vulnerability Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs A nine-year-old vulnerability (CVE-2026-64600) in the Linux kernel's XFS filesystem allows unprivileged local users to gain root access on default Red Hat Enterprise Linux, CentOS Stream, and Amazon Linux installations.… The Hacker News · Jul 23, 2026 High CVE-2026-64600CVE-2026-8933linuxxfskernel
threat-intel Cisco's open-weight bug busters take on Google and OpenAI This article covers a variety of cybersecurity and technology news items, including Cisco's efforts to compete with Nvidia's AI hardware, a security breach involving Joomla extensions, and various other developments in t… The Register · Jul 21, 2026 Medium securitycybersecurityjoomla
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (17 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. These vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The affected products range from deskt… CERT-FR · Jul 17, 2026 High CVE-2023-53995CVE-2025-68324CVE-2025-71089vulnerabilitylinuxsecurity
threat-intel Multiples vulnérabilités dans le noyau Linux d'Ubuntu (17 juillet 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Some of these vulnerabilities allow for privilege escalation, remote denial of service, and data confidentiality compromise. The vulnerabilitie… CERT-FR · Jul 17, 2026 High CVE-2021-47117CVE-2021-47202CVE-2022-48816linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (17 juillet 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities can lead to arbitrary code execution, privilege escalation, and a denial-of-service attack. Red Hat has released security adv… CERT-FR · Jul 17, 2026 High CVE-2025-38653CVE-2025-68183CVE-2025-68724linuxkernelvulnerability
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
vulnerability Schneider Electric PowerChute Serial Shutdown Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain multiple vulnerabilities that could allow attackers to overwrite critical files, inject malicious data, gain unauthorized access, or trigger… CISA Advisories · Jul 9, 2026 High CVE-2026-2399CVE-2026-2404CVE-2026-2405vulnerabilitypatchsecurity advisory
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability
threat-intel 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Researchers at Nebula Security discovered GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that allows an unprivileged user to gain root access on a machine. The flaw, discovered by their AI-driven bu… The Hacker News · Jul 8, 2026 High CVE-2026-43499CVE-2026-53166CVE-2026-46242linuxkernelprivilege-escalation
threat-intel Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems A long-standing Linux kernel vulnerability, dubbed Januscape (CVE-2026-53359), has been discovered that allows attackers to escape virtual machines and gain root access on the underlying host. This flaw, dormant for 16 y… SecurityWeek · Jul 7, 2026 Critical CVE-2026-53359linuxkernelvm
threat-intel 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor, dubbed ‘Januscape’ (CVE-2026-53359), allows guest virtual machines to corrupt the host kernel's shadow-page state. Researcher Hyunwoo Kim discovered t… The Hacker News · Jul 6, 2026 High CVE-2026-53359CVE-2026-43284CVE-2026-43500use-after-freeshadow pagenested virtualization
threat-intel Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability A proof-of-concept exploit for a Linux kernel vulnerability, dubbed ‘Bad Epoll,’ has been released, allowing unprivileged processes to gain root access on various devices. The vulnerability stems from a race condition wi… SecurityWeek · Jul 6, 2026 High CVE-2026-46242CVE-2026-43074linuxkernelvulnerability
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai
vulnerability ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access A critical vulnerability, dubbed ‘DirtyClone,’ has been identified in the Linux kernel, allowing local users to gain root access. This flaw, similar to previous ‘DirtyFrag’ and ‘Fragnesia’ vulnerabilities, stems from how… SecurityWeek · Jun 29, 2026 Critical CVE-2026-43503CVE-2026-43284CVE-2026-43500linuxkernelroot
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
threat-intel New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A vulnerability, dubbed "pedit COW," has been discovered in the Linux kernel's traffic-control subsystem, allowing unprivileged users to gain root access by poisoning cached binaries. The exploit, demonstrated with a wor… The Hacker News · Jun 26, 2026 Critical CVE-2026-46331USGBlinuxkernelexploit
vulnerability New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets A new vulnerability, CVE-2026-43503, has been discovered in the Linux kernel related to the DirtyClone variant of the DirtyFrag family. This flaw allows local users to gain root access by exploiting a cloned network pack… The Hacker News · Jun 26, 2026 High CVE-2026-43503CVE-2026-31431CVE-2026-43284linuxkernelprivilege escalation
threat-intel OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI is expanding its Daybreak initiative with GPT-5.5-Cyber, an AI model designed to accelerate vulnerability discovery and patching within software. This expansion includes a new plugin for streamlining the vulnerabi… The Hacker News · Jun 23, 2026 High CVE-2026-47729CVE-2026-4890CVE-2026-4891CAaivulnerabilitypatching