Mastodon Digest
for the past
scorer
threshold
Posts

‼️ Darknet Markets Timeline was added to show that DarkMattter Market is exit scamming. I'm in the process of updating the timeline to look and feel better as well as provide more information.

darkwebinformer.com/darknet-ma

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure

Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.

The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.

Affected versions include:

• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2

GitLab disclosed and patched the vulnerability on September 10.

Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.

Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.

GitLab.com is already patched.

Source: docs.gitlab.com/releases/patch

🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory

Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.

CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.

An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.

The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.

CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.

A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.

The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.

As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.

Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.

Source: securityonline.info/vlc-media-

Kicksecure: Kicksecure is a hardened Linux operating system designed for security-sensitive computing. It includes protections against malware and exploits, stronger system isolation, hardened defaults, and physical-security features such as a panic-key emergency shutdown that can quickly power off the system if it is at risk of being physically compromised.

Link: kicksecure.com/

Repas de merle

un
Boosts

#Introduction This is a server migration of a newbie's account. I recently discovered this social network by reading the bio of the founder of lichess website. I love chess, development, music, reading books and much more. I really appreciate the ethical principles behind Mastodon. I hope to improve my skills quickly. Thank you all for reading! 🙏 🐘