daily cyber × ai intelligence

index

tagged

[CVE-2026-31431]

3 items

July 27, 2026

Two Live Exploits and a Bench of Fresh Offensive Tooling

GitLab default-config RCE received a full technical write-up detailing memory-corruption bugs in the Oj JSON parser, and a working NGINX RCE exploit (CVE-2026-42533) was open-sourced. A Linux kernel local privilege-escalation flaw (CVE-2026-31431) affects all mainstream distributions with no vendor patches yet, while a Fortinet FortiClient kernel driver vulnerability enables credential theft. Multiple new offensive tools emerged including Nocturne (Windows loader), NaX (C2 beacon), beignet (macOS shellcode), Waypoint (EDR-bypass driver), and RootHound (Linux privilege-escalation mapper). Claude Opus 5 achieved 30.2% on ARC-AGI-3 benchmark while WallBreaker jailbreak claims emerged targeting the model. Supply-chain attacks continued with malicious npm/PyPI packages including a Shai-Hulud worm variant and a disguised @copilot-mcp/apex macOS infostealer.

July 11, 2026

Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat

Progress Software is urging ShareFile customers to physically power down Storage Zone Controllers due to active zero-day exploitation tracked by watchTowr. Gitea Docker images are under active exploitation via a critical authentication bypass allowing attacker impersonation. CVE-2026-47291 in Windows HTTP.sys enables kernel code execution through TLS header parsing flaws, and CVE-2026-31431 ("Copy Fail") is a Linux kernel privilege escalation affecting all major distributions since 2017 with no fixed kernels shipped yet. Okta warns of vishing attacks enrolling rogue Entra ID passkeys to hijack Microsoft 365 accounts, while GigaWiper is a modular Golang backdoor bundling wiper, ransomware, and persistence functionality. Qilin leads 2026 ransomware volume with 708 tracked attacks, and Anthropic published the Jacobian lens, an interpretability technique revealing how Claude internally reasons through concepts.

June 22, 2026

Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR

A usbliter8 BootROM exploit for Apple A12/A13 devices and the LACUNA Chain EDR evasion technique represent major offensive advances, while Klue's OAuth token-theft incident exposed Salesforce customers to the Icarus actor. Supply-chain threats include a malicious node-fetch-utils npm package deploying fileless Python implants and active exploitation of CVE-2026-4020 in Gravity SMTP WordPress plugin.