unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Phishing / Identity SecurityThreat hunters have disclosed details of a widespread data theft and e...
2026-9-7 15:51:56 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
lure
extortion
phishing
victim
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround:...
2026-9-7 14:36:7 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
2026
attackers
coder
phishing
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
Cloud Security / Data SecurityIf managing security across multiple cloud providers wasn't hard e...
2026-9-7 11:45:0 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
cloud
permissive
security
encryption
firewalls
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise Scre...
2026-9-7 11:36:39 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
client
huntress
vbscript
rogue
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into u...
2026-9-7 11:20:14 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
2026
tantosec
telerik
attacker
encryption
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
Vulnerability / Enterprise SecurityEvery on-premises N-central build below 2026.3.1.14 — including...
2026-9-7 08:31:12 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
2026
hotfix
exploited
security
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malwar...
2026-9-7 07:53:4 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
jsceal
proxy
victim
opera
payload
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Vulnerability / Network SecurityAttackers are exploiting MikroTik routers with their Secure Shell...
2026-9-6 09:32:38 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
routeros
security
mikrotik
ssh
recommends
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER...
2026-9-6 08:34:20 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
revstealer
stealer
windows
promanager
lockapphost
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce th...
2026-9-5 20:14:47 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
disrex
sansec
magento
php
gvfsd
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Data Breach / Identity SecurityJetBrains is urging Cadence users to revoke and rotate all credenti...
2026-9-5 16:52:33 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
cadence
jetbrains
cloud
2026
executions
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Vulnerability / Server SecurityBroadcom has released security updates for two security flaws impac...
2026-9-5 16:5:8 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
privileges
security
2026
broadcom
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Data Breach / VulnerabilityHardware wallet manufacturer Trezor on Friday disclosed that another 67...
2026-9-5 14:17:2 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
trezor
shipmonk
security
exposure
shipping
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as Op...
2026-9-5 07:55:10 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
agents
openai
wiki
hugging
security
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Vulnerability / Web SecurityThreat actors are exploiting the newly disclosed PaperCut flaws to fac...
2026-9-5 07:31:53 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
papercut
arctic
wolf
lsa
whoami
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag chara...
2026-9-4 15:57:15 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
phishing
invisible
microsoft
funding
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICAT...
2026-9-4 15:20:19 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
replication
pg
cyera
library
slots
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAPro...
2026-9-4 14:51:13 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
rapid7
haproxy
korean
maltrail
apt37
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Vulnerability / Web SecurityThreat actors are exploiting two critical security flaws in WordPress...
2026-9-4 08:48:45 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
php
2026
attacker
32475
14894
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Vulnerability / Network SecurityPlex is urging users to update their instances to the latest versi...
2026-9-4 07:35:14 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
plex
security
exposing
network
attackers
Previous
-595
-594
-593
-592
-591
-590
-589
-588
Next