Aggregator
在 Android 上运行 Linux 终端,体验究竟怎么样?(2026 版)
1 month 2 weeks ago
因为和ChromeOS中的Linux虚拟机开发环境有着千丝万缕的联系,2025年作为实验性功能登录Google自家Pixel机型的Linux虚拟机,发布后不仅没有就此在开发者选项中闲
CVE-2025-14870 | GitLab Community Edition/Enterprise Edition up to 18.9.6/18.10.5/18.11.2 JSON allocation of resources (EUVD-2025-209836)
1 month 2 weeks ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.9.6/18.10.5/18.11.2 and classified as problematic. Impacted is an unknown function of the component JSON Handler. Executing a manipulation can lead to allocation of resources.
This vulnerability appears as CVE-2025-14870. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-14869 | GitLab Community Edition/Enterprise Edition up to 18.9.6/18.10.5/18.11.2 API Endpoint improper validation of specified quantity in input (EUVD-2025-209835)
1 month 2 weeks ago
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 18.9.6/18.10.5/18.11.2 and classified as problematic. This issue affects some unknown processing of the component API Endpoint. Performing a manipulation results in improper validation of specified quantity in input.
This vulnerability is reported as CVE-2025-14869. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
解决一个安卓15/16调试APK运行adb jdwp无输出的问题
1 month 2 weeks ago
解决一个安卓15/16调试APK运行adb jdwp无输出的问题
New Fragnesia Linux flaw lets attackers gain root privileges
1 month 2 weeks ago
Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious code as root. [...]
Sergiu Gatlan
有IT管理员报告称Windows 11安装5月更新后网络速度下降 卸载后仍然无法恢复
1 month 2 weeks ago
CVE-2022-27645 | Netgear R6700v3 1.0.4.120_10.0.91 readycloud_control.cgi authorization (ZDI-22-522 / EUVD-2022-32146)
1 month 2 weeks ago
A vulnerability was found in Netgear R6700v3 1.0.4.120_10.0.91. It has been rated as very critical. This impacts an unknown function of the file readycloud_control.cgi. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2022-27645. The attack is only possible within the local network. No exploit exists.
vuldb.com
CVE-2022-27642 | Netgear R6700v3 1.0.4.120_10.0.91 authorization (ZDI-22-518 / EUVD-2022-32143)
1 month 2 weeks ago
A vulnerability was found in Netgear R6700v3 1.0.4.120_10.0.91 and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to incorrect authorization.
The identification of this vulnerability is CVE-2022-27642. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2022-27643 | Netgear R6700v3 1.0.4.120_10.0.91 SOAP Request buffer overflow (ZDI-22-519 / EUVD-2022-32144)
1 month 2 weeks ago
A vulnerability was found in Netgear R6700v3 1.0.4.120_10.0.91. It has been classified as critical. The impacted element is an unknown function of the component SOAP Request Handler. The manipulation leads to buffer overflow.
This vulnerability is referenced as CVE-2022-27643. The attack needs to be initiated within the local network. No exploit is available.
vuldb.com
CVE-2022-27644 | Netgear R6700v3 1.0.4.120_10.0.91 HTTPS certificate validation (ZDI-22-520 / EUVD-2022-32145)
1 month 2 weeks ago
A vulnerability was found in Netgear R6700v3 1.0.4.120_10.0.91. It has been declared as critical. This affects an unknown function of the component HTTPS Handler. The manipulation results in improper certificate validation.
This vulnerability is identified as CVE-2022-27644. The attack can only be performed from the local network. There is not any exploit available.
vuldb.com
CVE-2022-27641 | Netgear R6700v3 1.0.4.120_10.0.91 NetUSB integer overflow (ZDI-22-544 / EUVD-2022-32142)
1 month 2 weeks ago
A vulnerability has been found in Netgear R6700v3 1.0.4.120_10.0.91 and classified as very critical. Impacted is an unknown function of the component NetUSB Module. Performing a manipulation results in integer overflow.
This vulnerability was named CVE-2022-27641. The attack needs to be approached within the local network. There is no available exploit.
vuldb.com
美国批准10家中企采购英伟达H200芯片
1 month 2 weeks ago
美国政府官方已批准约十家中国企业采购英伟达公司旗舰级AI芯片 H200。不过截至目前,获批订单尚未完成任何实际芯片交付,相关合作仍处于停滞状态。据悉,此次获得美国采购许可的中企名单包含阿里巴巴、字节跳
«Джентльмены» снова облажались. Хакеры-вымогатели, державшие в страхе сотни компаний, сами стали жертвой утечки
1 month 2 weeks ago
За фасадом громких взломов обнаружилась рутина, которую никто из участников не хотел показывать.
伊朗黑客瞄准韩国大型电子制造商
1 month 2 weeks ago
与伊朗有关联的黑客组织 MuddyWater(又名 “种子蠕虫” Seedworm、“静态小猫” Static Kitten )发起了一场大规模的网络间谍活动,目标至少涉及多个行业和国家的 9 家知名机构。 受害者包括韩国一家大型电子制造商、政府机构、中东的一个国际机场、亚洲的工业制造商以及教育机构。 赛门铁克(Syman...
hackernews
伊朗黑客瞄准韩国大型电子制造商
1 month 2 weeks ago
error code: 1003
CVE-2026-7925 | Google Chrome up to 147.0.7727.138 on Windows Chromoting use after free (ID 501833 / Nessus ID 312822)
1 month 2 weeks ago
A vulnerability marked as critical has been reported in Google Chrome on Windows. This issue affects some unknown processing of the component Chromoting. The manipulation leads to use after free.
This vulnerability is listed as CVE-2026-7925. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-7922 | Google Chrome up to 147.0.7727.138 ServiceWorker use after free (WID-SEC-2026-1394)
1 month 2 weeks ago
A vulnerability has been found in Google Chrome and classified as critical. The affected element is an unknown function of the component ServiceWorker. This manipulation causes use after free.
The identification of this vulnerability is CVE-2026-7922. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
用 Obsidian Web Clipper,让豆瓣种草更容易
1 month 2 weeks ago
在上一篇文章中,我把我的豆瓣阅读清单导入到了 Obsidian 中,运用(那时候)新出的 Base 功能管理自己的阅读清单和书籍相关的笔记。朋友们在文章下方也提供了不少新的思路(例如:插件)。但有一个
罕见“联手”:苹果声援谷歌反对欧盟AI新规
1 month 2 weeks ago
苹果公司正式向欧盟委员会提交意见,公开批评欧盟近期提出的旨在帮助谷歌遵守《数字市场法案》(DMA)的监管措施。苹果警告称,欧盟拟议的强制谷歌向竞争对手开放人工智能服务的举措,将对用户的隐私、安全、设备