Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
This ThreatsDay roundup covers ransomware phishing campaigns, sandbox escapes, Apple email vulnerabilities, Linux kernel privilege escalation flaws, AI compute hijacking, and large scale malware operations affecting enterprise and consumer systems worldwide.
This week's cybersecurity roundup covers the DirtyClone Linux kernel vulnerability, AI focused malware techniques, Turla's STOCKSTAY backdoor, major malware disruptions, OpenAI updates, and emerging cyber threats.
Researchers have disclosed DirtyClone, a Linux kernel vulnerability tracked as CVE 2026 43503 that enables local privilege escalation by corrupting cached memory through cloned network packets.
A newly disclosed Linux kernel vulnerability tracked as CVE 2026 46331 allows local users to gain root privileges by poisoning cached binaries in memory, affecting multiple Linux distributions.
Security researchers have published public exploits for Linux kernel vulnerability CVE 2026 23111, allowing local privilege escalation to root and container escape on affected systems.
Dirty Frag Linux kernel vulnerability enables local privilege escalation to root across major distributions including Ubuntu, RHEL, Fedora, and CentOS, with active exploitation risk.