unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
2026-9-23 16:53:10 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
gitlab
aikido
attacker
mailbox
whereas
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative c...
2026-9-23 16:6:41 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
ssh
polska
2026
mikrotik
routeros
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models i...
2026-9-23 14:17:58 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
talos
windows
attacker
inspection
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm a...
2026-9-23 13:52:46 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
pypi
github
memtensor
cloud
developer
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Vulnerability / Web SecurityA flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPane...
2026-9-23 12:16:0 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
cpanel
wp
2026
plesk
whm
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how g...
2026-9-23 11:47:19 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
xranges
exploited
agents
security
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) comp...
2026-9-23 11:47:13 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
gpt
opus
openai
sol
luna
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container...
2026-9-23 11:12:18 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
depthfirst
containers
collector
security
sockets
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Vulnerability / Network SecurityAttackers are exploiting a critical flaw in F5 BIG-IP Access Polic...
2026-9-23 08:29:48 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
hotfix
apm
kev
eng
bigip
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google...
2026-9-23 08:29:24 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
2026
chrome
windows
download
chow
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Vulnerability / Web SecurityA new security vulnerability in Next.js could allow attackers to run c...
2026-9-23 07:4:40 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
vercel
satori
security
attacker
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal...
2026-9-23 05:30:9 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
2026
peoplesoft
maor
attackers
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Network Security / VulnerabilityAttackers exploited a previously unknown flaw in Check Point's S...
2026-9-22 18:29:39 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
r82
jumbo
hotfix
r81
2026
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Vulnerability / Web SecurityWordPress has fixed a critical flaw in its core software that lets an...
2026-9-22 18:3:10 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
wordpress
php
security
attacker
ressl
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Supply Chain Attack / MalwareCybersecurity researchers have disclosed details of a malicious npm p...
2026-9-22 17:58:15 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
twilio
malicious
pkgprobe
tw
security
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it...
2026-9-22 17:3:31 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
eviltokens
microsoft
phishing
victim
2026
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Artificial Intelligence / VulnerabilityA critical vulnerability in Bifrost, an open-source AI gate...
2026-9-22 16:41:12 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
bifrost
mcp
transports
attacker
2026
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
Vulnerability / Endpoint SecurityA zero-day proof-of-concept tool that stops Microsoft Defender fr...
2026-9-22 16:14:4 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
defender
microsoft
windows
naceri
AI Agents Are Rewriting the Rules of Lateral Movement
Security teams have spent decades asking whether an identity has too much access. AI agents raise a...
2026-9-22 12:30:0 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
agents
security
identities
autonomous
agentic
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Vulnerability / Network SecurityAttackers are exploiting a new flaw in on-premises VeloCloud Orc...
2026-9-22 12:29:0 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
vco
arista
velocloud
vc
Previous
-1421
-1420
-1419
-1418
-1417
-1416
-1415
-1414
Next