daily cyber × ai intelligence

index

tagged

[CVE-2026-64531]

2 editions · 2 items

August 6, 2026

  • A 13-year-old Open vSwitch flaw in the Linux kernel gives local users root, and a public exploit ships with pre-built records for ~800 kernel builds. Codenamed OVSwrap (CVE-2026-64531, CVSS 7.8), the length-wraparound bug enables kernel pointer leaks, arbitrary reads, and credential modification, with broad reach through user namespaces on default-configured distros (The Hacker News, Security Affairs). · Vulnerabilities & Exploits

in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board

July 29, 2026

  • LLM-driven vulnerability research keeps landing real CVEs. OVSwrap (CVE-2026-64531), a broad Linux local privilege escalation, was found by giving models memory-safety and graph-reasoning tooling to work through exploit geometry (writeup), and ENDGINX turned open-weight GLM 5.1/5.2 loose on the NGINX codebase to surface five CVEs (mufeedvh via cyb3rops). Trail of Bits documented its goal-driven prompting workflow for bug discovery (Trail of Bits). · AI & Model Security

in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route