Public Open vSwitch Exploit Gives Local Linux Users Root Access
OVSwrap exploits a 16-bit nested-action limit in the Linux kernel, leaving defenders to verify both the running fix and the earlier exposure window.
Reader edition
OVSwrap exploits a 16-bit nested-action limit in the Linux kernel, leaving defenders to verify both the running fix and the earlier exposure window.
A Microsoft case study traces mshta execution to one isolated QNET host and shows which workstations qualify for the preview action.
A remote SCTP peer can trigger the kernel flaw, while Tencent separately demonstrated local privilege escalation and container escape. Defenders need both reachability and running-kernel checks.
Cisco's August IOS XE hardening release fixes seven vulnerability classes across five reviewed trains; affected devices need an upgrade.
An automated npm campaign uses hundreds of disposable packages to launch detached native malware, with DNS TXT records as a fallback delivery channel.
WordPress 7.0.3 fixes a pre-auth login-page XSS that can turn administrator interaction with a malicious site into PHP execution.
Remus uses an Ethereum smart contract to resolve changing command infrastructure before stealing browser sessions, credentials, and wallet data.
Code in a signed-in Windows session can invoke a TPM-backed Windows Hello for Business key, authenticate without a device identity claim, and create a path to durable Entra access.
BINDCLOAK collects Windows user and process tokens, duplicates them, and starts modular malware components inside more privileged security contexts.
SpecterOps shows how relayed WSUS machine-account access can forge targeted updates and bypass payload signature checks when SUSDB runs on a separate SQL Server.
CISA confirms exploitation of a TeamCity flaw that lets an unauthenticated network attacker run commands as the server process, putting secrets and build integrity at risk.
Langflow, N-central, and Tomcat flaws entered CISA's exploited catalog. One gives unauthenticated callers Python execution by default.
A targeted npm cluster split its downloader across ordinary-looking modules, then escaped Node.js vm isolation to install a cross-platform RAT on developer systems using Alibaba tools.