unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Vulnerability / Web SecurityA flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPane...
2026-9-23 12:16:0 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
cpanel
wp
2026
plesk
whm
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how g...
2026-9-23 11:47:19 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
xranges
exploited
agents
security
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) comp...
2026-9-23 11:47:13 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
gpt
opus
openai
sol
luna
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container...
2026-9-23 11:12:18 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
depthfirst
containers
collector
security
sockets
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Vulnerability / Network SecurityAttackers are exploiting a critical flaw in F5 BIG-IP Access Polic...
2026-9-23 08:29:48 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
hotfix
apm
kev
eng
bigip
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google...
2026-9-23 08:29:24 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
2026
chrome
windows
download
chow
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Vulnerability / Web SecurityA new security vulnerability in Next.js could allow attackers to run c...
2026-9-23 07:4:40 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
vercel
satori
security
attacker
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal...
2026-9-23 05:30:9 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
2026
peoplesoft
maor
attackers
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Network Security / VulnerabilityAttackers exploited a previously unknown flaw in Check Point's S...
2026-9-22 18:29:39 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
r82
jumbo
hotfix
r81
2026
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Vulnerability / Web SecurityWordPress has fixed a critical flaw in its core software that lets an...
2026-9-22 18:3:10 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
wordpress
php
security
attacker
ressl
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Supply Chain Attack / MalwareCybersecurity researchers have disclosed details of a malicious npm p...
2026-9-22 17:58:15 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
twilio
malicious
pkgprobe
tw
security
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it...
2026-9-22 17:3:31 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
eviltokens
microsoft
phishing
victim
2026
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Artificial Intelligence / VulnerabilityA critical vulnerability in Bifrost, an open-source AI gate...
2026-9-22 16:41:12 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
bifrost
mcp
transports
attacker
2026
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
Vulnerability / Endpoint SecurityA zero-day proof-of-concept tool that stops Microsoft Defender fr...
2026-9-22 16:14:4 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
defender
microsoft
windows
naceri
AI Agents Are Rewriting the Rules of Lateral Movement
Security teams have spent decades asking whether an identity has too much access. AI agents raise a...
2026-9-22 12:30:0 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
agents
security
identities
autonomous
agentic
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Vulnerability / Network SecurityAttackers are exploiting a new flaw in on-premises VeloCloud Orc...
2026-9-22 12:29:0 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
vco
arista
velocloud
vc
DORA Year Two: Can Your SOC Actually See the Attack?
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in...
2026-9-22 11:45:0 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
network
dora
ict
ndr
security
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
Vulnerability / VirtualizationA new flaw in the Linux kernel's KVM virtualization code for ARM64 p...
2026-9-22 11:38:40 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
machine
kernels
memory
hardware
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Vulnerability / Web SecurityA SharePoint Server vulnerability that Microsoft initially classified...
2026-9-22 11:17:41 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
microsoft
2026
khoa
65660
security
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior withi...
2026-9-22 09:38:18 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
malicious
btree
security
lifecycle
developer
Previous
-1415
-1414
-1413
-1412
-1411
-1410
-1409
-1408
Next