unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a...
2026-8-18 11:40:6 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
malicious
rubygems
gem
yanked
payload
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
SaaS Security / Cloud SecurityA single piece of infrastructure has been pulling records out of Sal...
2026-8-18 11:30:0 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
reco
security
salesforce
servicenow
portals
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, em...
2026-8-18 09:10:45 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
safepal
security
2026
phishing
shipping
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Vulnerability / Network SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) o...
2026-8-18 06:34:20 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
ray
rebinding
security
malicious
network
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Ed...
2026-8-17 21:3:4 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
gitlab
2026
directive
multiplex
attacker
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Vulnerability / Artificial IntelligenceCybersecurity researchers at Wiz have disclosed a new GitHu...
2026-8-17 18:44:17 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
jira
github
snowflake
wiz
copilot
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Vulnerability / Website SecurityA critical security flaw has been disclosed in Forminator Forms,...
2026-8-17 18:22:9 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
wordpress
wordfence
attacker
security
php
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-an...
2026-8-17 17:41:6 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
c2
microsoft
cavern
2026
mailbox
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones.This week had plenty of proof. Exposed servi...
2026-8-17 13:23:51 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
2026
microsoft
security
remote
chromium
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned...
2026-8-17 11:58:0 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
mcp
agents
attacker
injection
security
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Vulnerability / Mobile SecuritySecurity researchers at SSD Secure Disclosure have published a two-...
2026-8-17 10:52:34 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
modem
unisoc
security
2026
memory
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1B...
2026-8-17 09:29:55 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
injection
proxy
remote
routers
c2
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broa...
2026-8-17 07:36:19 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
2026
vcenter
59310
vsphere
ssh
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
Vulnerability / Cloud SecurityA maximum-severity security vulnerability impacting SAP Commerce Clo...
2026-8-15 08:38:46 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
cloud
58231
2026
security
netweaver
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to d...
2026-8-15 07:24:4 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
2026
remote
security
machine
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect v...
2026-8-14 18:48:46 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
squirrel
dropcatch
expired
sable
reputation
IAM Compliance Requirements and Best Practices
IAM compliance is the practice of demonstrating that identity and access controls are not only docu...
2026-8-14 17:19:49 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
privileged
identities
auditors
lifecycle
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated vers...
2026-8-14 13:8:56 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
coolclient
windows
msagent
c2
stage
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Browser Security / Endpoint SecurityCybersecurity researchers have detailed a post-exploitation te...
2026-8-14 11:7:45 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
chrome
cdp
remote
repository
specterops
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign...
2026-8-14 10:57:0 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
recruitment
phishing
ctm360
bitb
Previous
-148
-147
-146
-145
-144
-143
-142
-141
Next