daily cyber × ai intelligence

index

July 9, 2026

A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro

34 sources 324 gathered 324 triaged 41 clustered 41 written

GhostLock, a stack use-after-free that has shipped in essentially every mainstream Linux distribution since 2011, tops today’s beat as part of a full browser-to-kernel exploit chain. The AI coding-agent attack surface also widened sharply, with symlink RCE, prompt-injection repo leaks, and hallucination-squatting all landing in the same week.

Vulnerabilities & Exploits

  • GhostLock (CVE-2026-43499), disclosed by Nebula Security, is a 15-year-old Linux kernel stack use-after-free that lets any logged-in user gain full root and escape containers on unpatched systems — no special permissions, settings, or network access required. It ships as “IonStack part II,” the kernel half of a full browser-to-kernel chain that pairs a Firefox 0-day (pre-151.0.2) with the kernel bug for a click-to-compromise Android 17 root demo. nebusec.ai, The Hacker News
  • DirtySlide is a fresh macOS local privilege escalation to root stemming from a single missing bounds check, with a public write-up and PoC. gracecondition.github.io
  • Git hash-chain malleability research shows that GitHub’s “Verified” badge is not the guarantee reviewers assume: given any signed commit, an attacker without the signing key can mint a second commit with identical files, author, and date, a valid signature, and a different hash that GitHub still marks Verified — a supply-chain integrity problem for anyone pinning by commit hash. The Hacker News, arXiv
  • Esri ArcGIS Server (CVE-2026-9181), a critical pre-auth path traversal through a crafted itemName parameter, lets remote attackers read sensitive files on versions up to 12.0; Horizon3 published attack analysis. horizon3.ai
  • Tenda firmware backdoor (CVE-2026-11405) grants unauthenticated attackers access to the router web management interface — and remains unpatched. SecurityWeek
  • CISA added actively-exploited Adobe ColdFusion (CVE-2026-48282), Langflow, and two Joomla extension flaws to its KEV catalog, giving federal agencies a Friday deadline. The Langflow auth bypass is the same flaw the LLM-driven JADEPUFFER operator exploited last week. BleepingComputer, The Hacker News
  • Ubiquiti shipped patches for seven critical flaws across UniFi Connect, Talk, Access, Protect, and OS, including a CVSS 10.0 access-control bug (CVE-2026-50746) and command-injection issues; no exploitation reported yet. BleepingComputer, NCSC-NL

AI & Model Security

  • GhostApproval — Wiz found symlink flaws in six AI coding assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) that let a booby-trapped repo turn an approved edit to a harmless-looking file into a write to a sensitive one, yielding RCE via a misleading confirmation dialog. Several vendors have shipped urgent patches. The Register, The Hacker News
  • “Friendly Fire” — an AI Now Institute PoC shows that asking Claude Code or OpenAI Codex in autonomous/auto-approve mode to scan untrusted open-source for bugs can instead cause the agent to execute the attacker’s code on the analyst’s own machine. The Hacker News
  • HalluSquatting weaponizes model hallucination: researchers map the plausible-but-fake package names an assistant reliably invents, register them first, and wait for the agent to fetch the trap — delivering botnet malware to the developer. The Hacker News
  • GitHub Copilot guardrail bypass — Kumar and Maple show a request Copilot refuses in chat can be produced anyway if broken into small, ordinary-looking steps inside the code editor, across models routed through Copilot, Claude, and Gemini. The Hacker News
  • Sophos telemetry shows benign AI coding agents (Claude Code, Cursor, Codex) routinely tripping behavioral EDR rules written for human intruders — decrypting browser credentials, enumerating the Windows credential store, etc. A real detection-engineering problem: agent activity and attacker activity look identical to the engine. The Hacker News
  • Google Dialogflow CX “Rogue Agent” — a now-fixed flaw could silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. SecurityWeek
  • Cracking firmware with Claude — Bishop Fox walks through an AI agent reverse-engineering SonicWall firmware with minimal human guidance, reconstructing cryptographic keys and tuning decryption parameters — senior-level analysis driven mostly by supervisory judgment rather than prior expertise. Bishop Fox
  • Mycelium Framework — Flare reports the first-observed “AI-as-a-Service” botnet advertised underground, marketing cross-platform execution and encrypted C2 with an integrated AI layer. Flare via blackorbird
  • Five Eyes guidance warns that AI is lowering the barrier to entry for less-skilled attackers, arguing that disciplined traditional security fundamentals remain the effective mitigation. Schneier on Security

Threat Activity

  • Entra passkey enrollment vishing — a threat actor is voice-calling Microsoft 365 users across multiple sectors with fake security requests urging them to enroll a new Entra ID passkey, establishing durable attacker-controlled auth. BleepingComputer
  • China-linked cluster is exploiting patched Roundcube flaws (incl. CVE-2024-42009) at physics and engineering departments of U.S. and Canadian universities to steal credentials and deploy backdoors. BleepingComputer
  • UAT-7810 (Cisco Talos), the actor behind the LapDogs ORB network, is expanding its SOHO-router relay infrastructure with new LONGLEASH, DogLeash, and JarLeash backdoors. The Hacker News, SecurityWeek
  • ClickFix operators expanded: Unit 42 tracks a macOS variant installing a LaunchAgent backdoor via affiliate/cloaking redirects, and Elastic details SCMBANKER (REF6045), an AI-assisted PowerShell toolkit hitting Mexican banking customers via fake CAPTCHA pages. Unit 42, Elastic Security Labs
  • RedWing — a Telegram-rented Android MaaS (a new Oblivion variant) packages device takeover, banking-credential theft, and OTP interception for low-skill operators. The Hacker News, Security Affairs
  • Lurking Lizard — Infoblox links a years-long malicious residential-proxy business (230+ lookalike domains, WireVPN and trojanized installers) to a Chinese threat actor recruiting victim devices as proxy nodes. The Hacker News, CyberInsider
  • StealC via GitHub spam — vx-underground flagged an automated campaign posting fake “patch” comments on open GitHub issues; the Go binary resolves C2 through a Telegram channel description acting as a bootleg DNS resolver, complicating takedowns. vx-underground
  • Trojanized LetsVPN installers deliver GoodPersonRAT, granting full remote control while masquerading as legit VPN software and targeting Telegram Desktop data. CyberInsider
  • EtherRAT — attackers phish, then impersonate IT support over Microsoft Teams voice calls to talk employees into installing the RAT. SC Media
  • Ghost phishing / EvilTokens keeps its malicious page encrypted until it decrypts inside the victim’s browser, evading URL reputation checks in a US/EU campaign targeting Microsoft 365. The Hacker News
  • Vidar infostealer is hitting SMBs through malvertising for cracked/pirated software, bundling data theft with cryptomining. Dark Reading
  • The Gentlemen (Storm-2697) — Unit 42 identified a C-based ransomware variant tied to the crew, with a leak-site countdown-style ransom note. Unit 42

Threat Intelligence

  • CRPxO (a.k.a. CRPx0), a new data-extortion ransomware operation, has listed six victims — almost entirely healthcare providers in the US and one Chinese firm — and is recruiting affiliates with a 70% split and $333 access fee. FalconFeeds
  • Spanish National Police arrested a Palencia man, on an FBI tip, alleged to support pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR), Z-Pentest, and NoName057(16). The Record, BleepingComputer

Supply Chain

  • Fake Paysafe / Skrill / Neteller SDKs on npm and PyPI delivered stealer malware to developers and users of those payment platforms. BleepingComputer

Data Breaches

  • Accenture confirmed a breach after an actor advertised ~35 GB of stolen source code and other data; the firm says it contained and remediated the incident with no service impact. SecurityWeek
  • KDDI disclosed that attackers breached an email platform used by five Japanese ISPs, exposing email addresses and passwords for over 12 million people. BleepingComputer

New Tools & Releases

  • cve-2026-20896-gitea-poc — a checker for the Gitea Docker X-WEBAUTH-USER auth bypass now under active exploitation (6,200+ exposed instances); useful for validating your own exposure. GitHub
  • ida-nativeaot — an IDA helper for analyzing .NET NativeAOT binaries, released alongside Check Point’s Cavern Manticore research and handy for reversing modern AOT-compiled malware. GitHub

Industry & Policy

  • The European Commission published an AI-and-cybersecurity action plan built on nine measures spanning model evaluation, frontier-model access, and vulnerability management, driven by concern that EU access to frontier models depends entirely on foreign providers. The Record
  • xAI shipped Grok 4.5, trailing Fable 5 and GPT-5.5 on coding benchmarks but at roughly one-tenth the cost (~$1.51 vs $17.32 per task on CursorBench), with EU availability expected mid-July. The Decoder
  • OpenAI is launching GPT-5.6 after the U.S. government lifted a release ban following added testing, and rolled out GPT-Live, a full-duplex voice model that listens and speaks simultaneously while offloading complex queries to GPT-5.5. The Decoder