惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cloudbric
Cloudbric
E
Exploit-DB.com RSS Feed
SecWiki News
SecWiki News
Forbes - Security
Forbes - Security
N
News | PayPal Newsroom
S
Security @ Cisco Blogs
Schneier on Security
Schneier on Security
V
V2EX - 技术
S
Secure Thoughts
W
WeLiveSecurity
Google DeepMind News
Google DeepMind News
C
CERT Recently Published Vulnerability Notes
NISL@THU
NISL@THU
S
Securelist
S
Security Archives - TechRepublic
Know Your Adversary
Know Your Adversary
V
Vulnerabilities – Threatpost
Security Latest
Security Latest
Recent Commits to openclaw:main
Recent Commits to openclaw:main
G
GRAHAM CLULEY
H
Hacker News: Front Page
Microsoft Azure Blog
Microsoft Azure Blog
I
Intezer
Google Online Security Blog
Google Online Security Blog
美团技术团队
阮一峰的网络日志
阮一峰的网络日志
T
The Exploit Database - CXSecurity.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Webroot Blog
Webroot Blog
Jina AI
Jina AI
Engineering at Meta
Engineering at Meta
P
Proofpoint News Feed
The Cloudflare Blog
I
InfoQ
L
LangChain Blog
U
Unit 42
P
Proofpoint News Feed
S
Schneier on Security
S
Security Affairs
Y
Y Combinator Blog
T
Tenable Blog
N
News and Events Feed by Topic
MyScale Blog
MyScale Blog
量子位
Google DeepMind News
Google DeepMind News
Cyberwarzone
Cyberwarzone
博客园 - 聂微东
D
Darknet – Hacking Tools, Hacker News & Cyber Security
GbyAI
GbyAI
AWS News Blog
AWS News Blog

www.guru3d.com

TCL Brings OLED+ and QD-Mini LED Gaming Monitors to Europe NZXT H6 RGB+ review Microsoft Confirms 110W RTX Spark Configuration for Surface Laptop Ultra NVIDIA RTX 50 SUPER Graphics Cards Reportedly Back on Track Windows 11 Pro $24 & Office 2024 for $12 - Mid-Year Mega Sale at CDKeyOffer (6-5-26) MSI Unveils EdgeMesa N AI+ Mini PC Powered by NVIDIA RTX Spark MediaTek Confirms Cheaper Nvidia RTX Spark Chips With Twelve Cores Media Player Classic - Home Cinema v2.7.2 Download AMD Non-Committal on FSR 4.1 Support for RDNA 3.5 Integrated Graphics Asetek Unveils Emma V3 Gen10 AIO Platform with Lower Noise and Improved Thermal Performance Intel Nova Lake-S Platform Emerges with New LGA 1954 Socket Maxsun Brings Intel Panther Lake and Wildcat Lake Mobile CPUs to Desktop Motherboards 3DMark Basic Edition Download v2.32.8871 G.SKILL Unveils DDR5-10933 Memory, DDR5-10000 512GB R-DIMM and 768GB DDR5-8800 Kits at Computex 2026 AMD Reengineered Ryzen 7 5800X3D After TSMC Packaging Changes NAND chip revenue in Q1 2026 was higher than the total revenue for the entire year of 2023 GALAX HOF Concept GPU Signals Future RTX 60 Series Ambitions AMD EXPO ULL Targets Lower Latency, Up to 15% Gaming Gains ASUS V600 AiO Launches with Ryzen AI, Wi-Fi 7 and HDMI Input ENERMAX Unveils Pump-Free AIO Cooling Thermal Solutions 3DMark Previews Native 4K Path-Tracing Benchmark With AI Rendering Kioxia Details 332-Layer BiCS10 NAND for Future PCIe Gen6 SSDs Phison Reveals PS5303-X3 PCIe 6.0 SSD Controller Reaching 28GB/s XFX Launches Radeon RX 9070 GRE SWIFT Triple Fan Graphics Cards Microsoft Majorana 2 Quantum Chip Claims 1000x Reliability Improvement MSI Previews Diamond GPU Cooling and Metal Fan Blade Technology MSI Showcases The Mandalorian and Grogu GeForce RTX 5080 at Computex Microsoft Introduces Surface RTX Spark Dev Box for Local AI Development Intel Reaffirms Arc Graphics Commitment Amid Ongoing Desktop GPU Questions Windows 11 Pro for $24 and Office 2024 from $12 at CDKeyOffer AMD Radeon Software Adrenalin 26.6.1 driver download Colorful Reintroduces GeForce RTX 3060 12GB Graphics Card in China Noctua Reveals its NL-LC1 AIO Series with Advanced Acoustic Design be quiet! Expands IO Ecosystem with New PSU, Cooling and Cases Possible Intel Z990 Motherboard Spotted at Computex 2026 ASUS Talks About ROG 48V GPU Power Architecture at Computex 2026 DeepCool Returns to Computex 2026 with New Air Coolers, Curved-Screen AIOs, Wireless Fans and PC Cases NZXT Launches H6 Compact Dual-Chamber Chassis with Curved Glass Design MSI Unveils RTX 5080 Suprim Draco Epic Anniversary Edition ASUS ROG GR20 Edition 20 Case Uses Modular Open-Frame Design ASUS Unveils ROG Thor 3000W Titanium III Edition 20 PSU with 3000W Capacity ASUS Unveils ROG Astral GeForce RTX 5090 Edition 20 with Curved AMOLED Display and 800W Power Mode Samsung Display Showcases 3000-Nit OLED and Advanced EL-QD Technologies Sapphire PULSE Radeon RX 9070 GRE review ASRock Steel Legend Radeon RX 9070 GRE review ASUS Launches Prime Radeon RX 9070 GRE EVO OC Graphics Card NZXT Introduces Single Frame Ultra RGB Fans with Multi-Zone ARGB Lighting ASUS and ROG Unveil Massive Monitor Lineup at Computex 2026 Cougar Showcases NU 700 and NU 500 AI Workstation Cases, 3200W PSU at Computex 2026 AMD Revives Ryzen 7 5800X3D and Adds Cheaper AM5 X3D CPU AMD Radeon RX 9070 GRE Goes Global with 12GB GDDR6 NVIDIA Completes DLSS 4.5 with Second-Generation Ray Reconstruction AMD Extends AM5 Socket Support Through 2029 for Future Ryzen CPUs Intel Launches 18A-Based Xeon 6 Plus with Up to 288 E-Cores Microsoft Surface Laptop Ultra Debuts with RTX Spark and Mini LED NVIDIA RTX Spark Brings Grace Arm CPUs and Blackwell Graphics to Windows NVIDIA Commits to New Windows Arm Processors Every Two Years ASRock Launches Radeon RX 9070 GRE Steel Legend Dark OC Graphics Card MSI MEG Vision X2 AI+ Introduces AI Holostage and LuckyClaw Noctua Partners with Carbice to Bring Carbon Nanotube Thermal Pads to DIY PCs MSI Celebrates 40 Years with Titan 18 HX Dragon Edition Laptop MSI Expands AM5 Portfolio with New B850 CARBON and MORTAR Boards MSI Unveils Fabric-Covered AIO Cooler and Floating Chassis Designs Display Driver Uninstaller (DDU) download version 18.1.5.4 BenQ Launches RD270Q Monitor For Programmers (WQHD and 144Hz) Google Unveils Coral Board for Local AI and Edge Computing G.SKILL Introduces Actively Cooled DDR5 Memory at Computex 2026 ASRock Celebrates Taichi 10th Anniversary with SE Motherboards and Cooling Solutions G.SKILL Demonstrates DDR5-9200 CU-DIMM Memory Running at Just 1.1 Volts ASUSTOR Positions Flashstor All-Flash NAS Series for Professional Content Creation Geometric Future Shows Model 9 and Model 7 Ultra-Tower Cases Acer Expands Gaming Monitor Portfolio with 3D, QD-OLED and 540Hz Models Windows 11 Pro $24 & Office 2024 $12 At CDKeyOffer | Activation Issue After PC Upgrade (29-5) Alienware New 39-Inch OLED Monitor Brings 5K2K and 330Hz Mode Qualcomm Plans Snapdragon C Platform for Affordable $300 Windows Laptops Leaked MSI Claw 8 EX AI+ Shows Design Overhaul Ahead of Launch Synology Introduces Compact FS200T Six-Bay All-Flash Storage Server ASUS Bundles ROG Equalizer Cable with Thor III Power Supplies The Witcher 3 Surpasses 65 Million Copies Sold as CD Projekt Reports Strong Q1 2026 Results Steam Deck OLED Sells Out Again Despite Significant Price Increase Silicon Motion Unveils SM2524XT PCIe Gen5 DRAMless AI SSD Controller Intel Arc G3 Handheld Chips Bring Panther Lake to Portable Gaming TP-Link Announces Archer 8 as First Wi-Fi 8 Router Platform NVIDIA Inspector Download version v3.0.1.13 ZOTAC Previews GeForce RTX 50-Series 20th Anniversary Graphics Cards AMD Radeon RX 9070 GRE Retail Listings Confirm European Launch Plans MSI Teases Dragon-Themed 40th Anniversary Draco Epic MEG ACE Boards YouTube Expands Automatic AI Video Detection And Warning Labels AMD Expands Versal Prime Gen 2 Lineup With Compact Embedded SoCs MSI Launches Cubi NUC AI+ Mini PC With Intel Core Ultra 5 Microsoft Rolls Out Windows 11 Low Latency Profile CPU Burst Optimization - Guide Valve Steam Machine Pricing Rumored To Sit Above Steam Deck OLED KTC Launches 27M1 Max Dual-Mode 4K 160Hz and 320Hz Gaming Monitor The Witcher 3 No Longer Supports Older PC Hardware Configurations Beelink Announces First Mini PCs Based on Intel Wildcat Lake Level Up Your PC for Less – Windows 11 Pro for $24 & Office 2024 from $12 at CDKeyOffer (27-5) HWiNFO Download v8.48 Download Intel network adapter driver package 31.2 Download Intel ARC graphics driver version: 32.0.101.8824 Nvidia GeForce 610.47 Driver Quietly Adds First DLSS 5 Neural Rendering Profiles
Ubiquiti Urges Immediate Updates Following Root Access Exploit Discovery
Hilbert Hagedoorn · 2026-06-11 · via www.guru3d.com

Security researchers have disclosed a critical vulnerability chain affecting Ubiquiti's UniFi OS Server platform that could allow attackers to bypass authentication controls, execute arbitrary commands, and obtain full root access to affected systems. The issue impacts enterprise deployments using UniFi OS Server and has been assigned three CVE identifiers: CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. According to technical analysis of the attack chain, the initial compromise relies on inconsistencies between how the front-end web server and the back-end authentication service process URL paths. By crafting specially designed requests, attackers can cause protected administrative functions to be interpreted as resources that do not require authentication. This effectively bypasses access controls and exposes internal functionality that would normally remain restricted. After authentication has been bypassed, attackers can exploit a command injection vulnerability located within the suite update service. The flaw exists because affected versions do not adequately validate user-defined suite names before passing them into system-level commands. Malicious input can therefore be injected and executed directly on the underlying operating system.

89759578789

Researchers confirmed successful exploitation against UniFi OS Server version 5.0.6, demonstrating complete privilege escalation to root. Once root access is obtained, an attacker gains unrestricted control over the platform and its associated services. The potential impact extends well beyond basic administrative access. Compromised systems may expose token-signing secrets, encrypted communication keys, cloud authentication tokens, user account databases, and configuration data related to RADIUS, Wi-Fi, VPN, and WireGuard deployments. In organizations using UniFi's broader ecosystem, the consequences may also affect physical security infrastructure. Deployments integrating UniFi access control systems or surveillance solutions could potentially allow attackers to interact with connected security devices after a successful compromise. This expands the attack surface from network infrastructure into building access management and monitoring environments. Ubiquiti has addressed the vulnerability chain in UniFi OS Server version 5.0.8 and recommends that administrators update immediately. The company also advises customers to verify firmware versions on any associated UniFi hardware to ensure corresponding fixes have been applied throughout the deployment. However, applying the update may not fully eliminate risk if systems were compromised before patching. Attackers may have already extracted signing keys or other sensitive credentials, potentially enabling continued access even after the vulnerabilities are fixed. Administrators are therefore encouraged to review audit logs, investigate suspicious activity, rotate credentials where necessary, and restrict management interface access to trusted management networks. Security teams unable to deploy updates immediately should ensure that UniFi management interfaces are not directly accessible from the public internet and should limit access to authorized administrative systems until remediation can be completed.

Vulnerability Description
CVE-2026-34908 Authentication bypass component of exploit chain
CVE-2026-34909 URL parsing and validation inconsistency exploitation
CVE-2026-34910 Command injection leading to privilege escalation
Affected Version UniFi OS Server 5.0.6
Patched Version UniFi OS Server 5.0.8 or newer
Impact Authentication bypass, command execution, root access

Source: Ubiquiti Security Advisory