unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Vulnerability / Enterprise SecurityCisco has published another round of security updates for Cross...
2026-8-21 10:3:11 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
2026
security
software
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
Vulnerability / Enterprise SecurityA newly disclosed security flaw in GitLab has come under active...
2026-8-21 07:4:25 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
gitlab
watchtowr
security
attacker
landed
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Vulnerability / Threat IntelligenceMicrosoft on Thursday warned of a maximum-severity security fla...
2026-8-21 06:6:11 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
microsoft
security
exploited
entra
thursday
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io a...
2026-8-20 20:22:35 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
crates
arrayref
malicious
crate
payload
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legi...
2026-8-20 19:59:19 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
phishing
attacker
unc7005
2026
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.S...
2026-8-20 17:23:48 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
security
2026
remote
glm
kriminal
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure or...
2026-8-20 16:59:44 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
s7
plcs
siemens
plc
agents
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a us...
2026-8-20 14:36:27 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
grok
adversa
xai
2026
gemini
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Vulnerability / Application SecurityCybersecurity researchers have disclosed a critical security f...
2026-8-20 13:48:24 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
isolate
isolated
crash
memory
corrupt
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Network Security / Enterprise SecurityCitrix has released updates to address two security flaws...
2026-8-20 13:35:13 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
netscaler
proxy
adc
fips
vserver
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Vulnerability / Email SecurityA now-patched security flaw impacting Zimbra Collaboration (ZCS) has...
2026-8-20 13:24:28 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
zimbra
security
polska
jetty
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives exp...
2026-8-20 12:1:24 | 阅读: 29 |
收藏
|
The Hacker News - thehackernews.com
expiry
visa
expired
expiration
Why "Shady AI" is Security's Next Big Governance Problem
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company an...
2026-8-20 11:45:0 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
security
governance
shady
approved
shadow
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major...
2026-8-20 11:39:35 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
cloudfront
alibaba
bandwidth
fastly
qpack
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, governme...
2026-8-20 11:26:8 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
manic
queued
c2
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operat...
2026-8-20 11:5:11 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
2026
instrument
ait
cycode
spacecraft
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Malware / Mobile SecurityCybersecurity researchers have shed light on an updated version of ToxicP...
2026-8-20 10:38:28 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
golddigger
toxicpanda
security
c2
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Browser Security / CryptocurrencyA set of 40 Mozilla Firefox extensions has been found to engage i...
2026-8-20 08:42:3 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
malicious
sports
football
ons
identities
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Vulnerability / Web SecurityCybersecurity researchers have disclosed details of a critical flaw in...
2026-8-20 06:4:34 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
wordpress
security
php
elementor
remote
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cloud Security / VulnerabilityCybersecurity researchers have disclosed details of a remote Spectre...
2026-8-19 19:2:40 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
dypris
memory
isolates
victim
remote
Previous
-212
-211
-210
-209
-208
-207
-206
-205
Next