unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives exp...
2026-8-20 12:1:24 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
expiry
visa
expired
expiration
Why "Shady AI" is Security's Next Big Governance Problem
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company an...
2026-8-20 11:45:0 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
security
governance
shady
approved
shadow
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major...
2026-8-20 11:39:35 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
cloudfront
alibaba
bandwidth
fastly
qpack
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, governme...
2026-8-20 11:26:8 | 阅读: 0 |
收藏
|
The Hacker News - thehackernews.com
manic
queued
c2
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operat...
2026-8-20 11:5:11 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
2026
instrument
ait
cycode
spacecraft
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Malware / Mobile SecurityCybersecurity researchers have shed light on an updated version of ToxicP...
2026-8-20 10:38:28 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
golddigger
toxicpanda
security
c2
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Browser Security / CryptocurrencyA set of 40 Mozilla Firefox extensions has been found to engage i...
2026-8-20 08:42:3 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
malicious
sports
football
ons
identities
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Vulnerability / Web SecurityCybersecurity researchers have disclosed details of a critical flaw in...
2026-8-20 06:4:34 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
wordpress
security
php
elementor
remote
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cloud Security / VulnerabilityCybersecurity researchers have disclosed details of a remote Spectre...
2026-8-19 19:2:40 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
dypris
memory
isolates
victim
remote
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest arti...
2026-8-19 18:6:44 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
openai
security
monitoring
alignment
safeguards
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting g...
2026-8-19 13:12:17 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
goginrat
nomadrat
sideloading
c2
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised...
2026-8-19 11:34:28 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
dahua
firmware
hunt
bypass
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something ma...
2026-8-19 11:30:0 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
security
microsoft
2026
phishing
ironscales
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacke...
2026-8-19 11:25:28 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
wordpress
php
victim
stealer
ransomware
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Vulnerability / RansomwareThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tues...
2026-8-19 11:1:48 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
2026
exploited
network
vcenter
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused...
2026-8-19 06:1:53 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
microsoft
recurring
cloud
rst
macsync
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw...
2026-8-19 05:39:25 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
windchill
shells
reliaquest
database
clop
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it sai...
2026-8-18 17:47:22 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
copilot
memory
microsoft
varonis
attacker
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Vulnerability / Artificial IntelligenceTwo critical vulnerabilities impacting MLflow, an open-sour...
2026-8-18 17:44:5 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
2026
mlflow
fuxa
cloud
attacker
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to...
2026-8-18 16:58:16 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
ransomware
extortion
victim
crpx0
affiliate
Previous
-189
-188
-187
-186
-185
-184
-183
-182
Next