Topic: local privilege escalation
-
Linux Kernel 0-Day Flaw Affects All Major Distros Since 2017
A critical Linux kernel zero-day vulnerability (CVE-2026-31431, "Copy Fail") allows any unprivileged local user to gain root access on nearly all major Linux distributions shipped since 2017 via a 732-byte Python script that exploits a logic bug in the authencesn cryptographic template. The flaw,...
Read More » -
Microsoft Defender Flaws Exploited in Active Attacks (CVE-2026-41091, CVE-2026-45498)
Attackers are actively exploiting two Microsoft Defender vulnerabilities: CVE-2026-41091 (a local privilege elevation bug that can grant SYSTEM privileges) and CVE-2026-45498 (a denial-of-service flaw), with both added to CISA's Known Exploited Vulnerabilities catalog. Microsoft has released patc...
Read More » -
New Linux Exploit Grants Hackers Root Access to Millions of Computers
A critical Linux privilege escalation vulnerability, CVE-2026-31431 (CopyFail), has been publicly exploited, allowing attackers to gain root access on virtually all Linux distributions using a single, unmodified script. The flaw is a pure logic error in the kernel's crypto API, making it highly r...
Read More » -
Severe Linux threat catches world off guard
A critical Linux vulnerability, CVE-2026-31431 (CopyFail), allows any unprivileged user to gain full root access on nearly all major distributions, with a working exploit now publicly released. The exploit consists of a single Python script that works on Ubuntu 22.04, Amazon Linux 2023, SUSE 15.6...
Read More » -
New Windows Zero-Day ‘RoguePlanet’ Exploit Goes Live
A newly disclosed Windows zero-day exploit called ‘RoguePlanet’ targets a race condition in Microsoft Defender, enabling local privilege escalation to SYSTEM-level access. The exploit allows an attacker with limited privileges to execute code with elevated permissions, bypassing security boundari...
Read More » -
Mythos Preview Used to Create First Public macOS M5 Kernel Exploit
Security researchers successfully compromised Apple's M5 chip via a macOS kernel memory corruption attack, bypassing the company's advanced Memory Integrity Enforcement (MIE) hardware protection to achieve full root shell access from an unprivileged local user account. The exploit was developed i...
Read More »