Posts of last 24 hours
A vulnerability classified as critical was found in Microsoft Windows. Affected by this issue is some unknown functionality of the component Media Foundation. The manipulation results in Remote Code Execution.
This vulnerability is identified as CVE-2021-42276. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/186397
GitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run their most sensitive software delivery workloads on GitLab, can now run GitLab Duo Agent Platform inside that same single tenant environment and region, connect their own models for inference, and keep AI-processed data inside their existing security boundary. GitLab 19.3 also ships today with support for Secrets Manager, Flow Creator Agent, and Bulk SAST … More →
The post GitLab 19.3 helps enterprises scale agentic development securely appeared first on Help Net Security.
https://www.helpnetsecurity.com/2026/08/21/gitlab-19-3-updates/
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.
The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring
https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
天文学家发现了银河系已知运行速度最快的恒星。这颗名为 S301 的恒星围绕银河系中心的超大质量黑洞——人马座A*运行,最快速度达到每秒 2.5 万公里,超过光速的 8%。它的运行轨道非常接近人马座A*,其运动有望帮助科学家首次直接测量大质量黑洞的自转,并为检验爱因斯坦广义相对论提供新的机会。S301 绕人马座A* 公转周期为 8.7年。在它距离人马座 A*最近时——类似于太阳到土星的距离——恒星的运行速度超过光速的 8%。研究人员认为,S301的轨道特征以及恒星无法在如此靠近超大质量黑洞的位置形成,表明它很可能原本属于一个双星系统。当这个双星系统靠近人马座A*时,黑洞强大的潮汐力将两颗恒星撕裂,其中一颗被黑洞引力捕获,成为如今的 S301;另一颗则被高速抛出,其速度可能高到足以逃离银河系。
https://www.solidot.org/story?sid=85154
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.
The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory
https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
Mozilla 工程总监 Sylvestre Ledru 上月宣布,从 2026 年 9 月起 Firefox 桌面版和 Android 版本的发布周期从 4 周减少到 2 周。本周释出的 Firefox 154 是最后一个按四周发布模式释出的版本,九月初释出的 v155 则是第一个双周发布版本。由 Mozilla 子公司 MZLA 开发的开源邮件客户端 Thunderbird 宣布也将采用双周发布模式。MZLA 的 Corey Bryant 称,从 9 月起 Thunderbird 采用相同的更新频率。
https://www.solidot.org/story?sid=85153
A vulnerability marked as critical has been reported in Microsoft Quantum Development Kit for Visual Studio Code. The affected element is an unknown function. Performing a manipulation results in Remote Code Execution.
This vulnerability is cataloged as CVE-2021-27082. It is possible to initiate the attack remotely. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.
https://vuldb.com/vuln/170980
A vulnerability classified as critical has been found in Microsoft Visual Studio. This affects an unknown function of the component Code Remote Containers Extension. The manipulation leads to Remote Code Execution.
This vulnerability is documented as CVE-2021-27083. The attack can be initiated remotely. There is not any exploit available.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/170982
A vulnerability, which was classified as critical, was found in Microsoft Windows up to Server 2022. This affects an unknown function of the component Virtual Machine Bus. Executing a manipulation can lead to privilege escalation.
This vulnerability is registered as CVE-2021-26443. The attack requires access to the local network. No exploit is available.
A patch should be applied to remediate this issue.
https://vuldb.com/vuln/186371
A vulnerability has been found in Microsoft Azure RTOS and classified as problematic. This impacts an unknown function. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2021-26444. It is possible to launch the attack on the physical device. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
https://vuldb.com/vuln/186372