unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Ed...
2026-8-17 21:3:4 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
gitlab
2026
directive
multiplex
attacker
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Vulnerability / Artificial IntelligenceCybersecurity researchers at Wiz have disclosed a new GitHu...
2026-8-17 18:44:17 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
jira
github
snowflake
wiz
copilot
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Vulnerability / Website SecurityA critical security flaw has been disclosed in Forminator Forms,...
2026-8-17 18:22:9 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
wordpress
wordfence
attacker
security
php
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-an...
2026-8-17 17:41:6 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
c2
microsoft
cavern
2026
mailbox
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones.This week had plenty of proof. Exposed servi...
2026-8-17 13:23:51 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
2026
microsoft
security
remote
chromium
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned...
2026-8-17 11:58:0 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
mcp
agents
attacker
injection
security
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Vulnerability / Mobile SecuritySecurity researchers at SSD Secure Disclosure have published a two-...
2026-8-17 10:52:34 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
modem
unisoc
security
2026
memory
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1B...
2026-8-17 09:29:55 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
injection
proxy
remote
routers
c2
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broa...
2026-8-17 07:36:19 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
2026
vcenter
59310
vsphere
ssh
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
Vulnerability / Cloud SecurityA maximum-severity security vulnerability impacting SAP Commerce Clo...
2026-8-15 08:38:46 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
cloud
58231
2026
security
netweaver
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to d...
2026-8-15 07:24:4 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
2026
remote
security
machine
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect v...
2026-8-14 18:48:46 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
squirrel
dropcatch
expired
sable
reputation
IAM Compliance Requirements and Best Practices
IAM compliance is the practice of demonstrating that identity and access controls are not only docu...
2026-8-14 17:19:49 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
privileged
identities
auditors
lifecycle
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated vers...
2026-8-14 13:8:56 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
coolclient
windows
msagent
c2
stage
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Browser Security / Endpoint SecurityCybersecurity researchers have detailed a post-exploitation te...
2026-8-14 11:7:45 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
chrome
cdp
remote
repository
specterops
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign...
2026-8-14 10:57:0 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
recruitment
phishing
ctm360
bitb
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
Spyware / Cyber EspionageApple on Thursday sent a fresh batch of notifications to customers whom i...
2026-8-14 10:44:34 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
spyware
mercenary
notified
attackers
tend
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
2026-8-14 09:38:56 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
american
schemes
citizens
combat
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Vulnerability / Enterprise SecurityThreat actors have begun to exploit a newly disclosed Microsoft...
2026-8-13 06:9:48 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
attacker
2026
rapid7
microsoft
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Vulnerability / Cyber EspionageThe North Korean threat actor known as Lazarus Group has been attri...
2026-8-12 17:39:27 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
enveil
download
securitypdf
security
malicious
Previous
-134
-133
-132
-131
-130
-129
-128
-127
Next