unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email...
2026-7-8 13:0:0 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
eviltokens
security
exposure
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment proces...
2026-7-8 12:52:15 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
windows
victim
security
clipboard
scmbanker
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the s...
2026-7-8 11:51:24 | 阅读: 25 |
收藏
|
The Hacker News - thehackernews.com
github
forge
ginesin
ecdsa
fetches
The Verification Step Is the New ATO Battleground in 2026
For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credential...
2026-7-8 11:30:0 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
ato
2026
attackers
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it any...
2026-7-8 11:21:7 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
harmful
copilot
answers
prompts
816
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
Malware / Network SecurityA Chinese threat actor tracked as UAT-7810 is actively refining its besp...
2026-7-8 09:4:33 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
uat
7810
network
orb
c2
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Vulnerability / Cloud SecurityResearchers at Nebula Security have disclosed GhostLock (CVE-2026-43...
2026-7-8 06:16:44 | 阅读: 42 |
收藏
|
The Hacker News - thehackernews.com
nebula
2026
ghostlock
cloud
machine
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
AI Security / VulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tue...
2026-7-8 05:33:12 | 阅读: 37 |
收藏
|
The Hacker News - thehackernews.com
2026
langflow
php
security
55255
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
Malware / Mobile SecurityA new Android malware operation called RedWing is being rented out on Tel...
2026-7-7 17:10:15 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
redwing
buyer
victim
installs
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code B...
2026-7-7 16:37:33 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
attacker
dialogflow
varonis
cloud
playbooks
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lur...
2026-7-7 15:14:14 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
phaas
bec
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's...
2026-7-7 14:4:50 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
github
repository
attacker
noma
gitlost
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retail...
2026-7-7 13:27:20 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
stokes
tied
prosecutors
scattered
spider
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
AI Security / VulnerabilityCybersecurity researchers have disclosed details of a now-patched criti...
2026-7-7 13:27:9 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
attacker
victim
security
sand
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
AI Security / Software Supply ChainSoftware supply chain security was hard enough. Then AI joined...
2026-7-7 11:30:0 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
security
software
agents
provenance
taught
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Email Security / VulnerabilityA suspected China-aligned threat activity cluster has been observed...
2026-7-7 09:10:51 | 阅读: 33 |
收藏
|
The Hacker News - thehackernews.com
roundcube
vshell
security
proofpoint
icecube
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found...
2026-7-7 06:40:47 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
v15
username
attacker
tenda
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
Vulnerability / Enterprise SecurityBeyondTrust has released updates to address two critical securi...
2026-7-7 05:16:51 | 阅读: 30 |
收藏
|
The Hacker News - thehackernews.com
remote
2026
beyondtrust
attacker
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has b...
2026-7-6 18:34:26 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
remote
cavern
c2
aot
software
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to cor...
2026-7-6 17:37:1 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
2026
shadow
machine
kim
Previous
6
7
8
9
10
11
12
13
Next