unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
Network Security / Enterprise SecurityFor years, routing traffic through cloud proxies was good en...
2026-7-15 11:50:1 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
security
network
inspection
cloud
proxy
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Vulnerability / Enterprise SecuritySecurity researcher Chaotic Eclipse (aka Nightmare-Eclipse) has...
2026-7-15 11:7:7 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
2026
microsoft
security
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
Web Security / Supply Chain SecurityA single approved marketing tag can quietly load fourth-party...
2026-7-15 11:6:57 | 阅读: 10 |
收藏
|
The Hacker News - thehackernews.com
security
approval
gap
approved
taboola
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root,...
2026-7-15 10:55:22 | 阅读: 9 |
收藏
|
The Hacker News - thehackernews.com
mindgard
windows
cymulate
repository
firm
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-st...
2026-7-15 09:16:13 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
payload
miasma
ipfs
asyncapi
stage
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Vulnerability / Enterprise SecuritySonicWall has warned of active exploitation of two zero-day vul...
2026-7-15 05:30:21 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
appliances
hotfix
2026
security
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that...
2026-7-14 20:25:47 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
microsoft
2026
exploited
remote
bypass
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Enterprise Security / VulnerabilitySAP has rolled out updates to address multiple vulnerabilities...
2026-7-14 18:17:57 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
client
2026
attacker
security
cloud
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome...
2026-7-14 17:27:23 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
claude
anthropic
manifold
forged
claudebleed
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (R...
2026-7-14 16:52:37 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
security
labubarat
blackpoint
nvidia
remote
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Vulnerability / Network SecurityCybersecurity researchers have disclosed details of two access con...
2026-7-14 13:48:7 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
broker
client
rabbitmq
network
attacker
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Int...
2026-7-14 12:46:18 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
shim
loader
microsoft
bootloaders
firmware
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extension...
2026-7-14 11:55:0 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
wallets
2026
makers
studied
calgary
How Pentera Turns AI Security Workflows into Validation Engines
AI security agents are starting to influence real security decisions. They summarize findings, prio...
2026-7-14 11:30:0 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
security
pentera
workflows
validated
exposure
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Cloud Security / Identity SecurityAt least two distinct threat actors are weaponizing a novel evas...
2026-7-14 11:21:35 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
client
spoofed
unk
entra
proofpoint
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, t...
2026-7-14 09:2:48 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
xai
grok
tracked
machine
cereblab
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individua...
2026-7-14 08:2:33 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
ransomware
russia
poorly
sanctions
security
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a di...
2026-7-14 07:8:36 | 阅读: 12 |
收藏
|
The Hacker News - thehackernews.com
jfrog
proxy
wisp
loader
proxies
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year...
2026-7-14 06:19:24 | 阅读: 25 |
收藏
|
The Hacker News - thehackernews.com
salesforce
microsoft
attackers
klue
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Endpoint Security / CybercrimeCybersecurity researchers have flagged a new macOS information steal...
2026-7-13 17:36:12 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
analysis
notarized
keychain
security
Previous
3
4
5
6
7
8
9
10
Next