cve

Tag

Cards List
#cve

We eliminated 1,400 CVEs in NanoClaw's container images

Hacker News Top · 6d ago Cached

Echo and NanoClaw collaborated to eliminate 1,400 CVEs in NanoClaw's container images through scanning, patching, and backporting fixes. The article details their agentic hardening process, including safe version bumps and manual patch research.

0 favorites 0 likes
#cve

My Homelab Got Hacked - A Postmortem

Lobsters Hottest · 2026-08-12 Cached

A homelab owner details how their Forgejo instance was hacked via CVE-2026-60004, an RCE in Gitea, and shares the postmortem including mistakes made and exploit analysis.

0 favorites 0 likes
#cve

SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free

Lobsters Hottest · 2026-08-06 Cached

Tencent's Corvus AI research pipeline discovered SCTPhantom, an 18-year-old use-after-free vulnerability in Linux SCTP dynamic address reconfiguration (ASCONF) that enables local privilege escalation. The article details the discovery, root cause, exploitation chain, and upstream fix.

0 favorites 0 likes
#cve

@EpochAIResearch: Serious cyber vulnerability disclosures keep climbing. In July, 21 major tech organizations published ~2,500 high- and …

X AI KOLs Following · 2026-08-03 Cached

The tweet reports that serious cyber vulnerability disclosures are climbing sharply, with 21 major tech organizations publishing about 2,500 high- and critical-severity CVEs in July — roughly 5× the previous monthly record — following Anthropic's reveal that Claude Mythos Preview could autonomously find software vulnerabilities.

0 favorites 0 likes
#cve

Critical CVE issued for hallucinated SQLite vulnerability

Hacker News Top · 2026-08-03 Cached

JFrog researchers debunk a batch of SQLite CVEs published by a suspicious GitHub repo, finding the advisories are likely LLM-generated slop with non-existent code references and non-working PoCs, prompting NVD downgrades.

0 favorites 0 likes
#cve

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Ars Technica · 2026-07-30 Cached

Kremlin-linked hackers are actively exploiting a maximum-severity Microsoft Exchange Server flaw (CVE-2026-42897) to install the OWAReaper backdoor and steal credentials via half-click attacks, according to Proofpoint and NSA warnings.

0 favorites 0 likes
#cve

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

Lobsters Hottest · 2026-07-30 Cached

A critical remote code execution vulnerability (CVE-2026-66066) has been discovered in Ruby on Rails' Active Storage when using the default Vips image processor, affecting Rails 7.x and 8.x default configurations. Patches have been released and immediate upgrading is recommended.

0 favorites 0 likes
#cve

About the security content of macOS Tahoe 26.6

Hacker News Top · 2026-07-28 Cached

Apple released macOS Tahoe 26.6 with security fixes addressing multiple vulnerabilities including buffer overflows, authorization issues, sandbox escapes, and kernel memory corruption.

0 favorites 0 likes
#cve

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

Lobsters Hottest · 2026-07-22 Cached

Qualys and Anthropic disclose CVE-2026-64600, a race condition in the Linux kernel's XFS filesystem that allows local privilege escalation to root, affecting over 16 million systems, with no kernel log output and survival across reboots.

0 favorites 0 likes
#cve

Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)

Lobsters Hottest · 2026-07-22 Cached

A blog post detailing a local privilege escalation vulnerability (CVE-2026-50343) in the Windows Install Service on Windows 11, allowing a standard user to execute code as SYSTEM by exploiting a writable plugin map and a user-plantable COM server.

0 favorites 0 likes
#cve

git --end-of-options

Lobsters Hottest · 2026-07-21 Cached

An in-depth article about Git's `--end-of-options` flag, its history, and its importance in preventing argument injection vulnerabilities, including related CVEs.

0 favorites 0 likes
#cve

432 Linux kernel CVEs published in the last 24 hours

Lobsters Hottest · 2026-07-21 Cached

432 Linux kernel CVEs were published in the last 24 hours, indicating a significant batch of security vulnerabilities.

0 favorites 0 likes
#cve

CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV

Hacker News Top · 2026-07-16 Cached

Fortinet FortiSandbox contains a critical unauthenticated OS command injection vulnerability (CVE-2026-25089) actively exploited in the wild, added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026.

0 favorites 0 likes
#cve

GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years

Hacker News Top · 2026-07-10 Cached

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel stack use-after-free vulnerability affecting all distributions, allowing local privilege escalation and container escape. Detailed exploitation techniques are presented.

0 favorites 0 likes
#cve

Google pays $250K for Linux vulnerability allowing guest VM escapes

Ars Technica · 2026-07-08 Cached

Google paid a $250,000 bounty for a Linux KVM vulnerability (Januscape) that allows unprivileged guest VMs to escape and gain root access on the host, affecting cloud platforms using AMD or Intel processors.

0 favorites 0 likes
#cve

OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root (CVE-2026-57589)

Lobsters Hottest · 2026-07-08 Cached

A use-after-free vulnerability in OpenBSD through version 7.9 allows local attackers to escalate privileges to root. The flaw exists in sysv_sem.c and is identified as CVE-2026-57589.

0 favorites 0 likes
#cve

Tenda firmware (multiple versions) contains hidden authentication backdoor

Hacker News Top · 2026-07-08 Cached

Several versions of Tenda firmware contain an undocumented authentication backdoor (CVE-2026-11405) that grants administrative access to devices' web management interfaces without valid credentials. No patch is available; mitigation includes disabling remote management.

0 favorites 0 likes
#cve

Reporting a 19+ Years Hidden Linux Kernel Zero-Day for Google kernelCTF: CVE-2026-43456

Lobsters Hottest · 2026-07-07 Cached

A Linux kernel zero-day vulnerability (CVE-2026-43456) rooted in code from 2007 was discovered by Yuki Koike and Kota Toda, rewarded over $80,000 via Google's kernelCTF. The flaw, a type confusion in the net/bonding subsystem, allows reliable privilege escalation within one second.

0 favorites 0 likes
#cve

Januscape: Guest-to-Host Escape in KVM/x86 [CVE-2026-53359]

Hacker News Top · 2026-07-06 Cached

Januscape (CVE-2026-53359) is a use-after-free vulnerability in KVM/x86's shadow MMU that allows guest-to-host escape. Exploitation can lead to host kernel panic or code execution, affecting multi-tenant cloud environments.

0 favorites 0 likes
#cve

Bad Epoll (CVE-2026-46242)

Lobsters Hottest · 2026-07-04 Cached

Bad Epoll (CVE-2026-46242) is a race-condition use-after-free vulnerability in the Linux kernel's epoll subsystem that allows unprivileged users to escalate to root on both Linux and Android devices. It was reported by Jaeyoung Chung and was missed by Anthropic's Mythos AI.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback