Aggregator
CVE-2024-0639 | Linux Kernel up to 6.4 SCTP net/sctp/socket.c sctp_auto_asconf_init deadlock
CVE-2026-0596 | MLflow os command injection
CVE-2026-35038 | SignalK signalk-server up to 2.23.x from information disclosure
CVE-2026-34601 | xmldom up to 0.8.11/0.9.8 xml injection (GHSA-wh4c-j3r5-mjhp / Nessus ID 304904)
CVE-2026-0545 | MLflow up to 3.0 FastAPI Job Endpoint missing authentication (EUVD-2026-18809)
CVE-2026-31392 | Linux Kernel up to 7.0-rc4 SMB Client /etc/krb5.keytab match_session weak password hash (Nessus ID 311783)
CVE-2026-23425 | Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 KVM pkvm_init_features_from_host initialization (WID-SEC-2026-0985)
CVE-2026-23435 | Linux Kernel up to 6.18.19/6.19.9/7.0-rc4 PMU NMI x86_pmu_enable null pointer dereference (WID-SEC-2026-0985)
CVE-2026-34743 | tukaani-project xz up to 5.8.2 Compression lzma_index_decoder heap-based overflow (GHSA-x872-m794-cxhv / Nessus ID 305980)
CVE-2026-4350 | Perfmatters Plugin up to 2.5.9.1 on WordPress PMCS::action_handler delete path traversal (EUVD-2026-18609)
CVE-2026-1995 | IDrive Cloud Backup Client prior 7.0.0.63 on Windows id_service.exe privileges management (EUVD-2026-14949)
HollowByte:11字节 payload 耗尽 OpenSSL 服务器内存
Zimbra 修复严重的 SNMP 命令注入和 XSS漏洞
CVE-2023-39916 | NLnet Labs Routinator up to 0.12.1 path traversal (Nessus ID 328871)
CVE-2026-16424 | Google Chrome up to 150.0.7871.128 GPU use after free (Nessus ID 328866)
CVE-2026-58102 | JONASBN Crypt::OpenSSL::X509 up to 2.1.2 Extension oid out-of-bounds (EUVD-2026-43574 / Nessus ID 328873)
CVE-2026-58101 | JONASBN Crypt::OpenSSL::X509 up to 2.1.2 Extension Parser keyid null pointer dereference (EUVD-2026-43573 / Nessus ID 328873)
2026年了,核弹还是fastjson,fastjson1.2.83 RCE是怎么回事?
7月19日,推上的一名安全研究员声称,他发现了一个在fastjson 1.2.83版本中无需gadget的RCE漏洞。一时间激起千帆浪。
Fastjson虽然已经停止维护1版本,但是1版本的Fj依旧是互联网上应用最多的Java JSON库之一,虽然1.2.83没有在维护,但是在长期和fastjson对抗的时间里,83版本仅可以基于expectClass和第三方库构成的gadget做的极其有限的攻击利用,几乎无法RCE,所以很多厂家没有选择更新到FJ2增加不确定性。
在过去的1天多时间内,基于作者的部分信息,大家正在逐渐探索出了漏洞的真相。
在7月22日,原作者公开了他们的研究文档https://fearsoff.org/cn/research/fastjson-1-2-83-rce
Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA), working alongside US law enforcement. The suspect was arrested in Indonesia by local police. Authorities describe Kratos as one of the “world’s most widely … More →
The post Police dismantle Kratos phishing platform behind 15,000 monthly campaigns appeared first on Help Net Security.