July 9, 2026
A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
34 sources → 324 gathered → 324 triaged → 41 clustered → 41 written
GhostLock, a stack use-after-free that has shipped in essentially every mainstream Linux distribution since 2011, tops today’s beat as part of a full browser-to-kernel exploit chain. The AI coding-agent attack surface also widened sharply, with symlink RCE, prompt-injection repo leaks, and hallucination-squatting all landing in the same week.
Vulnerabilities & Exploits
- GhostLock (CVE-2026-43499), disclosed by Nebula Security, is a 15-year-old Linux kernel stack use-after-free that lets any logged-in user gain full root and escape containers on unpatched systems — no special permissions, settings, or network access required. It ships as “IonStack part II,” the kernel half of a full browser-to-kernel chain that pairs a Firefox 0-day (pre-151.0.2) with the kernel bug for a click-to-compromise Android 17 root demo. nebusec.ai, The Hacker News
- DirtySlide is a fresh macOS local privilege escalation to root stemming from a single missing bounds check, with a public write-up and PoC. gracecondition.github.io
- Git hash-chain malleability research shows that GitHub’s “Verified” badge is not the guarantee reviewers assume: given any signed commit, an attacker without the signing key can mint a second commit with identical files, author, and date, a valid signature, and a different hash that GitHub still marks Verified — a supply-chain integrity problem for anyone pinning by commit hash. The Hacker News, arXiv
- Esri ArcGIS Server (CVE-2026-9181), a critical pre-auth path traversal through a crafted
itemNameparameter, lets remote attackers read sensitive files on versions up to 12.0; Horizon3 published attack analysis. horizon3.ai - Tenda firmware backdoor (CVE-2026-11405) grants unauthenticated attackers access to the router web management interface — and remains unpatched. SecurityWeek
- CISA added actively-exploited Adobe ColdFusion (CVE-2026-48282), Langflow, and two Joomla extension flaws to its KEV catalog, giving federal agencies a Friday deadline. The Langflow auth bypass is the same flaw the LLM-driven JADEPUFFER operator exploited last week. BleepingComputer, The Hacker News
- Ubiquiti shipped patches for seven critical flaws across UniFi Connect, Talk, Access, Protect, and OS, including a CVSS 10.0 access-control bug (CVE-2026-50746) and command-injection issues; no exploitation reported yet. BleepingComputer, NCSC-NL
AI & Model Security
- GhostApproval — Wiz found symlink flaws in six AI coding assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) that let a booby-trapped repo turn an approved edit to a harmless-looking file into a write to a sensitive one, yielding RCE via a misleading confirmation dialog. Several vendors have shipped urgent patches. The Register, The Hacker News
- “Friendly Fire” — an AI Now Institute PoC shows that asking Claude Code or OpenAI Codex in autonomous/auto-approve mode to scan untrusted open-source for bugs can instead cause the agent to execute the attacker’s code on the analyst’s own machine. The Hacker News
- HalluSquatting weaponizes model hallucination: researchers map the plausible-but-fake package names an assistant reliably invents, register them first, and wait for the agent to fetch the trap — delivering botnet malware to the developer. The Hacker News
- GitHub Copilot guardrail bypass — Kumar and Maple show a request Copilot refuses in chat can be produced anyway if broken into small, ordinary-looking steps inside the code editor, across models routed through Copilot, Claude, and Gemini. The Hacker News
- Sophos telemetry shows benign AI coding agents (Claude Code, Cursor, Codex) routinely tripping behavioral EDR rules written for human intruders — decrypting browser credentials, enumerating the Windows credential store, etc. A real detection-engineering problem: agent activity and attacker activity look identical to the engine. The Hacker News
- Google Dialogflow CX “Rogue Agent” — a now-fixed flaw could silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. SecurityWeek
- Cracking firmware with Claude — Bishop Fox walks through an AI agent reverse-engineering SonicWall firmware with minimal human guidance, reconstructing cryptographic keys and tuning decryption parameters — senior-level analysis driven mostly by supervisory judgment rather than prior expertise. Bishop Fox
- Mycelium Framework — Flare reports the first-observed “AI-as-a-Service” botnet advertised underground, marketing cross-platform execution and encrypted C2 with an integrated AI layer. Flare via blackorbird
- Five Eyes guidance warns that AI is lowering the barrier to entry for less-skilled attackers, arguing that disciplined traditional security fundamentals remain the effective mitigation. Schneier on Security
Threat Activity
- Entra passkey enrollment vishing — a threat actor is voice-calling Microsoft 365 users across multiple sectors with fake security requests urging them to enroll a new Entra ID passkey, establishing durable attacker-controlled auth. BleepingComputer
- China-linked cluster is exploiting patched Roundcube flaws (incl. CVE-2024-42009) at physics and engineering departments of U.S. and Canadian universities to steal credentials and deploy backdoors. BleepingComputer
- UAT-7810 (Cisco Talos), the actor behind the LapDogs ORB network, is expanding its SOHO-router relay infrastructure with new LONGLEASH, DogLeash, and JarLeash backdoors. The Hacker News, SecurityWeek
- ClickFix operators expanded: Unit 42 tracks a macOS variant installing a LaunchAgent backdoor via affiliate/cloaking redirects, and Elastic details SCMBANKER (REF6045), an AI-assisted PowerShell toolkit hitting Mexican banking customers via fake CAPTCHA pages. Unit 42, Elastic Security Labs
- RedWing — a Telegram-rented Android MaaS (a new Oblivion variant) packages device takeover, banking-credential theft, and OTP interception for low-skill operators. The Hacker News, Security Affairs
- Lurking Lizard — Infoblox links a years-long malicious residential-proxy business (230+ lookalike domains, WireVPN and trojanized installers) to a Chinese threat actor recruiting victim devices as proxy nodes. The Hacker News, CyberInsider
- StealC via GitHub spam — vx-underground flagged an automated campaign posting fake “patch” comments on open GitHub issues; the Go binary resolves C2 through a Telegram channel description acting as a bootleg DNS resolver, complicating takedowns. vx-underground
- Trojanized LetsVPN installers deliver GoodPersonRAT, granting full remote control while masquerading as legit VPN software and targeting Telegram Desktop data. CyberInsider
- EtherRAT — attackers phish, then impersonate IT support over Microsoft Teams voice calls to talk employees into installing the RAT. SC Media
- Ghost phishing / EvilTokens keeps its malicious page encrypted until it decrypts inside the victim’s browser, evading URL reputation checks in a US/EU campaign targeting Microsoft 365. The Hacker News
- Vidar infostealer is hitting SMBs through malvertising for cracked/pirated software, bundling data theft with cryptomining. Dark Reading
- The Gentlemen (Storm-2697) — Unit 42 identified a C-based ransomware variant tied to the crew, with a leak-site countdown-style ransom note. Unit 42
Threat Intelligence
- CRPxO (a.k.a. CRPx0), a new data-extortion ransomware operation, has listed six victims — almost entirely healthcare providers in the US and one Chinese firm — and is recruiting affiliates with a 70% split and $333 access fee. FalconFeeds
- Spanish National Police arrested a Palencia man, on an FBI tip, alleged to support pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR), Z-Pentest, and NoName057(16). The Record, BleepingComputer
Supply Chain
- Fake Paysafe / Skrill / Neteller SDKs on npm and PyPI delivered stealer malware to developers and users of those payment platforms. BleepingComputer
Data Breaches
- Accenture confirmed a breach after an actor advertised ~35 GB of stolen source code and other data; the firm says it contained and remediated the incident with no service impact. SecurityWeek
- KDDI disclosed that attackers breached an email platform used by five Japanese ISPs, exposing email addresses and passwords for over 12 million people. BleepingComputer
New Tools & Releases
- cve-2026-20896-gitea-poc — a checker for the Gitea Docker
X-WEBAUTH-USERauth bypass now under active exploitation (6,200+ exposed instances); useful for validating your own exposure. GitHub - ida-nativeaot — an IDA helper for analyzing .NET NativeAOT binaries, released alongside Check Point’s Cavern Manticore research and handy for reversing modern AOT-compiled malware. GitHub
Industry & Policy
- The European Commission published an AI-and-cybersecurity action plan built on nine measures spanning model evaluation, frontier-model access, and vulnerability management, driven by concern that EU access to frontier models depends entirely on foreign providers. The Record
- xAI shipped Grok 4.5, trailing Fable 5 and GPT-5.5 on coding benchmarks but at roughly one-tenth the cost (~$1.51 vs $17.32 per task on CursorBench), with EU availability expected mid-July. The Decoder
- OpenAI is launching GPT-5.6 after the U.S. government lifted a release ban following added testing, and rolled out GPT-Live, a full-duplex voice model that listens and speaks simultaneously while offloading complex queries to GPT-5.5. The Decoder
Topics
Vendors
Threat actors
CVEs