Tag: linux
-
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet.XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing’s image tier, not on one bad machine.…
-
RefluXFS: Kernel-Bug verleiht auf Millionen von Linux-Systemen Root-Zugriff
Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. First seen on golem.de Jump to article: www.golem.de/news/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux-2607-211245.html
-
RefluXFS: Gefährlicher Kernel-Bug verleiht Root-Zugriff unter Linux
Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. First seen on golem.de Jump to article: www.golem.de/news/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux-2607-211245.html
-
RefluXFS: Kritische Linux-Kernel-Lücke verschafft lokalen Nutzern Root-Rechte
Tags: linuxAdministratoren sollten deshalb zeitnah einen korrigierten Kernel der jeweiligen Linux-Distribution installieren und das System anschließend vollständig neu starten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/refluxfs-kritische-linux-kernel-luecke-verschafft-lokalen-nutzern-root-rechte/a45862/
-
Unprivilegierte lokale Nutzer erlangen Root-Rechte durch Linux-Kernel-Schwachstelle ‘RefluXFS”
Da in Unternehmen, Behörden und KRITIS-Umgebungen im DACH-Raum Linux und davon abgeleitete Distributionen in großem Umfang im Einsatz haben vielfach in Standardkonfiguration mit XFS-Dateisystem , betrifft die Linux-Kernel-Schwachstelle ‘RefluXFS” (CVE-2026-64600) einen erheblichen Teil der hiesigen Linux-Serverlandschaft unmittelbar. Qualys Threat Research Unit (TRU) veröffentlicht Details Patchen und Neustart sind die einzigen verlässliche Gegenmaßnahmen. […] First seen…
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of…
-
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/
-
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation.The company demonstrated…
-
Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access
A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reportedly existed since the release of Linux kernel version 4.1 in 2017.…
-
Linux kernel security faces challenge with surge in CVEs
First seen on scworld.com Jump to article: www.scworld.com/brief/linux-kernel-security-faces-challenge-with-surge-in-cves
-
Ubuntu: Root-Lücke in snapd gefährdet unzählige Linux-Systeme
Tags: linuxZwei Race Conditions in snap-confine verleihen Angreifern unter Linux Root-Zugriff. Mehrere Ubuntu-Versionen sind per Default anfällig. First seen on golem.de Jump to article: www.golem.de/news/ubuntu-root-luecke-in-snapd-gefaehrdet-unzaehlige-linux-systeme-2607-211151.html
-
Linux Kernel Team Publishes 440 CVE Security Advisories Within 24 Hours
The Linux kernel security team published approximately 440,440 CVE advisories over 24 hours, reflecting a significant release of vulnerability records linked to fixes already incorporated into the upstream kernel tree. These notices were distributed through the linux-cve-announce mailing list between July 19 and July 20, 2026, and cover a wide range of kernel subsystems, including…
-
Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools organized into modules that cover asynchronous I/O operations, BPF inspection and manipulation, EDR evasion techniques,…
-
Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools
Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value rather than dismissed outright. His comments were part of a discussion on the Linux Media…
-
OnionHop: Tool leitet Daten durch das Tor-Netzwerk
OnionHop für Linux, macOS und Windows ist ein Routing-Manager, der die Daten einzelner oder aller Programme über das Tor-Netzwerk leitet. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/datenschutz/onionhop-tool-leitet-daten-durch-das-tor-netzwerk-331520.html
-
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.”An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware,” First seen on…
-
No one knows how many old shims can still bypass UEFI Secure Boot
The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/eset-uefi-secure-boot-bypass/
-
Debian 13.6 Released With Security Updates for Linux, Apache, Curl, QEMU, and More
The Debian Project has released Debian 13.6, the sixth point update for its stable Debian 13 “trixie” distribution. This update, released on July 11, 2026, includes a collection of security fixes, critical bug corrections, and updated installation images. It does not introduce a new version of Debian; existing systems can be upgraded to the latest…
-
Schutz von Open Source Software in KRITIS – Linux Foundation startet Brancheninitiative Akrites
First seen on security-insider.de Jump to article: www.security-insider.de/linux-foundation-startet-brancheninitiative-akrites-a-13bea32919c906bc6aa25fbc37695cab/
-
Intel- und AMD-x86-Systeme betroffen – 16 Jahre alte Linux-KVM-Schwachstelle ermöglicht Ausbruch aus Gast-VMs
First seen on security-insider.de Jump to article: www.security-insider.de/linux-kvm-januscape-cve-2026-53359-vm-ausbruch-intel-amd-a-3dd0774374c1a8ddbc580e938b24384a/
-
HP Linux Imaging and Printing Software Flaw Enables Privilege Escalation Attacks
A critical vulnerability has been discovered in HP Linux Imaging and Printing Software (HPLIP), which exposes Linux systems to potential privilege escalation and remote code execution attacks. This vulnerability, tracked as CVE-2026-14544, has a CVSS v3 score of 9.8, indicating maximum severity due to its potential for network exploitation, low attack complexity, and lack of…
-
Google pays $250k for Linux vulnerability allowing guest VM escapes
Both vulnerabilities allow untrusted users to gain root privileges. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week/
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
15-Year-Old GhostLock Linux Kernel Vulnerability Enables Root Access and Container Escape
A critical vulnerability in the Linux kernel, known as “GhostLock” (CVE-2026-43499), has been disclosed by researchers at Nebula Security. This vulnerability, which has existed for 15 years, allows for reliable privilege escalation and container escape across nearly all Linux distributions. The issue dates back to Linux kernel version 2.6.39, released in 2011, and remained undetected…
-
Januscape Flaw in Linux KVM’s MMU Code Enables VM Escape on Intel and AMD
A newly disclosed Linux kernel vulnerability, CVE-2026-53359, dubbed Januscape, has exposed a critical weakness in the Linux Kernel-based Virtual Machine (KVM) hypervisor. The flaw resides in the shadow MMU code and allows attackers to escape a virtual machine (VM), compromise the underlying host, and potentially execute arbitrary code. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cve-2026-53359-januscape/
-
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network…
-
Linux bug dormant for 16 years can cause a VM escape
Tags: linuxFirst seen on scworld.com Jump to article: www.scworld.com/news/16-year-old-linux-bug-can-cause-a-vm-escape
-
New QuimaRAT malware targets Windows, Linux, and macOS via MaaS model
First seen on scworld.com Jump to article: www.scworld.com/brief/new-quimarat-malware-targets-windows-linux-and-macos-via-maas-model
-
Januscape Linux VM Escape Flaw Affects Intel and AMD Systems
Januscape (CVE-2026-53359) enables guest-to-host VM escape in Linux KVM on Intel and AMD systems. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/januscape-linux-vm-escape-flaw-affects-intel-and-amd-systems/
-
New Januscape Linux flaw allows VM escape on Intel, AMD devices
A 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/

