unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims...
2026-7-25 10:14:21 | 阅读: 3 |
收藏
|
The Hacker News - thehackernews.com
phishing
insurance
attackers
victim
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Vulnerability / RansomwareThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful S...
2026-7-25 10:14:3 | 阅读: 4 |
收藏
|
The Hacker News - thehackernews.com
cl0p
ptc
extortion
security
remote
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web p...
2026-7-25 09:53:41 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
devman
affiliate
affiliates
victim
huntress
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Vulnerability / Application SecuritySecurity researchers depthfirst published working exploit code...
2026-7-25 08:34:15 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
gitlab
oj
security
depthfirst
memory
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom an...
2026-7-24 15:12:35 | 阅读: 5 |
收藏
|
The Hacker News - thehackernews.com
victim
jumpsec
clickfix
meeting
chrome
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Vulnerability / Enterprise SecurityResearchers H0j3n and Aniq Fakhrul published a working exploit...
2026-7-24 14:15:21 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
microsoft
machine
windows
chase
enrollment
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Age...
2026-7-24 11:53:55 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
victim
attacker
chatgpt
agents
2026
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Vulnerability / Web SecurityA crafted SVG submitted to Bing's image search ran commands as NT AUTH...
2026-7-24 11:45:17 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
xbow
bing
microsoft
imagemagick
delegate
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and final...
2026-7-24 11:30:0 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
agents
security
agentic
cloud
plane
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it...
2026-7-24 10:15:29 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
ministry
hunt
2026
hermes
recovered
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
Threat Intelligence / Browser SecurityThe threat actors behind the Golden Chickens malware-as-a-se...
2026-7-24 10:9:24 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
tinyegg
maas
families
chickens
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Web Security / VulnerabilityEight security flaws in NodeBB went public on Wednesday, along with th...
2026-7-24 07:41:6 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
nodebb
eight
federation
security
aikido
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Vulnerability / Database SecurityRedis shipped seven security releases on July 23 after researcher...
2026-7-24 06:58:27 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
tdigest
redisbloom
memory
nack
rdb
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involve...
2026-7-24 06:50:57 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
webmail
ta458
malicious
winrar
phishing
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unk...
2026-7-23 18:36:8 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
proofpoint
zimbra
payload
ta488
seqrite
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week's trouble came dressed as something useful.A package stole data. A fake extension...
2026-7-23 15:2:7 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
malicious
claude
security
attacker
payload
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowor...
2026-7-23 13:27:59 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
cowork
pedit
accomplish
claude
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talo...
2026-7-23 13:11:9 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
msarat
talos
chrome
headless
twilio
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Malware / Threat IntelligenceAn exposed Alibaba Cloud server has revealed a China-nexus operation...
2026-7-23 12:20:23 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
claude
loader
ib
2026
payload
How Synthetic Identity Fraud is Coming for Machine Identities
Most people understand identity theft as an attacker stealing a real person's sensitive informatio...
2026-7-23 11:45:0 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
fabricated
identities
machine
attacker
nhi
Previous
-71
-70
-69
-68
-67
-66
-65
-64
Next