unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom an...
2026-7-24 15:12:35 | 阅读: 1 |
收藏
|
The Hacker News - thehackernews.com
victim
jumpsec
clickfix
meeting
chrome
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Vulnerability / Enterprise SecurityResearchers H0j3n and Aniq Fakhrul published a working exploit...
2026-7-24 14:15:21 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
microsoft
machine
windows
chase
enrollment
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Age...
2026-7-24 11:53:55 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
victim
attacker
chatgpt
agents
2026
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Vulnerability / Web SecurityA crafted SVG submitted to Bing's image search ran commands as NT AUTH...
2026-7-24 11:45:17 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
xbow
bing
microsoft
imagemagick
delegate
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and final...
2026-7-24 11:30:0 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
agents
security
agentic
cloud
plane
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it...
2026-7-24 10:15:29 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
ministry
hunt
2026
hermes
recovered
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
Threat Intelligence / Browser SecurityThe threat actors behind the Golden Chickens malware-as-a-se...
2026-7-24 10:9:24 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
tinyegg
maas
families
chickens
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Web Security / VulnerabilityEight security flaws in NodeBB went public on Wednesday, along with th...
2026-7-24 07:41:6 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
nodebb
eight
federation
security
aikido
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Vulnerability / Database SecurityRedis shipped seven security releases on July 23 after researcher...
2026-7-24 06:58:27 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
tdigest
redisbloom
memory
nack
rdb
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involve...
2026-7-24 06:50:57 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
webmail
ta458
malicious
winrar
phishing
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unk...
2026-7-23 18:36:8 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
proofpoint
zimbra
payload
ta488
seqrite
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week's trouble came dressed as something useful.A package stole data. A fake extension...
2026-7-23 15:2:7 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
malicious
claude
security
attacker
payload
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowor...
2026-7-23 13:27:59 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
cowork
pedit
accomplish
claude
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talo...
2026-7-23 13:11:9 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
msarat
talos
chrome
headless
twilio
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Malware / Threat IntelligenceAn exposed Alibaba Cloud server has revealed a China-nexus operation...
2026-7-23 12:20:23 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
claude
loader
ib
2026
payload
How Synthetic Identity Fraud is Coming for Machine Identities
Most people understand identity theft as an attacker stealing a real person's sensitive informatio...
2026-7-23 11:45:0 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
fabricated
identities
machine
attacker
nhi
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised Git...
2026-7-23 11:28:54 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
github
malicious
srilankan
developer
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Authentication / Data ProtectionGoogle on Thursday announced a new way for users to sign-in to the...
2026-7-23 10:0:0 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
selfie
giant
gestures
facial
prompted
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unpri...
2026-7-23 08:4:35 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
xfs
reflink
qualys
rhel
2026
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Vulnerability / Network SecurityCheck Point has released security updates to address multiple vuln...
2026-7-23 06:34:36 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
security
2026
attacker
r80
privileges
Previous
-53
-52
-51
-50
-49
-48
-47
-46
Next