unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
DORA Year Two: Can Your SOC Actually See the Attack?
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in...
2026-9-22 11:45:0 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
network
dora
ict
ndr
security
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
Vulnerability / VirtualizationA new flaw in the Linux kernel's KVM virtualization code for ARM64 p...
2026-9-22 11:38:40 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
machine
kernels
memory
hardware
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Vulnerability / Web SecurityA SharePoint Server vulnerability that Microsoft initially classified...
2026-9-22 11:17:41 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
microsoft
2026
khoa
65660
security
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior withi...
2026-9-22 09:38:18 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
malicious
btree
security
lifecycle
developer
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
Malware / Cyber EspionageThe threat actor known as SideCopy has been observed using spear-phishing...
2026-9-22 07:52:3 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
sidecopy
remote
trellix
phishing
spear
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Vulnerability / Artificial IntelligenceMalware already running on a Mac can quietly take over Meta...
2026-9-22 06:33:57 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
muse
attacker
wardle
dictation
cloud
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Vulnerability / Web SecurityA new flaw in WordPress core let an anonymous visitor leave a comment...
2026-9-22 06:3:14 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
wordpress
security
attacker
exploited
moderation
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Vulnerability / Endpoint SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA...
2026-9-22 05:31:59 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
gs1900
veeam
zyxel
2026
elevated
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shu...
2026-9-21 17:31:1 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
lastpass
windows
microsoft
stealer
security
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 3...
2026-9-21 17:19:0 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
north
korean
waterplum
japan
developers
Google Fined €403 Million Over GDPR Violations Tied to Location Data
Data Privacy / Regulatory ComplianceGoogle has been fined €403 million for breaking the EU's data...
2026-9-21 16:57:31 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
dpc
inquiry
beuc
accuracy
european
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this we...
2026-9-21 14:24:13 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
2026
security
brevo
openai
clickfix
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Endpoint Security / MalwareCybersecurity researchers have disclosed details of a new campaign dubb...
2026-9-21 14:15:40 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
powershell
c2
windows
vbscript
clipboard
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote acce...
2026-9-21 08:39:38 | 阅读: 32 |
收藏
|
The Hacker News - thehackernews.com
chainscript
clickfix
malicious
stealer
stage
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Malware / Social EngineeringThe North Korean threat actor known as Jade Sleet has been attributed...
2026-9-21 06:6:44 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
roofdeck
kelpdao
flatroof
backdoors
developer
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused cr...
2026-9-19 13:28:41 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
cloud
identities
security
governance
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws a...
2026-9-19 10:1:10 | 阅读: 33 |
收藏
|
The Hacker News - thehackernews.com
openai
libheif
2026
discourse
hacktron
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Vulnerability / Identity SecuritySolarWinds has released security updates to address a high-severi...
2026-9-19 09:31:17 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
2026
remote
security
desk
whd
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Vulnerability / Web SecurityA critical vulnerability impacting Orkes Conductor is being actively e...
2026-9-19 08:18:54 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
conductor
2026
orkes
remote
attackers
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Artificial Intelligence / Web SecurityGoogle's Gemini model has become the latest artificial intel...
2026-9-19 07:51:34 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
openai
irregular
journal
evaluation
agents
Previous
-1383
-1382
-1381
-1380
-1379
-1378
-1377
-1376
Next