< ciso
brief />
Tag Banner

All news with #privilege escalation tag

352 articles · page 5 of 18

RefluXFS: Critical XFS Race Condition Allows Root

🛡️ A nine-year-old race condition in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600 and dubbed RefluXFS by Qualys TRU, enables local attackers to overwrite protected files and gain root privileges. The flaw affects systems with reflink-enabled XFS on kernel v4.11+ and requires a directory writable by an unprivileged user plus a high-value target file. Exploitation is reliable, leaves no kernel logs, survives reboots, and bypasses common defenses because it operates at the filesystem allocation layer. Vendor-fixed kernels are available and immediate patching and rebooting are recommended.
read more →

RefluXFS Linux flaw allows local persistent root

🛡️Qualys disclosed RefluXFS (CVE-2026-64600), a Linux kernel race in XFS reflink handling that lets an unprivileged local user overwrite root-owned files and achieve persistent root access. The bug dates to Linux 4.11 (2017) and affects systems with reflink-enabled XFS filesystems; default installs of several RHEL-derived distributions, Fedora Server, and Amazon Linux can be vulnerable. A patch was merged July 16 and vendors began shipping backports; apply updates and reboot to ensure protection.
read more →

Ubuntu snap-confine local root escalation advisory

🛡️ Cybersecurity researchers disclosed a high-severity local privilege escalation in snap-confine (CVE-2026-8933, CVSS 7.8) affecting default Ubuntu Desktop installs of 24.04, 25.10, and 26.04. The flaw arises from a race condition introduced during sandbox initialization that lets an unprivileged user exploit temporary /tmp artifacts and symlinks to gain root. Vendors advise applying the latest snapd updates immediately to mitigate the risk.
read more →

Ubuntu snap-confine local root escalation CVE

🔒 A high-severity vulnerability in Ubuntu's snap-confine component (CVE-2026-8933) lets any local user gain full root on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. Qualys TRU published research on July 21 showing two race conditions introduced after a hardening change to set-capabilities; attackers can exploit a brief ownership window via FUSE mounts and symlinks, then bypass AppArmor to execute commands as root. Canonical has issued patches and admins are urged to update snapd immediately.
read more →

Unofficial patches available for LegacyHive zero-day

🛡️ Free unofficial micropatches are available for a recently disclosed Windows zero-day, dubbed LegacyHive, which enables non-admin users to escalate privileges by mounting other users' registry hives. The vulnerability was disclosed by researcher Nightmare Eclipse alongside a stripped proof-of-concept after Microsoft's July 2026 updates. ACROS Security (0Patch) offers free micropatches for affected Windows 10 2004+/Windows Server 2022+ systems; Microsoft says it is investigating the claims.
read more →

New LegacyHive Windows zero-day enables privilege escalation

🔒 A researcher known as Nightmare Eclipse published a proof-of-concept named LegacyHive after Microsoft's July 2026 Patch Tuesday, claiming it exploits a vulnerability in the Windows User Profile Service. The PoC has been intentionally modified to require additional credentials, making exploitation harder than earlier releases. Analysts note successful exploitation allows non-admin users to modify the classes registry hive and achieve code execution on admin login. Detection queries for Microsoft Defender for Endpoint were published shortly after.
read more →

Zoom fixes critical account-takeover vulnerability

🔒 Zoom disclosed and patched a critical vulnerability that could allow an unauthenticated attacker to perform an account takeover via network access, affecting several Windows clients and VDI branches. The company also fixed three privilege-escalation bugs across Zoom Workplace, Zoom Rooms, and related VDI plugins. Security experts warned the flaw is highly dangerous due to low complexity and no user interaction required, while praising Zoom for discovering and patching the issues.
read more →

Zoom issues urgent Windows security updates

🔒 Zoom released updates to patch a critical account-takeover vulnerability affecting several Windows clients and SDKs. The flaw, tracked as CVE-2026-53412 (CVSS 9.8), impacts Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows and could allow unauthenticated remote takeover. The advisory also fixes three high-severity escalation-of-privilege and TOCTOU bugs in various Workplace, VDI, plugin, Rooms, and Remote Control components; no active exploitation has been reported.
read more →

New Windows Bind Link techniques can evade EDR

🛡️ Bitdefender researchers disclosed three techniques abusing Windows Bind Links — File-Binding, Process-Binding, and Silo-Binding — that let attackers with admin rights redirect file paths in memory so security tools see benign files while malicious payloads run. The methods exploit the bindflt.sys driver and can blind EDRs and bypass defenses like AMSI and AppLocker, though Microsoft assessed the issues as low severity because admin privileges are required.
read more →

Microsoft ships record July Patch Tuesday fixes

🔒 Microsoft released its largest Patch Tuesday ever, addressing 622 CVEs including two actively exploited elevation-of-privilege flaws in on‑premises SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). The SharePoint bug allows unauthenticated network privilege escalation and is tied to incident responders at Mandiant and Google's FLARE; admins should patch immediately and consider enabling AMSI Full Mode. The AD FS bug permits local privilege escalation for authenticated users and was credited to Microsoft DART. A third disclosed BitLocker bypass (CVE-2026-50661) requires physical access and is lower priority. The update also finalizes Kerberos RC4 hardening, risking authentication breaks for service accounts still using RC4 unless audited and rotated first. Microsoft says AI tooling increased bug discovery, and the scale of fixes means organizations should prioritize by exploitation status rather than CVSS score.
read more →

Ryuk Operative Pleads Guilty, Faces 15 Years

🛡️ Karen Serobovich Vardanyan, 34, pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware after being extradited from Kyiv. She provided initial access to corporate networks and helped deploy ransomware between November 2019 and April 2020, leading to large ransom payments including a Michigan firm that paid 200 BTC. Prosecutors say the group collected about 1,610 BTC (≈$15 million then).
read more →

OpenClaw flaws enable host escape and credential theft

🔒 Three critical vulnerabilities in the OpenClaw personal AI assistant could allow credential theft, privilege escalation, and arbitrary host code execution if exploited. The flaws include two command injection bugs (GHSA-hjr6-g723-hmfm and GHSA-9969-8g9h-rxwm) and a path traversal/link-following issue (GHSA-575v-8hfq-m3mc). OpenClaw 2026.6.6 patches these issues; operators are advised to harden configurations and limit tool/channel allowlists.
read more →

Ransomware family exploits signed drivers to evade

🛡️ Symantec details how the GodDamn ransomware, a 2026 evolution of the Hyadina family, uses Microsoft-signed malicious drivers to disable endpoint defenses. The attackers deployed AnyDesk covertly, dropped a signed kernel driver named PoisonX disguised as a Symantec product, and used credential-stealing tools like Mimikatz to escalate access. After weakening defenses and harvesting credentials, the threat actors executed file encryption and displayed a ransom note, demonstrating continued tactical evolution.
read more →

Microsoft patches RoguePlanet Defender flaw

🛡️ Microsoft released a security update addressing a privilege escalation bug in the Microsoft Malware Protection Engine, tracked as CVE-2026-50656. The issue, dubbed RoguePlanet, is a race condition that can allow an attacker to spawn a SYSTEM-level shell to run arbitrary code. The fix is included in engine version 1.1.26060.3008 and includes defense-in-depth hardening.
read more →

Microsoft patches Defender RoguePlanet zero‑day

🛡️ Microsoft released a Malware Protection Engine update to fix a Defender zero-day tracked as CVE-2026-50656, dubbed "RoguePlanet." The vulnerability, disclosed by researcher "Nightmare Eclipse," allows spawning a SYSTEM command prompt via a Defender race condition and reportedly works on fully patched Windows 10 and 11 devices. Microsoft shipped version 1.1.26060.3008 to address the issue after confirming work on a patch on June 16.
read more →

15-Year-Old Linux GhostLock Flaw Enables Root

🛡️ Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free that allows any logged-in user to gain root privileges on unpatched systems. The bug, present in mainstream distributions since 2011, requires only ordinary local threading calls and no network access. Nebula developed a 97% reliable exploit that also escapes containers and received $92,337 from Google's kernelCTF bounty. Patching is urgent, with early fixes having introduced a follow-up crash bug and distributions still rolling out the corrected kernel.
read more →

Critical Dialogflow CX 'Rogue Agent' code execution flaw

🛡️ A critical flaw in Google Dialogflow CX's Code Blocks could let an attacker with edit rights on one agent compromise other Code Block-enabled agents in the same Google Cloud project. Varonis named the issue Rogue Agent; it required the dialogflow.playbooks.update permission and thus implied a malicious insider or compromised developer account rather than an unauthenticated internet attacker. Google fixed the vulnerability after Varonis disclosed it via the VRP; there are no signs of exploitation.
read more →

Januscape Linux kernel flaw enables VM escape

🛡️ A 16-year-old Linux kernel vulnerability called Januscape (CVE-2026-53359) allows guest-to-host escapes via a use-after-free in the KVM/x86 shadow MMU emulation. Discovered and detailed by researcher Hyunwoo Kim and patched in June 2026, it affects both Intel and AMD architectures and was used in Google's kvmCTF program. Unpatched multi-tenant hosts, especially with world-writable /dev/kvm, risk host takeover or denial-of-service.
read more →

Januscape: 16-year KVM flaw allows guest-to-host escape

🛡️ A long-standing use-after-free bug in Linux's KVM shadow MMU, tracked as CVE-2026-53359 and dubbed Januscape, lets a guest VM corrupt host shadow-page state and can reliably panic hosts. The public PoC triggers host crashes; the researcher reported an unreleased exploit that achieves full host code execution on Intel and AMD. Fixes were merged June 19, 2026 and backported to stable kernels on July 4, 2026; hosts with nested virtualization should be patched or have nesting disabled.
read more →

LLM-Driven Ransomware JadePuffer Targets Langflow

🔒 Sysdig reports a novel ransomware campaign, dubbed JadePuffer, driven entirely by a large language model agent that exploited CVE-2025-3248 in an internet-facing Langflow instance. The automated attack conducted reconnaissance, credential harvesting, lateral movement, and destructive actions against production databases, encrypting and deleting Nacos configurations so they could not be recovered. Sysdig highlights automation of old vulnerabilities, agent narration that may aid detection, and the erosion of response time for defenders.
read more →