unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional servi...
2026-8-7 18:16:13 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
2026
phishing
extortion
unc6671
security
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Web Security / VulnerabilityWordPress has fixed a pre-authentication reflected cross-site scripti...
2026-8-7 12:56:23 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
wordpress
php
attacker
security
Growing Up The Hard Way
Open Source had a great childhood.For two decades it got to be a kid. It ran around barefoot, gav...
2026-8-7 11:55:26 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
maintainers
subset
maintainer
software
puppy
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Te...
2026-8-7 11:10:33 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
sctp
machine
neither
exposure
sctphantom
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active "widespread email-driven phishing camp...
2026-8-7 10:38:27 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
microsoft
phishing
wolf
arctic
payroll
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
Web Security / VulnerabilityPortSwigger says HTTP Terminator, an artificial intelligence (AI)-assi...
2026-8-7 10:9:54 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
kettle
rqp
terminator
portswigger
desync
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Network Security / VulnerabilitySecurity researcher Malcolm Stagg has disclosed a new attack class...
2026-8-7 09:32:57 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
windows
natjack
network
stagg
2026
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Endpoint Security / VulnerabilityEntra ID researcher Dirk-jan Mollema demonstrated that malware al...
2026-8-7 08:52:11 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
windows
mollema
microsoft
attacker
entra
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Artificial Intelligence / VulnerabilityA GitHub issue opened by an account with no repository priv...
2026-8-7 08:18:35 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
gemini
claude
codex
openai
repository
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Cybercrime / VulnerabilityA new analysis has uncovered that the threat actor tracked as TeamPCP ha...
2026-8-7 06:50:5 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
teampcp
operational
security
oligo
kubernetes
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Virtualization Security / LinuxZapscape, a new Linux kernel vulnerability, could allow an attacker...
2026-8-6 17:58:30 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
kim
mmu
shadow
2026
stale
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Network Security / VulnerabilityCisco has rolled out updates to address multiple critical securi...
2026-8-6 17:13:15 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
2026
improper
software
security
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor...
2026-8-6 16:17:13 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
zen
interrupt
interrupts
attacker
bulletin
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can h...
2026-8-6 15:24:31 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
security
2026
memory
malicious
remote
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
OT Security / VulnerabilityForescout found 22 internet-facing Rockwell Automation programmable log...
2026-8-6 12:16:58 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
forescout
rockwell
micrologix
1400
1100
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Vulnerability / BlockchainCoinspect has identified CryptoJS.lib.WordArray.random() as the weak ran...
2026-8-6 11:49:48 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
coinspect
bexo
phrase
phrases
blockchain
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Vulnerability / Network SecurityCybersecurity researchers have disclosed a security issue with App...
2026-8-6 11:33:8 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
webkit
proxy
webauthn
passkeys
security
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no...
2026-8-6 11:30:0 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
memory
security
poisoning
competitor
cheat
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Database Security / Endpoint SecurityAttackers broke into an organization's Oracle database throug...
2026-8-6 09:19:23 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
database
khunt
huntress
attackers
security
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untru...
2026-8-6 08:57:30 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
2026
harness
vercel
adk
opencode
Previous
2
3
4
5
6
7
8
9
Next