unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at...
2026-8-6 08:5:22 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
firmware
zbtlink
kworker
client
rctl
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August...
2026-8-6 07:19:54 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
cartel
silnikau
charged
virginia
prosecutors
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Vulnerability / Enterprise SecurityA newly patched security flaw impacting on-premise versions of...
2026-8-6 06:51:43 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
teamcity
jetbrains
exploited
2026
security
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Cybercrime / Law EnforcementConnor Riley Moucka pleaded guilty in Seattle federal court on Wednesd...
2026-8-6 06:4:30 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
snowflake
moucka
mandiant
prosecutors
victim
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors befor...
2026-8-5 18:44:31 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
microsoft
gate
fingerprint
amos
download
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
Cybercrime / Artificial IntelligenceOpenAI said it disrupted a Cambodia-based scam operation that...
2026-8-5 18:33:47 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
openai
network
personas
gambling
investment
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
AI Security / Threat IntelligenceCybersecurity researchers have discovered more than half-a-dozen...
2026-8-5 15:36:3 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
claude
anthropic
poison
opus
okta
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a devel...
2026-8-5 15:14:5 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
paperclip
attacker
416
v2026
2026
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terrafo...
2026-8-5 14:27:30 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
2026
django
hashicorp
veeam
mcp
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Cyber Espionage / Threat IntelligenceCybersecurity researchers have flagged an evolution of the Et...
2026-8-5 13:41:27 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
c2
etherhiding
calldata
fluid
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a p...
2026-8-5 11:43:27 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
ovs
manizada
attacker
ordinary
vswitch
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.The phishing kit...
2026-8-5 11:43:19 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
kali365
microsoft
phishing
tier
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hos...
2026-8-5 11:4:23 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
gitea
2026
markup
repository
anonymous
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commi...
2026-8-5 10:35:29 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
n8n
workflows
github
attacker
gitguardian
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate dev...
2026-8-5 09:23:3 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
vscode
security
developer
repository
machine
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged...
2026-8-5 07:53:50 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
aisi
github
openai
agents
mythos
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Vulnerability / Patch ManagementThe U.S. Cybersecurity and Infrastructure Security Agency (CISA),...
2026-8-5 07:40:39 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
2026
autonomous
langflow
exploited
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain a...
2026-8-5 05:47:19 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
firebase
fdmtp
compat
quickfox
malicious
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest cri...
2026-8-4 17:27:39 | 阅读: 29 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
greatness
phaas
ringcentral
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in
[email protected]
spread beyond the Keyv and Cacheab...
2026-8-4 13:30:23 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
safedep
keyv
github
mjs
claude
Previous
3
4
5
6
7
8
9
10
Next