unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Cod...
2026-7-8 17:2:12 | 阅读: 39 |
收藏
|
The Hacker News - thehackernews.com
agents
sophos
claude
attacker
windows
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will...
2026-7-8 15:7:24 | 阅读: 38 |
收藏
|
The Hacker News - thehackernews.com
attacker
invents
machine
gemini
repository
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Vulnerability / Network SecurityUbiquiti has shipped updates to address multiple critical security...
2026-7-8 14:38:5 | 阅读: 41 |
收藏
|
The Hacker News - thehackernews.com
unifi
2026
network
attacker
affects
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email...
2026-7-8 13:0:0 | 阅读: 29 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
eviltokens
security
exposure
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment proces...
2026-7-8 12:52:15 | 阅读: 29 |
收藏
|
The Hacker News - thehackernews.com
windows
victim
security
clipboard
scmbanker
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the s...
2026-7-8 11:51:24 | 阅读: 35 |
收藏
|
The Hacker News - thehackernews.com
github
forge
ginesin
ecdsa
fetches
The Verification Step Is the New ATO Battleground in 2026
For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credential...
2026-7-8 11:30:0 | 阅读: 29 |
收藏
|
The Hacker News - thehackernews.com
ato
2026
attackers
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it any...
2026-7-8 11:21:7 | 阅读: 32 |
收藏
|
The Hacker News - thehackernews.com
harmful
copilot
answers
prompts
816
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
Malware / Network SecurityA Chinese threat actor tracked as UAT-7810 is actively refining its besp...
2026-7-8 09:4:33 | 阅读: 38 |
收藏
|
The Hacker News - thehackernews.com
uat
7810
network
orb
c2
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Vulnerability / Cloud SecurityResearchers at Nebula Security have disclosed GhostLock (CVE-2026-43...
2026-7-8 06:16:44 | 阅读: 52 |
收藏
|
The Hacker News - thehackernews.com
nebula
2026
ghostlock
cloud
machine
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
AI Security / VulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tue...
2026-7-8 05:33:12 | 阅读: 49 |
收藏
|
The Hacker News - thehackernews.com
2026
langflow
php
security
55255
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
Malware / Mobile SecurityA new Android malware operation called RedWing is being rented out on Tel...
2026-7-7 17:10:15 | 阅读: 42 |
收藏
|
The Hacker News - thehackernews.com
redwing
buyer
victim
installs
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code B...
2026-7-7 16:37:33 | 阅读: 37 |
收藏
|
The Hacker News - thehackernews.com
attacker
dialogflow
varonis
cloud
playbooks
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lur...
2026-7-7 15:14:14 | 阅读: 36 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
phaas
bec
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's...
2026-7-7 14:4:50 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
github
repository
attacker
noma
gitlost
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retail...
2026-7-7 13:27:20 | 阅读: 32 |
收藏
|
The Hacker News - thehackernews.com
stokes
tied
prosecutors
scattered
spider
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
AI Security / VulnerabilityCybersecurity researchers have disclosed details of a now-patched criti...
2026-7-7 13:27:9 | 阅读: 33 |
收藏
|
The Hacker News - thehackernews.com
attacker
victim
security
sand
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
AI Security / Software Supply ChainSoftware supply chain security was hard enough. Then AI joined...
2026-7-7 11:30:0 | 阅读: 36 |
收藏
|
The Hacker News - thehackernews.com
security
software
agents
provenance
taught
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Email Security / VulnerabilityA suspected China-aligned threat activity cluster has been observed...
2026-7-7 09:10:51 | 阅读: 46 |
收藏
|
The Hacker News - thehackernews.com
roundcube
vshell
security
proofpoint
icecube
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found...
2026-7-7 06:40:47 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
v15
username
attacker
tenda
Previous
15
16
17
18
19
20
21
22
Next