daily cyber × ai intelligence

index

tagged

[noname057-16]

4 items

July 9, 2026

A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro

GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free in every mainstream distribution since 2011, enables unauthenticated root access and container escape when paired with a Firefox 0-day in a full browser-to-kernel exploit chain. GhostApproval symlink flaws in six AI coding assistants (Amazon Q Developer, Claude Code, Cursor, Google Antigravity, Windsurf, Augment) allow booby-trapped repositories to redirect file writes and achieve RCE via misleading confirmation dialogs. CISA added actively-exploited Adobe ColdFusion (CVE-2026-48282) and Langflow auth-bypass flaws to its KEV catalog, with the Langflow issue matching the JADEPUFFER operator's exploitation from the prior week. AI agents are lowering the barrier for less-skilled attackers: hallucination-squatting registers fake package names that models invent, delivering malware to developers, while researchers demonstrate that agents scanning untrusted code for bugs can instead execute the attacker's payload on the analyst's machine.

June 29, 2026

Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week

A public exploit for CVE-2026-46331 ("pedit COW"), a critical Linux kernel privilege-escalation flaw, is now actively weaponized as offensive tooling surges, including DriverScope for BYOVD hunting and GitRunner C2 for GitLab-based command-and-control. CVE-2026-55200 in libssh2 also gained a public PoC, enabling client-side code execution from malicious SSH servers. Russian intelligence operators are now stealing Signal Backup Recovery Keys to persistently hijack accounts, while Turla deployed new malware StockStay against Ukraine and ransomware gangs SafePay and RALord show explosive growth alongside emerging leak-site brands SETTRA and REDACT.

June 22, 2026

Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR

A usbliter8 BootROM exploit for Apple A12/A13 devices and the LACUNA Chain EDR evasion technique represent major offensive advances, while Klue's OAuth token-theft incident exposed Salesforce customers to the Icarus actor. Supply-chain threats include a malicious node-fetch-utils npm package deploying fileless Python implants and active exploitation of CVE-2026-4020 in Gravity SMTP WordPress plugin.

June 21, 2026

FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.