / VulnerabilityOpenAI on Wednesday disclosed six new instances of "unexpec...
2026-9-17 09:53:38 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
openai
2026
agents
alignment
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen secur...
2026-9-17 08:0:29 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
2026
isc
resolver
fourteen
attacker
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user re...
2026-9-17 07:30:1 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
helpfeel
gyazo
captures
attacker
maintenance
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Vulnerability / Web SecurityCisco has warned of a fresh maximum-severity security flaw impacting I...
2026-9-17 06:39:40 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
2026
ise
attacker
remote
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
Cybercrime / DDoS-for-HireThe U.S. Department of Justice (DoJ) on Tuesday announced the court-auth...
2026-9-17 05:13:46 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
hire
doj
seized
district
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Vulnerability / Web SecurityA critical security flaw in Issabel Framework, a web-based framework f...
2026-9-16 15:50:59 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
2026
issabel
coded
asterisk
security
Previous
-1275
-1274
-1273
-1272
-1271
-1270
-1269
-1268
Next