unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 mil...
2026-7-13 17:17:24 | 阅读: 25 |
收藏
|
The Hacker News - thehackernews.com
collector
modheader
chrome
olt
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. Th...
2026-7-13 15:5:57 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
2026
security
windows
malicious
remote
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite w...
2026-7-13 13:49:48 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
memory
openclaw
memghost
agents
attacker
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code...
2026-7-13 13:3:33 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
forg365
zerobac
victim
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
Meta has filed a patent application for an AI that listens to your voice throughout the day, works...
2026-7-13 11:54:46 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
patent
filing
mood
emotional
coach
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his securi...
2026-7-13 11:37:5 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
brain
kahneman
judgment
claude
genuinely
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vi...
2026-7-13 11:2:33 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
attacker
cloud
huntress
sygnia
staging
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a...
2026-7-13 07:30:0 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
microsoft
phishing
evilginx
victim
saroula01
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
Vulnerability / Web SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has a...
2026-7-13 05:36:2 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
2026
joomla
icagenda
wordpress
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infost...
2026-7-11 17:59:26 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
windows
payload
jscrambler
stealer
pulled
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against seve...
2026-7-11 17:49:31 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
police
plugx
shadowpad
pakistani
balochistan
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Vulnerability / Email SecurityZimbra is urging customers to apply updates to address a critical se...
2026-7-11 06:45:55 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
zimbra
exploited
malicious
security
client
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Software Supply Chain / MalwareUnknown threat actors compromised the Injective Labs SDK project's...
2026-7-10 17:29:28 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
malicious
repository
github
mnemonic
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Enterprise Security / Security IncidentProgress Software has told ShareFile customers to shut down...
2026-7-10 16:30:0 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
sharefile
security
exploited
cloud
citrix
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program...
2026-7-10 15:57:14 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
2026
brly
binarly
attacker
bootloader
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed a...
2026-7-10 14:51:49 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
tangem
chip
donjon
laser
trezor
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
AI Security / VulnerabilityDetails have emerged about three now-patched security flaws in the Open...
2026-7-10 14:19:50 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
openclaw
ghsa
security
m3mc
575v
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Malware / Enterprise SecurityThe China-linked cybercrime group known as Silver Fox has been attrib...
2026-7-10 13:15:23 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
qianxin
trojan
modbeacon
counterfeit
c2
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
Vulnerability / Server SecurityA single wrong variable on one line in XQUIC, Alibaba's QUIC and HT...
2026-7-10 11:47:43 | 阅读: 25 |
收藏
|
The Hacker News - thehackernews.com
qpack
foxio
xquic
alibaba
xring
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests ot...
2026-7-10 11:39:40 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
asset
lumen
exposure
krahn
axonius
Previous
4
5
6
7
8
9
10
11
Next