unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Vulnerability / Cyber AttacksAttackers have begun to exploit two critical vulnerabilities in WordP...
2026-7-21 08:59:30 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
wordpress
remote
2026
security
attackers
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI...
2026-7-21 07:34:32 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
encforge
langflow
sysdig
weights
indexes
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Vulnerability / Artificial IntelligenceThreat actors are now exploiting a recently disclosed criti...
2026-7-21 06:29:26 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
servicenow
security
zurich
defused
yokohama
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of whic...
2026-7-20 18:23:3 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
mcp
malicious
fakegit
smartloader
island
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,...
2026-7-20 17:29:50 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
rapid7
webdav
windows
attacker
lure
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its comman...
2026-7-20 14:33:43 | 阅读: 6 |
收藏
|
The Hacker News - thehackernews.com
ib
microsoft
client
mailbox
hollowgraph
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execut...
2026-7-20 13:32:26 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
2026
security
ransomware
malicious
attacker
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
IoT Security / Cyber EspionageAt least one Russian intelligence service is systematically hijackin...
2026-7-20 12:13:39 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
cameras
censys
military
exploited
ukraine
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. Ho...
2026-7-20 11:30:0 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
exposure
security
mythos
proactive
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Vulnerability / Endpoint SecurityOpening a crafted XZ archive in 7-Zip could let an attacker run c...
2026-7-20 09:10:56 | 阅读: 11 |
收藏
|
The Hacker News - thehackernews.com
xz
zdi
attacker
2026
overflow
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations t...
2026-7-20 09:7:11 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
gemini
skill
bandcampro
migration
assisted
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
AI Security / VulnerabilityIn an ironic twist, open-source artificial intelligence (AI) platform H...
2026-7-20 05:27:26 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
attacker
hugging
guardrails
clusters
autonomous
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targ...
2026-7-20 05:15:39 | 阅读: 18 |
收藏
|
The Hacker News - thehackernews.com
rubygems
malicious
fastlane
testlab
firebase
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger...
2026-7-19 20:42:49 | 阅读: 8 |
收藏
|
The Hacker News - thehackernews.com
shaw
2026
captures
42533
overflow
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy...
2026-7-19 13:30:55 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
clickfix
captcha
apk
stealer
powershell
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
Vulnerability / Network SecurityA previously undocumented threat actor has been attributed to the...
2026-7-19 13:18:56 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
2026
appliance
sma
appliances
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Vulnerability / Web SecurityAn anonymous HTTP request can run code on a WordPress site. The bug is...
2026-7-17 21:20:10 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
wordpress
wp
anonymous
searchlight
php
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message t...
2026-7-17 20:20:53 | 阅读: 7 |
收藏
|
The Hacker News - thehackernews.com
memory
okta
hollowbyte
changelog
attacker
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Software Supply Chain / MalwareCybersecurity researchers have discovered a cluster of seven malici...
2026-7-17 18:54:51 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
vite
blockchain
payload
malicious
tron
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's...
2026-7-17 17:12:23 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
mcp
xlab
nadmesh
cloud
comfyui
Previous
-1
0
1
2
3
4
5
6
Next