unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Network Security / VulnerabilityAttackers exploited a previously unknown flaw in Check Point's S...
2026-9-22 18:29:39 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
r82
jumbo
hotfix
r81
2026
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Vulnerability / Web SecurityWordPress has fixed a critical flaw in its core software that lets an...
2026-9-22 18:3:10 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
wordpress
php
security
attacker
ressl
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Supply Chain Attack / MalwareCybersecurity researchers have disclosed details of a malicious npm p...
2026-9-22 17:58:15 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
twilio
malicious
pkgprobe
tw
security
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it...
2026-9-22 17:3:31 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
eviltokens
microsoft
phishing
victim
2026
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Artificial Intelligence / VulnerabilityA critical vulnerability in Bifrost, an open-source AI gate...
2026-9-22 16:41:12 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
bifrost
mcp
transports
attacker
2026
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
Vulnerability / Endpoint SecurityA zero-day proof-of-concept tool that stops Microsoft Defender fr...
2026-9-22 16:14:4 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
defender
microsoft
windows
naceri
AI Agents Are Rewriting the Rules of Lateral Movement
Security teams have spent decades asking whether an identity has too much access. AI agents raise a...
2026-9-22 12:30:0 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
agents
security
identities
autonomous
agentic
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Vulnerability / Network SecurityAttackers are exploiting a new flaw in on-premises VeloCloud Orc...
2026-9-22 12:29:0 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
vco
arista
velocloud
vc
DORA Year Two: Can Your SOC Actually See the Attack?
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in...
2026-9-22 11:45:0 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
network
dora
ict
ndr
security
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
Vulnerability / VirtualizationA new flaw in the Linux kernel's KVM virtualization code for ARM64 p...
2026-9-22 11:38:40 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
machine
kernels
memory
hardware
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Vulnerability / Web SecurityA SharePoint Server vulnerability that Microsoft initially classified...
2026-9-22 11:17:41 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
microsoft
2026
khoa
65660
security
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior withi...
2026-9-22 09:38:18 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
malicious
btree
security
lifecycle
developer
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
Malware / Cyber EspionageThe threat actor known as SideCopy has been observed using spear-phishing...
2026-9-22 07:52:3 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
sidecopy
remote
trellix
phishing
spear
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Vulnerability / Artificial IntelligenceMalware already running on a Mac can quietly take over Meta...
2026-9-22 06:33:57 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
muse
attacker
wardle
dictation
cloud
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Vulnerability / Web SecurityA new flaw in WordPress core let an anonymous visitor leave a comment...
2026-9-22 06:3:14 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
wordpress
security
attacker
exploited
moderation
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Vulnerability / Endpoint SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA...
2026-9-22 05:31:59 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
gs1900
veeam
zyxel
2026
elevated
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shu...
2026-9-21 17:31:1 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
lastpass
windows
microsoft
stealer
security
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 3...
2026-9-21 17:19:0 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
north
korean
waterplum
japan
developers
Google Fined €403 Million Over GDPR Violations Tied to Location Data
Data Privacy / Regulatory ComplianceGoogle has been fined €403 million for breaking the EU's data...
2026-9-21 16:57:31 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
dpc
inquiry
beuc
accuracy
european
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this we...
2026-9-21 14:24:13 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
2026
security
brevo
openai
clickfix
Previous
-1396
-1395
-1394
-1393
-1392
-1391
-1390
-1389
Next