Tagged: privilege escalation
Two Unknown Bugs Became Full Server Control Two unknown vulnerabilities turned the Zammad support system into an entry point with full control of the server. The Dutch Institute for Vulnerability Disclosure (DIVD) revealed the...
The boundary separating an individual client account from the entire server infrastructure within LiteSpeed Web Server Enterprise has proven alarmingly fragile. Recently, cPanel issued a stark warning regarding a critical privilege escalation vulnerability. Within...
The September Patch Tuesday became the largest security update release in Microsoft’s history. The company closed 966 vulnerabilities, two of which attackers had already wielded in real-world attacks. Previous records proved short-lived: in July,...
NVIDIA graphics cards employ specialized error-correcting memory capable of detecting and repairing random data corruption on its own. A new attack called GPUThor has demonstrated that even this protection can be circumvented, leading to...
A WordPress site administrator’s password could be changed by an attacker without ever logging in. A critical vulnerability in the popular Pods plugin allowed an unauthenticated outsider to bypass several layers of security checks...
A Microsoft Defender vulnerability patched just one month ago appears to be exploitable once again. A researcher operating under the alias MSNightmare has published ShieldBreak – a new proof-of-concept that claims to bypass Microsoft’s...
Users of anonymous operating systems typically rely on the guarantee that no single program running within the environment can betray their true identity. Sometimes, however, a solitary flaw in the Linux kernel is sufficient...
Unmasking the RefluXFS Vulnerability Impervious defense mechanisms in Linux offer no sanctuary when critical vulnerabilities manifest at the filesystem layer itself. The newly identified RefluXFS Linux vulnerability permits an unprivileged local actor to covertly...
Sandbox Isolation Compromised in Ubuntu Desktop An isolated application can inadvertently grant complete system control when architectural flaws emerge during sandbox initialization. The recently disclosed CVE-2026-8933 snap-confine vulnerability carries a CVSS 3.1 rating of...
Renowned cybersecurity researcher Nightmare-Eclipse has once again disclosed an unpatched local privilege escalation vulnerability affecting Windows 10 and 11. Orchestrated as a calculated act of retaliation, the researcher deliberately timed the public disclosure to...
An anti-cheat system designed to keep games fair has instead introduced a serious security gap. CERT/CC at Carnegie Mellon University disclosed three vulnerabilities in the GamersFirst Anti-Cheat driver. All three reside in the driver...
A critical vulnerability has been unearthed within the Linux kernel. This flaw empowers an ordinary user to escalate their privileges to root. It threatens not merely servers and workstations, but also Android devices. Designated...