惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Archives - TechRepublic
Security Archives - TechRepublic
H
Heimdal Security Blog
T
Tenable Blog
Webroot Blog
Webroot Blog
Cisco Talos Blog
Cisco Talos Blog
NISL@THU
NISL@THU
Help Net Security
Help Net Security
W
WeLiveSecurity
量子位
Stack Overflow Blog
Stack Overflow Blog
Schneier on Security
Schneier on Security
Simon Willison's Weblog
Simon Willison's Weblog
Recorded Future
Recorded Future
Martin Fowler
Martin Fowler
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
L
Lohrmann on Cybersecurity
SecWiki News
SecWiki News
Blog — PlanetScale
Blog — PlanetScale
F
Full Disclosure
Recent Commits to openclaw:main
Recent Commits to openclaw:main
小众软件
小众软件
Cyberwarzone
Cyberwarzone
S
Security Affairs
L
LangChain Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
V
V2EX
WordPress大学
WordPress大学
爱范儿
爱范儿
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LINUX DO - 热门话题
Forbes - Security
Forbes - Security
Engineering at Meta
Engineering at Meta
博客园 - 三生石上(FineUI控件)
Scott Helme
Scott Helme
H
Help Net Security
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
Cyber Attacks, Cyber Crime and Cyber Security
有赞技术团队
有赞技术团队
IT之家
IT之家
G
Google Developers Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Schneier on Security
Google DeepMind News
Google DeepMind News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
Hacker News: Ask HN
Hacker News: Ask HN
O
OpenAI News
宝玉的分享
宝玉的分享

The Stack

How Lloyds has transformed its trusted critical data for AI Micron's revenue surges with no end to the memory shortage in sight Mistral's new OCR 4 model shows size matters EU approves €76m in state aid for chip testing firm Even FedEx is a winner of the data centre boom Why AWS thinks AI coding assistants need a new place to run Why China is forging closer ties with open-source foundations China's CPU-only supercomputer tops power list Runtime: Why 'Bring-your-own-Cloud' is taking off; the TRAIT&R framework for agents, and... AWS adds yet another security tool to speed up patching Scattered Spider: UK teen pleads guilty to TfL attack OSS security finally gets a Magic Quadrant Places for People forking out £60m for new ERP system Google offers ATT&CK for bad AI, with surging cost forecast STACKUP: The Stack's weekly tech startups and funding wrap Bring Your Own Cloud: why more enterprises are buying in AWS takes NVIDIA "G7" Blackwell instances GA Runtime: Vercel sets up a new framework for agents, Databricks finds a new Genie, and… Borussia Dortmund's IT head has to sometimes think "outside of the box" Accenture stumbles after Middle East, AI, merger questions Cabinet Office offering £100k+ for AI "ambassador" Critical Splunk Enterprise vulnerability being exploited Accenture buys majority stake in OT security company Dragos npm's security rethink, Satya’s warning, a COBOL win, and... US spending billions to counter China's tech influence NatGeo Society CTO on migrating 15 years of video data to the cloud Alibaba opens French data centres in Europe cloud push SpaceX to take over Cursor in $60bn play for AI coding market Hosting firm Hetzner hikes prices sharply amid supply chain pain HSBC's CIO: AI is easy. True impact is hard. Databricks' Ali Ghodsi: 'Your processes have to change' Rackspace’s "30MW" AMD deal: The devil's in the details The Stack acquires Runtime What is npm doing to protect the JavaScript ecosystem Ron van Kemanade, Group COO, Lloyds, on agents, COBOL, IAM. Langflow instances are getting exploited – again Red Hat's $5 billion answer to Mythos: fix all the code OpenAI acquires German startup to spin up cloud dev environments for better agent control STACKUP: The Stack's weekly tech startups and funding wrap Microsoft CEO warns over concentrated AI model dependency Internet pillar cURL takes a summer holiday from security Anthropic knee-capped by abrupt export controls Months after losing its CEO, now Adobe's CFO gets poached Oracle zero-day exploited for nearly two weeks by Shiny Hunters HM Treasury needs a new CTO, the salary is below average AMD joins UK's Sovereign AI train with Cambridge "AI lab" Oracle PeopleSoft vulnerability exploited: 100s reported hit Oracle reports a $638 billion backlog The UK wants to record court hearings - but not an actual plan Bank of England restarts stalled £24m data collection refresh Anthropic warns LLMs can crank out N-day exploits cheap and fast Defender under Attack: June's Patch Tuesday in the spotlight The CISO needs to get focused on business resilience LibreOffice denounces Euro-Office as Microsoft Trojan Horse Apple's revamped Siri AI leans on Google models and cloud AI could be driving IT hiring in Europe, new report finds UK calls for “device-based” nude controls Cult browser project Ladybird cuts off code community UK gets $1.5bn AI Hardware Plan, and a big-coalition sovereign model plan too STACKUP: The Stack's weekly tech startups and funding wrap Fake IT support staff are walking in to US law firms to steal data Apple found a way to sharply cut token use Apache Livy graduates to Top-level project for Spark support Supabase raises $500m, looks to horizontal Postgres scaling GitLab Field CTO on unlikely customers pulling ahead with AI Killing the card? The UK’s banks eye a payments revolution MPs call on UK government to drop £330m Palantir-NHS deal The Tokenomics Foundation is coming for AI Finops Microsoft's new models give it a better moat The EU dropped its latest tech sovereignty package – what to know HMRC digital transformation: new customer service platform Tokenmaxxing is dead. Finops for AI is emerging slowly. This database company wants to take on Palantir ChatGPT 5.5 and Codex now on Bedrock for easy AWS access Multicloud gets sweeter with a 500 Mbps free private link Alphabet raising $80bn to keep up with ballooning AI CapEx How to get visibility and isolation for AI in Kubernetes Red Hat packages injected with worm in supply chain attack STACKUP: The Stack's weekly tech startups and funding wrap Dell COO says “pain” of price hikes will continue NVIDIA, MS tease tighter agent-native security primitives in Windows Sumedh Thakar: CISOs need to think Shock, WoW, and "AWE" Microsoft turns down temperature amid Nightmare Eclypse row IBM to put $5bn and 20,000 engineers into OSS security fight MongoDB eyes more federal work, snaps up partner Clarity Chinese cyber victims overlapping with industrial strategy - ESET Microsoft stirs a hornets nest over “criminal” zero day disclosure threats Snowflake's AI coding tool is "flywheel" for data platform “Headless” Salesforce hits 1 trillion API calls MySQL gets a foundation with no Oracle, but Alibaba presense GCHQ teases “blueprint” for national AI cyber defense BNP Paribas moves to “zero copy” data model Snowflake joins US federal discount scheme Can Dropbox's new CEO save it from stagnation? Zscaler CEO drools over Mythos tailwind, but Jason's and Joe's departures spook markets Google chases a Kubernetes moment for AI agents UKHSA sticks with Oracle after outsourcing payroll Lenovo eyes “personal AI super agents” in $100 billion drive US eyes physics-based safeguards for water cyber threats Accenture beats IBM in Post Office's latest bid to ditch Horizon
Ubiquiti UniFi OS vulnerabilities exploited in the wild
Kiera Fields · 2026-06-25 · via The Stack

cybersecurity

Ubiquitously bad: CVSS-10 Ubiquiti bugs exploited in the wild

The self-hosted wireless and wired networking OS had three stinkers that are being actively exploited, but newer versions are safe.

Kiera Fields

 -  3 min read

Ubiquitously bad: CVSS-10 Ubiquiti bugs exploited in the wild
Image credit: https://unsplash.com/@davidfucsku

A trio of critical vulnerabilities in Ubiquiti networking software are being exploited in the wild, CISA warned this week.

The bugs — described as CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910 — all impact UniFi OS devices, hardware consoles, and Cloud Gateways that run Ubiquiti's UniFi operating system, and can be exploited via network access.

All three have a CVSS score of 10 — the highest possible score — and were added to the Known Exploited Vulnerabilities catalog on Tuesday, June 23, but they have yet to be flagged as used in ransomware campaigns. Ubiquiti published a security bulletin with patched version updates for all three on May 22.

Get the full story: Subscribe for free

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

Subscribe now