安全情报 Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices 📡 The Hacker News · 2026-07-03 Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million      
安全情报 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets 📡 The Hacker News · 2026-07-03 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million      
安全情报 📊 2026-07-21 漏洞情报日报 · 200 条 · 高危 104 每日漏洞情报汇总 · 2026-07-21 📊 2026-07-21 漏洞情报日报 📋 共 200 条 🔥 高危/严重 104 条 🐙 GitHub-Advisory 50 条 🔥20 🛡️ NVD-Latest 84 条 🔥84 ⚔️ Sploitus 66 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-59873 (Critical) - node-tar 解压拒绝服务: 影响所有使用 npm tar 库的 Node.js 应用。由于库未对解压数据总量设硬上限,攻击者可构造恶意压缩包,导致服务器磁盘空间与 CPU 资源耗尽。 * CVE-2026-63795 (CVSS 10.0) - Linux 内核 9p 文件系统漏洞:
安全情报 Vulhub PoC: CVE-2026-63030 - Add WordPress CVE-2026-63030 pre-auth RCE (wp2shell) environment (#791) * Add W 📡 Vulhub · 2026-07-18 Vulhub PoC: CVE-2026-63030 - Add WordPress CVE-2026-63030 pre-auth RCE (wp2shell) environment (#791) * Add W CVE-2026-63030CVE-2026-60137 Vulhub Docker 复现环境 CVE: CVE-2026-63030, CVE-2026-60137 Add WordPress CVE-2026-63030 pre-auth RCE (wp2shell) environment (#791) * Add WordPress CVE-2026-63030 pre-auth RCE (wp2shell) environment Chains the REST API batch route confusion (CVE-2026-63030) with the WP_Query
安全情报 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses 📡 The Hacker News · 2026-06-30 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million    
安全情报 Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters 📡 The Hacker News · 2026-07-01 Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million     
安全情报 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses 📡 The Hacker News · 2026-06-30 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million    
安全情报 Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data 📡 The Hacker News · 2026-06-30 Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million     
安全情报 📊 2026-07-20 漏洞情报日报 · 200 条 · 高危 96 每日漏洞情报汇总 · 2026-07-20 📊 2026-07-20 漏洞情报日报 📋 共 200 条 🔥 高危/严重 96 条 🐙 GitHub-Advisory 26 条 🔥12 🛡️ NVD-Latest 84 条 🔥84 ⚔️ Sploitus 90 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-16117 (CVSS 10.0) - Fastify HTTP代理: @fastify/http-proxy ≤11.5.0 因未正确处理URL编码的前缀路径,导致请求路由绕过,可被用于SSRF或访问内部资源。利用条件:攻击者能够发送特制HTTP请求到代理服务。 * CVE-2026-45695 (CVSS 9.8) - Kopia备份工具: Kopia HTTP服务器以`--without-password`
安全情报 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses 📡 The Hacker News · 2026-06-30 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million    
安全情报 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets 📡 The Hacker News · 2026-07-03 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million      
安全情报 North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign 📡 The Hacker News · 2026-07-04 North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million     
安全情报 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses 📡 The Hacker News · 2026-06-30 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million    
安全情报 📊 2026-07-19 漏洞情报日报 · 200 条 · 高危 89 每日漏洞情报汇总 · 2026-07-19 📊 2026-07-19 漏洞情报日报 📋 共 200 条 🔥 高危/严重 89 条 🐙 GitHub-Advisory 35 条 🔥14 🛡️ NVD-Latest 75 条 🔥75 ⚔️ Sploitus 90 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-9810 (CVSS 9.8):WordPress AI Copilot 插件认证绕过漏洞。未绑定 OAuth 令牌至用户,攻击者可通过公共 OAuth 流程获取有效令牌直接获取管理员权限。 * CVE-2026-45695 (CVSS 9.8):Kopia 备份工具 HTTP 服务无需密码启动时,存在未授权API访问风险。远程攻击者可利用该漏洞读取或操作备份数据。 * CVE-2026-53713 (Critical)
安全情报 Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data 📡 The Hacker News · 2026-07-07 Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million    
安全情报 AI-Generated Malware Powers New Armored Likho APT Campaign 📡 Security Affairs · 2026-07-07 AI-Generated Malware Powers New Armored Likho APT Campaign AI-Generated Malware Powers New Armored Likho APT Campaign Home Cyber Crime Cyber warfare APT Data Breach Deep Web Hacking Hacktivism Intelligence Artificial Intelligence Internet of Things Laws and regulations Malware Mobile Reports Security Social Networks Terrorism ICS-SCADA Crypto POLICIES
安全情报 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses 📡 The Hacker News · 2026-06-30 Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million    
安全情报 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets 📡 The Hacker News · 2026-07-03 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million      
安全情报 📊 2026-07-18 漏洞情报日报 · 200 条 · 高危 96 每日漏洞情报汇总 · 2026-07-18 📊 2026-07-18 漏洞情报日报 📋 共 200 条 🔥 高危/严重 96 条 🚨 CISA-KEV 3 条 🐙 GitHub-Advisory 52 条 🔥27 🛡️ NVD-Latest 69 条 🔥69 ⚔️ Sploitus 76 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-56699 (CVSS 10.0,Wazuh Manager): 严重级别最高。未转义字段导致NDJSON注入,已注册代理可任意删除/索引数据,直接威胁SIEM日志完整性。 * CVE-2026-45695 (CVSS 9.8,Kopia备份工具): 无密码启动HTTP服务时,攻击者可未经认证直接访问备份仓库,导致敏感数据全量泄露。 * CVE-2026-55579 (Pheditor编辑器): 硬编码默认密码“admin”
安全情报 DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts 📡 The Hacker News · 2026-07-07 DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million       Get the
安全情报 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets 📡 The Hacker News · 2026-07-03 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million      
安全情报 📊 2026-07-17 漏洞情报日报 · 200 条 · 高危 106 每日漏洞情报汇总 · 2026-07-17 📊 2026-07-17 漏洞情报日报 📋 共 200 条 🔥 高危/严重 106 条 🚨 CISA-KEV 3 条 🐙 GitHub-Advisory 71 条 🔥40 🛡️ NVD-Latest 66 条 🔥66 ⚔️ Sploitus 60 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-56699 (CVSS 10.0):Wazuh Manager < 5.0.0-beta3 存在NDJSON注入漏洞。已注册的Agent可构造恶意DataValue.index字段,向OpenSearch Bulk API注入删除或写入操作,威胁日志系统完整性与可用性。 * CVE-2026-62422 (CVSS 10.0):JetBrains YouTrack(
安全情报 GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures 📡 The Hacker News · 2026-07-08 GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million  
安全情报 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets 📡 The Hacker News · 2026-07-03 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million      
安全情报 GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures 📡 The Hacker News · 2026-07-08 GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures --> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million  