unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Int...
2026-7-14 12:46:18 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
shim
loader
microsoft
bootloaders
firmware
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extension...
2026-7-14 11:55:0 | 阅读: 21 |
收藏
|
The Hacker News - thehackernews.com
wallets
2026
makers
studied
calgary
How Pentera Turns AI Security Workflows into Validation Engines
AI security agents are starting to influence real security decisions. They summarize findings, prio...
2026-7-14 11:30:0 | 阅读: 16 |
收藏
|
The Hacker News - thehackernews.com
security
pentera
workflows
validated
exposure
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Cloud Security / Identity SecurityAt least two distinct threat actors are weaponizing a novel evas...
2026-7-14 11:21:35 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
client
spoofed
unk
entra
proofpoint
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, t...
2026-7-14 09:2:48 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
xai
grok
tracked
machine
cereblab
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individua...
2026-7-14 08:2:33 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
ransomware
russia
poorly
sanctions
security
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a di...
2026-7-14 07:8:36 | 阅读: 13 |
收藏
|
The Hacker News - thehackernews.com
jfrog
proxy
wisp
loader
proxies
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year...
2026-7-14 06:19:24 | 阅读: 25 |
收藏
|
The Hacker News - thehackernews.com
salesforce
microsoft
attackers
klue
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Endpoint Security / CybercrimeCybersecurity researchers have flagged a new macOS information steal...
2026-7-13 17:36:12 | 阅读: 22 |
收藏
|
The Hacker News - thehackernews.com
analysis
notarized
keychain
security
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 mil...
2026-7-13 17:17:24 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
collector
modheader
chrome
olt
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. Th...
2026-7-13 15:5:57 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
2026
security
windows
malicious
remote
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite w...
2026-7-13 13:49:48 | 阅读: 20 |
收藏
|
The Hacker News - thehackernews.com
memory
openclaw
memghost
agents
attacker
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code...
2026-7-13 13:3:33 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
phishing
microsoft
forg365
zerobac
victim
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
Meta has filed a patent application for an AI that listens to your voice throughout the day, works...
2026-7-13 11:54:46 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
patent
filing
mood
emotional
coach
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his securi...
2026-7-13 11:37:5 | 阅读: 15 |
收藏
|
The Hacker News - thehackernews.com
brain
kahneman
judgment
claude
genuinely
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vi...
2026-7-13 11:2:33 | 阅读: 14 |
收藏
|
The Hacker News - thehackernews.com
attacker
cloud
huntress
sygnia
staging
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a...
2026-7-13 07:30:0 | 阅读: 25 |
收藏
|
The Hacker News - thehackernews.com
microsoft
phishing
evilginx
victim
saroula01
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
Vulnerability / Web SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has a...
2026-7-13 05:36:2 | 阅读: 17 |
收藏
|
The Hacker News - thehackernews.com
2026
joomla
icagenda
wordpress
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infost...
2026-7-11 17:59:26 | 阅读: 26 |
收藏
|
The Hacker News - thehackernews.com
windows
payload
jscrambler
stealer
pulled
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against seve...
2026-7-11 17:49:31 | 阅读: 23 |
收藏
|
The Hacker News - thehackernews.com
police
plugx
shadowpad
pakistani
balochistan
Previous
4
5
6
7
8
9
10
11
Next