Posts of last 24 hours
A vulnerability classified as problematic was found in Oracle Java SE 6u95/7u80/8u45. This issue affects some unknown processing of the component JMX. The manipulation results in information disclosure.
This vulnerability was named CVE-2015-2621. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/76609
https://www.securitylab.ru/analytics/576111.php
Глобально новые требования Google затронут все сертифицированные устройства Android в 2027 году.
https://www.securitylab.ru/news/576284.php
2026 AI 安全攻防实战白皮书,帮你突破 AI 时代的安全困局。
https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==&mid=2651390618&idx=1&sn=f29b0d8e7027f7ad443093aff4f8f991
Flock 的车牌跟踪系统最近在美国引发了激烈争论,媒体同一时间报道了大量警官利用 Flock 摄像头跟踪女友/前女友、妻子/前妻的新闻。但在一片争论之中,皇帝最忠实的助手、西斯尊主达斯·维达则大肆赞美了 Flock。周三晚上加州圣地亚哥公共安全与宜居社区委员会会议(Public Safety and Livable Neighborhoods Committee Meeting)的公众评论期间,达斯·维达在台上说,“皇帝是 Flock 的粉丝,我们必须继续利用 Flock 技术,如此才能跟踪和监视那些叛军渣滓,看着他们从一个游乐场到另一个游乐场,从游乐场到游泳池,从游泳池到体育馆。因为我们都知道,Flock 摄像头不仅跟踪车牌;它们还跟踪孩子。它们在公园和体育馆里跟踪孩子,我们需要这个,我需要它来跟踪前女友。”
https://www.solidot.org/story?sid=85156
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Anil Shetty, senior VP of Engineering with Cloud Software Group … More →
The post Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) appeared first on Help Net Security.
https://www.helpnetsecurity.com/2026/08/21/citrix-netscaler-gateway-cve-2026-19490/
PurpleDelta欺诈性就业行动:朝鲜IT工人渗透西方企业的完整分析;PATCHCORD:针对阿富汗电信和南亚关键基础设施的APT36新型恶意软件家族;Armored Likho部署Still Toolkit新型间谍工具集
https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519957&idx=2&sn=aafeada85716143c834687ec457e4034
2026年8月20日,arrayref维护者账号被盗,攻击者发布构建时恶意载荷。开发者甚至不需要运行程序,只要 cargo build 一次,恶意代码就已在本机执行。
https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519957&idx=1&sn=b666c8c8fef193b22443d9861d95d60c
AI与云安全事件案例分析周报|2026.08.17 - 2026.08.21
https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247500228&idx=1&sn=5a4c60d70f5f377f8eb3ce4961b91b8b
A vulnerability, which was classified as problematic, has been found in Microsoft Windows. This affects an unknown part of the component Diagnostics Hub Standard Collector. This manipulation causes improper privilege management.
This vulnerability is tracked as CVE-2021-42277. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/186398