vulnerability

Tag

Cards List
#vulnerability

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

Lobsters Hottest · 2026-07-22 Cached

Qualys and Anthropic disclose CVE-2026-64600, a race condition in the Linux kernel's XFS filesystem that allows local privilege escalation to root, affecting over 16 million systems, with no kernel log output and survival across reboots.

0 favorites 0 likes
#vulnerability

Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)

Lobsters Hottest · 2026-07-22 Cached

A blog post detailing a local privilege escalation vulnerability (CVE-2026-50343) in the Windows Install Service on Windows 11, allowing a standard user to execute code as SYSTEM by exploiting a writable plugin map and a user-plantable COM server.

0 favorites 0 likes
#vulnerability

an AI agent got prompt-injected into moving $175K on-chain. first documented case of this actually happening

Reddit r/artificial · 2026-07-22

First documented case of an AI agent being prompt-injected via an NFT to execute unauthorized on-chain transactions, resulting in a $175K transfer. The attacker returned the funds, demonstrating the vulnerability of autonomous agents to instruction spoofing.

0 favorites 0 likes
#vulnerability

Using Fine-Tuned LLMs to Identify Indicators of Vulnerability in UK Police Incident Logs

arXiv cs.CL · 2026-07-22 Cached

This paper explores using fine-tuned LLMs to identify indicators of vulnerability (mental ill health, substance misuse, alcohol dependence, homelessness) in UK police incident logs, finding that while LLMs can produce meaningful prevalence estimates, they require careful methodological support and are not reliable for individual-level decisions.

0 favorites 0 likes
#vulnerability

@Dinosn: The Hidden CCS2 Attack Surface on EV Chargers

X AI KOLs Timeline · 2026-07-21 Cached

Security researchers found that XCharge C6 EV chargers expose SSH and Telnet services with default root:root credentials over the CCS2 charging interface, enabling attackers to gain full control by connecting a malicious EV.

0 favorites 0 likes
#vulnerability

Apple Fixes Hide My Email Vulnerability After 404 Media Coverage

Hacker News Top · 2026-07-21 Cached

Apple fixed a vulnerability in its Hide My Email feature that could reveal users' real email addresses after 404 Media reported on the issue, despite Apple knowing about it for over a year.

0 favorites 0 likes
#vulnerability

@aacle_: Everyone's obsessing over prompt injection hiding in PDFs and websites. Meanwhile the tool list itself — the thing ever…

X AI KOLs Timeline · 2026-07-21 Cached

A tweet and blog post highlight that the tool list itself is an attack surface: by controlling a tool's description, an attacker can hijack an AI agent's behavior without exploit code. This is part 2 of a series on MCP bug bounties.

0 favorites 0 likes
#vulnerability

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

Wired · 2026-07-21 Cached

Researchers at UC San Diego discovered a severe Bluetooth vulnerability in the KARR aftermarket car alarm, installed in over 2 million US vehicles, allowing attackers to unlock, track, or disable cars. A firmware patch has been released, but many owners are unaware the device is installed.

0 favorites 0 likes
#vulnerability

A Linux Kernel 0-day Journey - From a limited UAF to Physical Memory R/W

Lobsters Hottest · 2026-07-20 Cached

This article details the discovery and exploitation of a Linux kernel 0-day vulnerability in the network scheduler subsystem (red scheduler), turning a limited slab use-after-free into full physical memory read/write, ultimately achieving privilege escalation to root. The vulnerability existed for 2.5 years and was fixed in June 2026.

0 favorites 0 likes
#vulnerability

@Dinosn: Dnsmasq DNS Remote Heap Buffer Overflow

X AI KOLs Timeline · 2026-07-20 Cached

A heap buffer overflow vulnerability in Dnsmasq (CVE-2026-2291) allows remote code execution via a malicious upstream DNS server. The issue was introduced in version 2.73 and fixed in 2.92rel2 and 2.93.

0 favorites 0 likes
#vulnerability

7 Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors

Lobsters Hottest · 2026-07-20 Cached

Pillar Research found sandbox escape vulnerabilities in AI coding agents from Cursor, Codex, Gemini CLI, and Antigravity, revealing that these agents can write files that host components later trust, bypassing sandbox boundaries. The findings highlight the need for a new threat model for agentic security.

0 favorites 0 likes
#vulnerability

Fuzzing for fun - unauthenticated denial of service in snac2

Lobsters Hottest · 2026-07-20 Cached

This article describes using fuzzing to discover an unauthenticated denial-of-service vulnerability in snac2's JSON parser, allowing remote crashes via crafted inputs.

0 favorites 0 likes
#vulnerability

CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV

Hacker News Top · 2026-07-16 Cached

Fortinet FortiSandbox contains a critical unauthenticated OS command injection vulnerability (CVE-2026-25089) actively exploited in the wild, added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026.

0 favorites 0 likes
#vulnerability

10%+ of MCP servers leak credentials/PII through tool responses, not network calls - SAST/DAST can’t see it

Reddit r/AI_Agents · 2026-07-16

A security report reveals that over 10% of MCP servers leak credentials or personally identifiable information through tool responses, bypassing traditional SAST/DAST scanning.

0 favorites 0 likes
#vulnerability

Windows 0-day drops the same day Microsoft releases record number of patches

Ars Technica · 2026-07-15 Cached

A Windows 0-day vulnerability called LegacyHive allows non-admin users to escalate privileges by abusing how Windows loads user class hives, with Microsoft investigating and detection scripts available.

0 favorites 0 likes
#vulnerability

Nat Slipstreaming v2.0 allows an attacker to remotely access any TCP/UDP service

Hacker News Top · 2026-07-15 Cached

NAT Slipstreaming v2.0 is a browser-based attack that exploits ALG connection tracking to remotely access any TCP/UDP service behind a victim's NAT, bypassing firewall restrictions.

0 favorites 0 likes
#vulnerability

@bdsqlsz: Breaking news: 64GB CMP 170HX NVIDIA GPU(a100 tensor core) has surfaced on China’s secondhand market for just $1,170. R…

X AI KOLs Timeline · 2026-07-15 Cached

A 64GB CMP 170HX NVIDIA GPU with A100 tensor cores has appeared on China's secondhand market for $1,170, and a software-level vulnerability has successfully removed its computing power limit.

0 favorites 0 likes
#vulnerability

How I tricked Claude into leaking your deepest, darkest secrets

Simon Willison's Blog · 2026-07-15 Cached

A security researcher discovered a vulnerability in Claude's web_fetch tool that allowed data exfiltration by chaining through nested links, compromising user privacy. Anthropic has since fixed the issue.

0 favorites 0 likes
#vulnerability

I tricked Claude into leaking your deepest, darkest secrets

Hacker News Top · 2026-07-15 Cached

A security researcher demonstrates a method to trick Claude AI into exfiltrating user personal data from its memory system by encoding data in web fetch URLs, exploiting the combination of memory retrieval and web browsing capabilities.

0 favorites 0 likes
#vulnerability

TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

Hacker News Top · 2026-07-15 Cached

A vulnerability in Tailscale SSH allowed users to gain root access by using a crafted username with a leading dash. The issue is fixed in version 1.98.9.

0 favorites 0 likes
← Previous
Next →
← Back to home

Submit Feedback