unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Vulnerability / Enterprise SecurityResearchers H0j3n and Aniq Fakhrul published a working exploit...
2026-7-24 14:15:21 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
microsoft
machine
windows
chase
enrollment
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Age...
2026-7-24 11:53:55 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
victim
attacker
chatgpt
agents
2026
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Vulnerability / Web SecurityA crafted SVG submitted to Bing's image search ran commands as NT AUTH...
2026-7-24 11:45:17 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
xbow
bing
microsoft
imagemagick
delegate
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and final...
2026-7-24 11:30:0 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
agents
security
agentic
cloud
plane
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it...
2026-7-24 10:15:29 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
ministry
hunt
2026
hermes
recovered
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
Threat Intelligence / Browser SecurityThe threat actors behind the Golden Chickens malware-as-a-se...
2026-7-24 10:9:24 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
tinyegg
maas
families
chickens
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Web Security / VulnerabilityEight security flaws in NodeBB went public on Wednesday, along with th...
2026-7-24 07:41:6 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
nodebb
eight
federation
security
aikido
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Vulnerability / Database SecurityRedis shipped seven security releases on July 23 after researcher...
2026-7-24 06:58:27 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
tdigest
redisbloom
memory
nack
rdb
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involve...
2026-7-24 06:50:57 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
webmail
ta458
malicious
winrar
phishing
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unk...
2026-7-23 18:36:8 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
proofpoint
zimbra
payload
ta488
seqrite
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week's trouble came dressed as something useful.A package stole data. A fake extension...
2026-7-23 15:2:7 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
malicious
claude
security
attacker
payload
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowor...
2026-7-23 13:27:59 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
cowork
pedit
accomplish
claude
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talo...
2026-7-23 13:11:9 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
msarat
talos
chrome
headless
twilio
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Malware / Threat IntelligenceAn exposed Alibaba Cloud server has revealed a China-nexus operation...
2026-7-23 12:20:23 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
claude
loader
ib
2026
payload
How Synthetic Identity Fraud is Coming for Machine Identities
Most people understand identity theft as an attacker stealing a real person's sensitive informatio...
2026-7-23 11:45:0 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
fabricated
identities
machine
attacker
nhi
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised Git...
2026-7-23 11:28:54 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
github
malicious
srilankan
developer
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Authentication / Data ProtectionGoogle on Thursday announced a new way for users to sign-in to the...
2026-7-23 10:0:0 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
selfie
giant
gestures
facial
prompted
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unpri...
2026-7-23 08:4:35 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
xfs
reflink
qualys
rhel
2026
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Vulnerability / Network SecurityCheck Point has released security updates to address multiple vuln...
2026-7-23 06:34:36 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
security
2026
attacker
r80
privileges
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severi...
2026-7-22 18:37:42 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
github
security
hackerone
rewards
Previous
-50
-49
-48
-47
-46
-45
-44
-43
Next