unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Vulnerability / Mobile SecurityResearchers at the security firm Calif have built a worm that takes...
2026-9-8 11:54:29 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
calif
wechat
attacker
security
worm
What It Took to Reach 1 Billion Build Manifests
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion conta...
2026-9-8 11:49:2 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
chainguard
catalog
driftlessaf
rebuild
agentic
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choo...
2026-9-8 11:22:7 | 阅读: 2 |
收藏
|
The Hacker News - thehackernews.com
freeipa
389
2026
client
attacker
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Vulnerability / Web SecurityAdobe on Monday released security patches to address a maximum-sever...
2026-9-8 09:13:47 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
2026
magento
security
php
75650
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) po...
2026-9-8 08:43:51 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
bengalseo
lure
github
dfir
mayabot
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Data Privacy / RegulationOnline dating app Grindr has opted to pay £26 million ($35.1 million) to...
2026-9-8 07:0:43 | 阅读: 30 |
收藏
|
The Hacker News - thehackernews.com
grindr
hiv
advertisers
parties
2026
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Malware / Browser SecurityCybersecurity researchers have disclosed details of a complex Chromium-b...
2026-9-7 18:12:9 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
peep
socradar
c2
chrome
sideloading
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Phishing / Identity SecurityThreat hunters have disclosed details of a widespread data theft and e...
2026-9-7 15:51:56 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
lure
extortion
phishing
victim
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround:...
2026-9-7 14:36:7 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
2026
attackers
coder
phishing
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
Cloud Security / Data SecurityIf managing security across multiple cloud providers wasn't hard e...
2026-9-7 11:45:0 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
cloud
permissive
security
encryption
firewalls
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise Scre...
2026-9-7 11:36:39 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
client
huntress
vbscript
rogue
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into u...
2026-9-7 11:20:14 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
2026
tantosec
telerik
attacker
encryption
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
Vulnerability / Enterprise SecurityEvery on-premises N-central build below 2026.3.1.14 — including...
2026-9-7 08:31:12 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
2026
hotfix
exploited
security
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malwar...
2026-9-7 07:53:4 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
jsceal
proxy
victim
opera
payload
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Vulnerability / Network SecurityAttackers are exploiting MikroTik routers with their Secure Shell...
2026-9-6 09:32:38 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
routeros
security
mikrotik
ssh
recommends
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER...
2026-9-6 08:34:20 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
revstealer
stealer
windows
promanager
lockapphost
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce th...
2026-9-5 20:14:47 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
disrex
sansec
magento
php
gvfsd
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Data Breach / Identity SecurityJetBrains is urging Cadence users to revoke and rotate all credenti...
2026-9-5 16:52:33 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
cadence
jetbrains
cloud
2026
executions
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Vulnerability / Server SecurityBroadcom has released security updates for two security flaws impac...
2026-9-5 16:5:8 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
privileges
security
2026
broadcom
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Data Breach / VulnerabilityHardware wallet manufacturer Trezor on Friday disclosed that another 67...
2026-9-5 14:17:2 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
trezor
shipmonk
security
exposure
shipping
Previous
-616
-615
-614
-613
-612
-611
-610
-609
Next