unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unk...
2026-7-23 18:36:8 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
proofpoint
zimbra
payload
ta488
seqrite
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week's trouble came dressed as something useful.A package stole data. A fake extension...
2026-7-23 15:2:7 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
malicious
claude
security
attacker
payload
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowor...
2026-7-23 13:27:59 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
cowork
pedit
accomplish
claude
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talo...
2026-7-23 13:11:9 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
msarat
talos
chrome
headless
twilio
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Malware / Threat IntelligenceAn exposed Alibaba Cloud server has revealed a China-nexus operation...
2026-7-23 12:20:23 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
claude
loader
ib
2026
payload
How Synthetic Identity Fraud is Coming for Machine Identities
Most people understand identity theft as an attacker stealing a real person's sensitive informatio...
2026-7-23 11:45:0 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
fabricated
identities
machine
attacker
nhi
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised Git...
2026-7-23 11:28:54 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
github
malicious
srilankan
developer
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Authentication / Data ProtectionGoogle on Thursday announced a new way for users to sign-in to the...
2026-7-23 10:0:0 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
selfie
giant
gestures
facial
prompted
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unpri...
2026-7-23 08:4:35 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
xfs
reflink
qualys
rhel
2026
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Vulnerability / Network SecurityCheck Point has released security updates to address multiple vuln...
2026-7-23 06:34:36 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
security
2026
attacker
r80
privileges
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severi...
2026-7-22 18:37:42 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
github
security
hackerone
rewards
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerab...
2026-7-22 18:7:16 | 阅读: 19 |
收藏
|
The Hacker News - thehackernews.com
snap
confine
attacker
snapd
qualys
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Vulnerability / Browser SecurityCybersecurity researchers have disclosed details of a now-patche...
2026-7-22 15:1:21 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
attacker
rendered
victim
guardio
security
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Vulnerability / Web SecurityA high-severity security flaw impacting open-source developer platform...
2026-7-22 12:36:36 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
2026
security
windmill
superadmin
vulncheck
The Fastest Path to AI Adoption Runs Through Security
Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners...
2026-7-22 11:58:0 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
security
governance
approved
workaround
leaders
Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attacke...
2026-7-22 11:25:35 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
network
security
ndr
operational
telemetry
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
Law Enforcement / CybercrimeGerman and US law enforcement have taken down the core infrastructur...
2026-7-22 06:38:45 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
microsoft
bka
kratos
phishing
php
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Supply Chain Attack / MalwareCybersecurity researchers have discovered a NuGet typosquat that's un...
2026-7-22 06:0:6 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
digitain
rigging
crash
newtonsoft
nuget
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agen...
2026-7-22 04:57:52 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
manifold
attacker
reviewer
microsoft
wiki
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
AI Security / Cloud SecurityOpenAI on Tuesday said a combination of its artificial intelligence (A...
2026-7-22 04:18:33 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
openai
hugging
evaluation
security
software
Previous
-29
-28
-27
-26
-25
-24
-23
-22
Next