unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit
TL;DR CVE-2026-11374 is a critical, unauthenticated account takeover that hands an attacker any...
2026-7-21 15:0:0 | 阅读: 0 |
收藏
|
bishopfox.com - bishopfox.com
sso
attacker
victim
replay
ad360
Using MCP Agents for Penetration Testing
TL;DR:Agent harnesses cut time-to-finding from d...
2026-7-17 13:0:0 | 阅读: 8 |
收藏
|
bishopfox.com - bishopfox.com
llm
cloud
mcp
destructive
security
Introducing snowpick: Testing ServiceNow for Public Data Exposure
TL;DRServiceNow portals can expose backend recor...
2026-7-14 13:0:0 | 阅读: 0 |
收藏
|
bishopfox.com - bishopfox.com
servicenow
widget
snowpick
widgets
exposure
Cracking Firmware with Claude: Senior-Level Skill, Junior-Level Autonomy
TL;DRWe gave Claude Code, running Sonnet 4.5, an encrypted SonicWall firmware image and a copy...
2026-7-8 13:0:0 | 阅读: 0 |
收藏
|
bishopfox.com - bishopfox.com
claude
firmware
encryption
senior
unseal
On Favicons: From Browser Icons to Attack Surface Intelligence
TL;DRUsed an AI-assisted pipeline to hash, corre...
2026-7-2 13:0:0 | 阅读: 0 |
收藏
|
bishopfox.com - bishopfox.com
favicon
favicons
cpe
honeypot
software
AI Finds Vulnerabilities. Security Experts Find Impact.
TL;DR AI accelerates security work, but it doesn...
2026-6-24 13:0:0 | 阅读: 0 |
收藏
|
bishopfox.com - bishopfox.com
security
ssrf
bypass
invitation
burp
A Crash, Not a Shell: SolarWinds Serv-U CVE-2026-28318
TL;DR:SolarWinds Serv-...
2026-6-16 13:0:0 | 阅读: 16 |
收藏
|
bishopfox.com - bishopfox.com
memory
serv
crash
hf1
A Crash, Not a Shell: SolarWinds Serve-U CVE-2026-28318
TL;DR:SolarWinds Serv-...
2026-6-16 13:0:0 | 阅读: 17 |
收藏
|
bishopfox.com - bishopfox.com
memory
serv
crash
2026
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
TL;DRUbiquiti’s Security Advisory Bulletin 064 c...
2026-6-5 13:0:0 | 阅读: 34 |
收藏
|
bishopfox.com - bishopfox.com
unifi
2026
network
attacker
bypass
Otto Support - Testing MCP Servers
TL;DR: This final entry runs a modified version...
2026-6-3 13:0:0 | 阅读: 22 |
收藏
|
bishopfox.com - bishopfox.com
mcp
otto
nmap
nuclei
inspector
Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557
TL;DR: CVE-2026-22557 is an unauthenticated path...
2026-5-29 13:0:0 | 阅读: 34 |
收藏
|
bishopfox.com - bishopfox.com
backup
network
unifi
attacker
2026
Sparkplug B Protocol Fuzzing with AI Assistance
TL;DR: The problem: Sparkplug B is the dominant MQTT-based protocol in industrial control and S...
2026-5-26 13:0:0 | 阅读: 16 |
收藏
|
bishopfox.com - bishopfox.com
sparkplug
mqtt
fuzzer
metric
broker
Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypass
TL;DR: CVE-2026-0265 is a pre-authentication JSON Web Token (JWT) signature bypass in PAN-OS an...
2026-5-22 13:0:0 | 阅读: 12 |
收藏
|
bishopfox.com - bishopfox.com
cas
pan
verdict
CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi
TL;DR Bishop Fox confirmed CVE-2026-27886, a cri...
2026-5-22 07:0:0 | 阅读: 12 |
收藏
|
bishopfox.com - bishopfox.com
strapi
attacker
pagination
allowlist
populate
Otto Support - Logging and Visibility in MCP Servers
TL;DR: otto-support ships with two log files sid...
2026-5-14 13:0:0 | 阅读: 26 |
收藏
|
bishopfox.com - bishopfox.com
mcp
2026
security
agents
otto
Otto-Support: Supply Chain Risks in MCP Servers
TL;DR: otto-support's selfpwn module quantifies exactly what a hostile MCP server can read from...
2026-5-13 13:0:0 | 阅读: 24 |
收藏
|
bishopfox.com - bishopfox.com
mcp
otto
selfpwn
malicious
postmark
Otto Support - The Confused Deputy
TL;DR: A confused deputy attack lands when an agent reads attacker-controlled content, like a t...
2026-5-8 13:0:0 | 阅读: 25 |
收藏
|
bishopfox.com - bishopfox.com
attacker
confused
deputy
copilot
otto
Otto Support - SSRF and Token Passthrough with MCP
TL;DR: Server-side request forgery (SSRF) and token passthrough are old web vulnerabilities in...
2026-5-7 13:0:0 | 阅读: 24 |
收藏
|
bishopfox.com - bishopfox.com
mcp
ssrf
passthrough
atlassian
2026
CVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM Proxy
TL;DR Bishop Fox researchers reproduced and confirmed CVE-2026-42208, a critical pre-authentication...
2026-5-6 13:0:0 | 阅读: 32 |
收藏
|
bishopfox.com - bishopfox.com
litellm
proxy
bearer
database
attacker
Otto Support - Excessive Agency and Tool Privileges
TL;DR: AI agents handed more tools than the task requires have already wiped production environ...
2026-5-6 13:0:0 | 阅读: 20 |
收藏
|
bishopfox.com - bishopfox.com
agents
excessive
2026
mcp
Previous
-72
-71
-70
-69
-68
-67
-66
-65
Next