unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors have been observed attempting to exploit a recently patched critical security flaw in...
2026-7-6 16:28:59 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
proxy
gitea
reverse
security
sysdig
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a res...
2026-7-6 13:1:14 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
2026
phishing
microsoft
security
attacker
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors...
2026-7-6 11:30:2 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
exaforce
exabot
triage
agents
verdict
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax p...
2026-7-6 10:58:16 | 阅读: 28 |
收藏
|
The Hacker News - thehackernews.com
tax
payload
windows
analysis
phishing
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Cyber Espionage / Endpoint SecurityResearchers at Shandong University have shown a fast new way to...
2026-7-6 08:50:54 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
trojpix
gap
hardware
tempest
machine
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRA...
2026-7-6 08:13:33 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
payload
quimarat
windows
quima
c2
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a m...
2026-7-6 07:27:50 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
opera
gx
victim
letter
crx
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simpl...
2026-7-6 06:33:56 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
skill
scanners
agents
malicious
marketplace
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to...
2026-7-4 12:47:53 | 阅读: 32 |
收藏
|
The Hacker News - thehackernews.com
kairos
county
ransomware
krishnan
victim
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publ...
2026-7-4 11:17:24 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
malicious
github
contagious
mjs
2026
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that...
2026-7-3 20:19:31 | 阅读: 31 |
收藏
|
The Hacker News - thehackernews.com
fatfs
runzero
2026
memory
firmware
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no...
2026-7-3 19:40:1 | 阅读: 37 |
收藏
|
The Hacker News - thehackernews.com
epoll
2026
chung
lands
memory
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework cod...
2026-7-3 18:55:24 | 阅读: 29 |
收藏
|
The Hacker News - thehackernews.com
llm
avalon
ransomware
windows
stage
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages th...
2026-7-3 16:7:15 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
rollup
polyfill
ssh
payload
cloud
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks...
2026-7-3 13:36:33 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
stealer
c2
likho
armored
remote
European Parliament Member Investigating Spyware Was Hacked With Pegasus
A new report from the Citizen Lab has revealed that former Member of the European Parliament Stel...
2026-7-3 11:5:43 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
spyware
citizen
committee
kouloglou
pega
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that empl...
2026-7-3 08:3:37 | 阅读: 24 |
收藏
|
The Hacker News - thehackernews.com
maccy
stealer
payload
applescript
victim
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
Google has significantly degraded NetNut, one of the biggest networks that turns home devices into...
2026-7-2 18:54:6 | 阅读: 27 |
收藏
|
The Hacker News - thehackernews.com
netnut
network
proxy
popa
synthient
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Cit...
2026-7-2 18:30:33 | 阅读: 29 |
收藏
|
The Hacker News - thehackernews.com
ransomware
vect
teampcp
anubis
partnership
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week’s security news is mostly about weak spots.Browsers, bots, sandboxes, AI systems, and emai...
2026-7-2 15:24:18 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
security
phishing
malicious
bots
ransomware
Previous
7
8
9
10
11
12
13
14
Next