unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shu...
2026-9-21 17:31:1 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
lastpass
windows
microsoft
stealer
security
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 3...
2026-9-21 17:19:0 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
north
korean
waterplum
japan
developers
Google Fined €403 Million Over GDPR Violations Tied to Location Data
Data Privacy / Regulatory ComplianceGoogle has been fined €403 million for breaking the EU's data...
2026-9-21 16:57:31 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
dpc
inquiry
beuc
accuracy
european
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this we...
2026-9-21 14:24:13 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
2026
security
brevo
openai
clickfix
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Endpoint Security / MalwareCybersecurity researchers have disclosed details of a new campaign dubb...
2026-9-21 14:15:40 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
powershell
c2
windows
vbscript
clipboard
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote acce...
2026-9-21 08:39:38 | 阅读: 31 |
收藏
|
The Hacker News - thehackernews.com
chainscript
clickfix
malicious
stealer
stage
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Malware / Social EngineeringThe North Korean threat actor known as Jade Sleet has been attributed...
2026-9-21 06:6:44 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
roofdeck
kelpdao
flatroof
backdoors
developer
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused cr...
2026-9-19 13:28:41 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
cloud
identities
security
governance
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws a...
2026-9-19 10:1:10 | 阅读: 30 |
收藏
|
The Hacker News - thehackernews.com
openai
libheif
2026
discourse
hacktron
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Vulnerability / Identity SecuritySolarWinds has released security updates to address a high-severi...
2026-9-19 09:31:17 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
2026
remote
security
desk
whd
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Vulnerability / Web SecurityA critical vulnerability impacting Orkes Conductor is being actively e...
2026-9-19 08:18:54 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
conductor
2026
orkes
remote
attackers
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Artificial Intelligence / Web SecurityGoogle's Gemini model has become the latest artificial intel...
2026-9-19 07:51:34 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
openai
irregular
journal
evaluation
agents
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account...
2026-9-19 07:14:54 | 阅读: 25 |
收藏
|
The Hacker News - thehackernews.com
crowdsec
github
tanstack
investors
malicious
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security fla...
2026-9-19 06:24:10 | 阅读: 30 |
收藏
|
The Hacker News - thehackernews.com
2026
security
attacker
exploited
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a...
2026-9-18 18:2:24 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
manizada
diagspill
dirtyah6
sctp
network
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
Vulnerability / Web SecurityWordPress today released patches to fix a new set of vulnerabilities i...
2026-9-18 16:56:19 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
wordpress
security
attacker
click2shell
neither
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
Malware / Cyber EspionageThe Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36...
2026-9-18 15:24:16 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
india
github
rustyshade
apt36
c2
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Vulnerability / Cloud SecurityMicrosoft has released fixes for a maximum-severity security flaw in...
2026-9-18 12:47:4 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
windows
microsoft
privileges
2026
attacker
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The C...
2026-9-18 11:1:16 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
security
hostnames
analysis
hostile
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Vulnerability / Artificial IntelligenceA flaw in four widely used AI coding agents lets someone wh...
2026-9-18 11:1:1 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
github
agents
gemini
repository
anthropic
Previous
-1365
-1364
-1363
-1362
-1361
-1360
-1359
-1358
Next