unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source ag...
2026-7-29 15:39:30 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
ruflo
mcp
network
memory
attacker
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Vulnerability / Enterprise SecurityBroadcom has released security updates to address multiple secu...
2026-7-29 15:31:15 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
esx
cloud
2026
vsphere
vcenter
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
Critical Infrastructure / Threat IntelligenceA coordinated cyberattack targeted operational techn...
2026-7-29 13:48:36 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
mnit
water
minnesota
operational
coordinated
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves crea...
2026-7-29 13:42:57 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
fraudulent
f6
victim
attackers
Mythos Asks the Right Question. It Doesn't Answer It.
AI is compressing exploit timelines. The real question isn't whether your vulnerability management...
2026-7-29 12:15:0 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
security
mythos
playbook
asset
prioritize
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Vulnerability / Browser SecurityNebula Security says a patched Firefox JIT flaw could be triggered...
2026-7-29 11:57:0 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
nebula
2026
zou
151
mozilla
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
Most organizations have incident response plans, security tools, and technical teams in place. Yet...
2026-7-29 11:13:10 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
readiness
cloud
operational
security
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
Cybercrime / Law EnforcementThe Federal Security Service of the Russian Federation (FSB) on Wedn...
2026-7-29 11:0:0 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
durov
men
terrorist
citizens
ukrainian
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Vulnerability / Enterprise SecurityCybersecurity researchers have shared additional technical deta...
2026-7-29 08:58:27 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
dn
remote
attacker
security
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A...
2026-7-29 07:47:19 | 阅读: 32 |
收藏
|
The Hacker News - thehackernews.com
gitea
repository
security
attacker
bare
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Mobile Security / Threat IntelligenceSource code for the Flying Eagle Android remote access trojan...
2026-7-29 07:7:23 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
flying
eagle
dragon
hunt
night
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed eva...
2026-7-29 06:45:2 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
hugging
evaluation
openai
security
artifactory
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Beta release versions of two npm packages in the @joyfill namespace have been compromised to delive...
2026-7-29 04:20:57 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
detached
blockchain
aptos
payload
bsc
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-2...
2026-7-28 18:59:7 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
hawk
anthropic
lattice
mythos
seven
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Linux / Endpoint SecurityA new Mirai-derived botnet called Tengu can use a compromised Linux devic...
2026-7-28 15:1:33 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
nozomi
tengu
urlhaus
c2
apk
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management...
2026-7-28 14:41:36 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
bmc
ipmi
remote
passwords
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Vulnerability / Artificial IntelligenceJFrog has confirmed that OpenAI models exploited a zero-day...
2026-7-28 13:33:47 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
openai
jfrog
artifactory
hugging
evaluation
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of re...
2026-7-28 12:56:14 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
openwrt
luci
2026
dhcpv6
odhcpd
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Malware / Cyber EspionageThe Iranian state-backed hacking group tracked as Nimbus Manticore (aka...
2026-7-28 11:55:20 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
bridgehead
arcbridge
tunneling
nightledger
windows
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Vulnerability / Enterprise SecurityJetBrains is urging customers of on-premise versions of TeamCit...
2026-7-28 08:11:22 | 阅读: 53 |
收藏
|
The Hacker News - thehackernews.com
teamcity
security
jetbrains
2026
63077
Previous
6
7
8
9
10
11
12
13
Next