Tag: privilege escalation

Attackers are actively exploiting WordPress CVE-2026-87902, a critical vulnerability that could enable remote code execution. Administrators are advised to update affected versions.
Security researchers have found the third-party.com placeholder domain serving ClickFix malware lures, affecting users through fake verification pages and malicious commands.

Researchers Reveal GPUThor Rowhammer Technique Affecting NVIDIA GDDR6 GPUs

Researchers have disclosed GPUThor, a new Rowhammer attack that bypasses ECC protections on select NVIDIA GDDR6 GPUs, enabling denial of service and host privilege escalation under specific conditions.

Researchers Reveal Unpatched Unisoc Android Kernel Exploit Through VoLTE Video Calls

Security researchers have disclosed a two stage exploit chain affecting Unisoc chipsets that can achieve Android kernel access through VoLTE video calls with no vendor patch currently available.

Microsoft Defender ShieldBreak Zero Day Demonstrates RoguePlanet Patch Bypass

A security researcher has released a proof of concept for ShieldBreak, a new Microsoft Defender zero day that reportedly bypasses the RoguePlanet patch and enables SYSTEM level privilege escalation.

Cybersecurity Next Insider Threat May Be the Agent You Authorised

Explore how AI agents are creating new cybersecurity risks by exploiting legitimate credentials, infrastructure, and enterprise tools, prompting organizations to rethink security, governance, and AI oversight.

Critical Linux Kernel Open vSwitch Vulnerability Allows Local Privilege Escalation

A newly disclosed Linux kernel vulnerability tracked as CVE 2026 64531 allows local users to gain root privileges through Open vSwitch. Security updates are available for affected kernel versions.

DirtyClone Linux Kernel Flaw Allows Local Users To Gain Root Access Through Cloned Packets

Researchers have disclosed DirtyClone, a Linux kernel vulnerability tracked as CVE 2026 43503 that enables local privilege escalation by corrupting cached memory through cloned network packets.

CISA Adds LiteSpeed CPanel Plugin Vulnerability To Known Exploited Vulnerabilities Catalog

CISA adds CVE 2026 54420 affecting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities catalog, warning of root privilege escalation risks on shared hosting servers.

Linux Kernel Vulnerability CVE 2026 23111 Enables Local Root Access As Public Exploits Emerge

Security researchers have published public exploits for Linux kernel vulnerability CVE 2026 23111, allowing local privilege escalation to root and container escape on affected systems.

Google Releases June 2026 Android Security Update Fixing 124 Vulnerabilities

Google has released its June 2026 Android security update addressing 124 vulnerabilities, including an actively exploited high severity flaw affecting Android 14, 15, and 16 devices.

Researchers Examine BYOVD Risks Through Vulnerable Windows Drivers Without Hardware Dependencies

New cybersecurity research highlights how vulnerable Windows kernel mode drivers may remain exploitable without dedicated hardware, raising concerns around BYOVD attacks and endpoint security risks.

Windows Zero Days Expose BitLocker Bypasses And CTFMON Privilege Escalation Risks

Security researchers have disclosed new Windows zero day vulnerabilities affecting BitLocker and CTFMON, exposing privilege escalation and encryption bypass risks across Windows 11 and Windows Server systems.

Linux Kernel Dirty Frag Vulnerability Enables Root Access Across Major Linux Distributions

Dirty Frag Linux kernel vulnerability enables local privilege escalation to root across major distributions including Ubuntu, RHEL, Fedora, and CentOS, with active exploitation risk.

Recent articles

spot_img