threat-intel Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems A long-standing Linux kernel vulnerability, dubbed Januscape (CVE-2026-53359), has been discovered that allows attackers to escape virtual machines and gain root access on the underlying host. This flaw, dormant for 16 y… SecurityWeek · Jul 7, 2026 Critical CVE-2026-53359linuxkernelvm
threat-intel Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability A proof-of-concept exploit for a Linux kernel vulnerability, dubbed ‘Bad Epoll,’ has been released, allowing unprivileged processes to gain root access on various devices. The vulnerability stems from a race condition wi… SecurityWeek · Jul 6, 2026 High CVE-2026-46242CVE-2026-43074linuxkernelvulnerability
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai
vulnerability ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access A critical vulnerability, dubbed ‘DirtyClone,’ has been identified in the Linux kernel, allowing local users to gain root access. This flaw, similar to previous ‘DirtyFrag’ and ‘Fragnesia’ vulnerabilities, stems from how… SecurityWeek · Jun 29, 2026 Critical CVE-2026-43503CVE-2026-43284CVE-2026-43500linuxkernelroot
threat-intel New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A vulnerability, dubbed "pedit COW," has been discovered in the Linux kernel's traffic-control subsystem, allowing unprivileged users to gain root access by poisoning cached binaries. The exploit, demonstrated with a wor… The Hacker News · Jun 26, 2026 Critical CVE-2026-46331USGBlinuxkernelexploit
vulnerability New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets A new vulnerability, CVE-2026-43503, has been discovered in the Linux kernel related to the DirtyClone variant of the DirtyFrag family. This flaw allows local users to gain root access by exploiting a cloned network pack… The Hacker News · Jun 26, 2026 High CVE-2026-43503CVE-2026-31431CVE-2026-43284linuxkernelprivilege escalation
vulnerability Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks Researchers discovered a long-standing vulnerability (CVE-2026-20971) in Samsung’s KNOX kernel across numerous Galaxy devices, from S9 to S25. The flaw, a race-condition use-after-free (UAF), allowed for potential kernel… SecurityWeek · Jun 23, 2026 High uafkernelrace condition
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor
vulnerability One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public A critical vulnerability, CVE-2026-23111, has been discovered in the Linux kernel’s nf_tables packet-filtering code, allowing unprivileged users to escalate to root access and break out of containers. The flaw, initially… The Hacker News · Jun 8, 2026 Critical CVE-2026-23111linuxkerneluse-after-free
vulnerability New CIFSwitch Linux flaw gives root on multiple distributions A newly discovered vulnerability, dubbed 'CIFSwitch,' in the Linux kernel allows attackers to escalate privileges to root by forging CIFS authentication key descriptions. The flaw, present since 2007, affects multiple Li… BleepingComputer · May 30, 2026 High CVE-2026-46243linuxkernelprivilege escalation
vulnerability 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros A nine-year-old vulnerability in the Linux kernel, CVE-2026-46333, allows unprivileged users to execute commands as root, posing a significant risk to systems running affected distributions. The flaw stems from improper… The Hacker News · May 21, 2026 High CVE-2026-46333linuxkernelprivilege escalation
threat-intel DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability A Proof-of-Concept (PoC) exploit, dubbed DirtyDecrypt, has been released for a Linux kernel vulnerability (CVE-2026-31635) allowing for local privilege escalation. The vulnerability, related to a missing copy-on-write (C… The Hacker News · May 19, 2026 High CVE-2026-31635CVE-2026-31431CVE-2026-43284linuxkernellpe
threat-intel Siemens SIMATIC Siemens has released a security update for its SIMATIC CN 4100 system to address multiple vulnerabilities discovered within its Linux kernel components and libxml2. These vulnerabilities, including null pointer dereferen… CISA Advisories · May 14, 2026 High CVE-2024-47704CVE-2024-57924CVE-2024-58240DElinuxkernelvulnerability
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe
supply-chain A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave A Google Project Zero researcher discovered a 0-click exploit chain targeting the Pixel 9, leveraging a BigWave hardware accelerator and a vulnerability in the mediacodec SELinux context. The exploit bypasses sandboxing… Google Project Zero · Jan 14, 2026 Critical kernelsupply-chainarbitrary-read-write