<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Linux Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Linux.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Scans for ESAFENET CDG 3 Document Management System Weak Logins</title><link>https://isc.sans.edu/diary/rss/33184</link><guid isPermaLink="false">cst-3228</guid><description>ESAFENET's CDG (Content Data Guard) document management system is being actively scanned for exploitation using default credentials. The product, which targets Chinese markets, ships with weak default passwords that appear in public exploit templates despite meeting standard password complexity requirements. Attackers are leveraging these known default logins to attempt unauthorized access to CDG deployments.</description><pubDate>Sun, 26 Jul 2026 15:26:14 GMT</pubDate></item><item><title>In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws</title><link>https://securityweek.com/in-other-news-dolphin-x-ai-powered-malware-car-anti-theft-device-hack-400-linux-kernel-flaws</link><guid isPermaLink="false">cst-3182</guid><description>A roundup of several security stories including Siemens ROX II industrial switch vulnerabilities, a Russian espionage campaign targeting Zimbra webmail, a ransomware extortion attempt against Stadler Rail, AI-powered malware called Dolphin X, a car anti-theft device hack, and over 400 Linux kernel flaws.</description><pubDate>Fri, 24 Jul 2026 14:20:00 GMT</pubDate></item><item><title>Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs</title><link>https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html</link><guid isPermaLink="false">cst-3071</guid><description>A nine-year-old flaw in the Linux kernel's XFS filesystem implementation, disclosed on July 22, 2026 as CVE-2026-64600, allows unprivileged local users to overwrite root-owned files and achieve persistent root access. Default configurations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are vulnerable to the issue. Qualys has demonstrated a working exploitation method for the race condition.</description><pubDate>Thu, 23 Jul 2026 08:04:35 GMT</pubDate></item><item><title>Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs</title><link>https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html</link><guid isPermaLink="false">cst-3033</guid><description>A local privilege escalation vulnerability in snap-confine (CVE-2026-8933, CVSS 7.8) allows unprivileged users to gain root access on default Ubuntu Desktop installations including versions 24.04, 25.10, and 26.04. The flaw has been publicly disclosed by cybersecurity researchers.</description><pubDate>Wed, 22 Jul 2026 18:07:16 GMT</pubDate></item><item><title>Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?</title><link>https://sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis</link><guid isPermaLink="false">cst-3045</guid><description>SentinelLabs evaluated frontier AI models on a multi-stage malware analysis benchmark based on their investigation of fast16, a 2005 sabotage implant, finding that only OpenAI's GPT-5.6 Sol completed the full eight-stage reverse-engineering task. The benchmark tested whether models could maintain investigative integrity as new evidence contradicted earlier conclusions, with successful completion requiring project-scale recovery including withdrawing incorrect conclusions and repairing technical artifacts. The researchers concluded that the strongest current use case is supervised investigative support where human analysts retain authority over objectives, quality control, and final publication.</description><pubDate>Wed, 22 Jul 2026 16:55:29 GMT</pubDate></item><item><title>Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in</title><link>https://risky.biz/risky-bulletin-linux-kernel-discloses-442-cves-as-ai-bugpocalypse-settles-in</link><guid isPermaLink="false">cst-2983</guid><description>The Linux kernel project disclosed 442 vulnerabilities in a three-day period, likely discovered using AI-powered bug-finding tools provided by firms like Anthropic and OpenAI to security researchers. Most of the identified issues carry low severity ratings and pose no immediate critical risk to systems running the kernel.</description><pubDate>Wed, 22 Jul 2026 06:30:24 GMT</pubDate></item><item><title>AI-generated reports push GNOME to shorten its disclosure window</title><link>https://helpnetsecurity.com/2026/07/21/gnome-security-disclosure-update</link><guid isPermaLink="false">cst-2877</guid><description>GNOME is shortening its vulnerability disclosure window in response to an influx of AI-generated security reports from tools like language models. Michael Catanzaro, who manages GNOME's security tracking, is revising the project's policies to address the volume and quality challenges posed by automated report submission. Many of these AI-generated reports lack clear indication of their machine origin.</description><pubDate>Tue, 21 Jul 2026 03:53:19 GMT</pubDate></item><item><title>ABB Ability Edgenius</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-195-02</link><guid isPermaLink="false">cst-2506</guid><description>ABB has released an advisory for CVE-2026-31431, a Linux kernel vulnerability affecting ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 installed on multiple gateway and server models. The flaw allows locally authenticated users or compromised container workloads to escalate privileges to root, potentially granting complete system control. A patch is available in version 3.2.4.1, and ABB recommends immediate application along with access restrictions to SSH and Cockpit.</description><pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Debian 13.6 security update patches over a hundred advisories in trixie</title><link>https://helpnetsecurity.com/2026/07/13/debian-13-6-security-update-released</link><guid isPermaLink="false">cst-2374</guid><description>Debian 13.6 (trixie) was released with over a hundred security patches and fixes for serious issues. The update addresses a critical problem involving an expired UEFI Secure Boot certificate authority that has affected most PCs since 2013, with fwupd providing the remediation path for systems with Secure Boot enabled.</description><pubDate>Sun, 12 Jul 2026 22:25:16 GMT</pubDate></item><item><title>Schneider Electric PowerChute Serial Shutdown</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-190-02</link><guid isPermaLink="false">cst-2261</guid><description>Schneider Electric has disclosed multiple vulnerabilities in PowerChute Serial Shutdown versions 1.4 and earlier that could allow attackers to overwrite critical files, inject malicious log data, forge credentials, cause denial-of-service conditions, or expose sensitive information. The vulnerabilities affect deployments across communications, energy, healthcare, manufacturing, information technology, and transportation sectors worldwide. Version 1.5 includes fixes for these issues and is available for Windows and Linux platforms.</description><pubDate>Thu, 09 Jul 2026 12:00:00 GMT</pubDate></item><item><title>15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros</title><link>https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html</link><guid isPermaLink="false">cst-2127</guid><description>Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present in the codebase since 2011 that affects most mainstream distributions. The flaw allows any logged-in user to gain root privileges without requiring special permissions, unusual configurations, or network access.</description><pubDate>Wed, 08 Jul 2026 06:16:44 GMT</pubDate></item><item><title>New Januscape Linux flaw allows VM escape on Intel, AMD devices</title><link>https://bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices</link><guid isPermaLink="false">cst-518</guid><description>A 16-year-old Linux kernel vulnerability tracked as Januscape enables attackers to escape virtual machines and execute arbitrary code on the host system. The flaw affects both Intel and AMD devices running vulnerable Linux kernel versions.</description><pubDate>Tue, 07 Jul 2026 12:06:09 GMT</pubDate></item><item><title>Hitachi Energy e-mesh EMS</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-188-03</link><guid isPermaLink="false">cst-549</guid><description>Hitachi Energy has disclosed a heap-based buffer overflow vulnerability (CVE-2026-42945) in its e-mesh EMS product versions 4.1.6, 4.4.2, and 4.7.0, caused by an NGINX module flaw. The vulnerability, with a CVSS 3.1 score of 8.1, could allow unauthenticated attackers to cause denial of service or execute arbitrary code by sending crafted HTTP requests, particularly on systems without Address Space Layout Randomization (ASLR) enabled. Hitachi Energy recommends applying hotfixes to update NGINX to version 1.30.2 or later, and has provided interim mitigations including configuration changes and operating system upgrades.</description><pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems</title><link>https://securityweek.com/linux-kernel-vulnerability-allows-vm-escape-on-intel-and-amd-systems</link><guid isPermaLink="false">cst-514</guid><description>A 16-year-old vulnerability in Linux's KVM hypervisor, dubbed Januscape, allows attackers to escape virtual machines and execute code on the underlying host system on both Intel and AMD processors. The flaw represents a critical privilege escalation path from guest to host in virtualized environments.</description><pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate></item><item><title>6th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/6th-july-threat-intelligence-report-2</link><guid isPermaLink="false">cst-594</guid><description>A threat intelligence bulletin reports multiple significant incidents across sectors: ransomware attacks affecting financial, defense, manufacturing, and insurance organizations; artificial intelligence threats including LLM-generated ransomware, unsafe coding agents, and phishing domain hijacking; and critical vulnerabilities in Oracle, Linux, Citrix, and Progress products with active exploitation observed.</description><pubDate>Mon, 06 Jul 2026 12:01:54 GMT</pubDate></item><item><title>New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android</title><link>https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.html</link><guid isPermaLink="false">cst-26</guid><description>A Linux kernel vulnerability named Bad Epoll (CVE-2026-46242) allows unprivileged users to escalate privileges to root access on affected Linux systems and Android devices. A fix has been released. The flaw exists in kernel code where an AI model recently identified a separate vulnerability.</description><pubDate>Fri, 03 Jul 2026 19:40:01 GMT</pubDate></item><item><title>Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.</title><link>https://darkreading.com/vulnerabilities-threats/anthropic-s-ai-finds-bugs-ibm-bets-5b-it-can-fix-them-</link><guid isPermaLink="false">cst-80</guid><description>IBM and Red Hat are dedicating 20,000 engineers to Project Lightwell, a new service focused on securing the open source software supply chain, prompted by vulnerability findings from Anthropic's Mythos research. The initiative reflects growing industry concern about security gaps in widely-used open source components and the scale of effort required to address them.</description><pubDate>Thu, 02 Jul 2026 12:33:57 GMT</pubDate></item><item><title>Risky Bulletin: Researcher drops giant cache of zero-day exploits</title><link>https://risky.biz/risky-bulletin-researcher-drops-giant-cache-of-zero-day-exploits</link><guid isPermaLink="false">cst-165</guid><description>A researcher using the pseudonym Bikini published proof-of-concept exploits and technical details for over a dozen zero-day vulnerabilities in popular open-source and commercial software without notifying vendors beforehand. The affected projects include the Linux kernel, Libssh2, Anydesk, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN, and VLC player, among others.</description><pubDate>Wed, 01 Jul 2026 07:00:47 GMT</pubDate></item><item><title>What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials</title><link>https://tenable.com/blog/what-the-miasma-campaign-reveals-about-the-new-supply-chain-threat-model-and-the-underground</link><guid isPermaLink="false">cst-383</guid><description>The Miasma campaign exploited a stolen Red Hat developer credential from underground markets to inject malicious packages into the npm registry, affecting 89 plus packages across three waves in early June. The attack demonstrated a structured threat model where harvested developer credentials are bought and weaponized weeks after theft, and included novel techniques such as forged SLSA provenance attestations and persistence mechanisms targeting AI coding assistants like Claude and Cursor. The campaign illustrates an emerging developer credential economy where infostealers, dark web markets, and supply chain compromises operate as coordinated layers in a single attack pipeline.</description><pubDate>Tue, 23 Jun 2026 13:00:00 GMT</pubDate></item><item><title>Impact of Linux Kernel vulnerabilities on B&amp;R products</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-174-06</link><guid isPermaLink="false">cst-280</guid><description>B&amp;R Industrial Automation has issued an advisory regarding Linux kernel vulnerabilities affecting multiple product versions, including Linux for B&amp;R, APROL, and X20EDS410 equipment. Local exploitation of these vulnerabilities could enable privilege escalation, with public proof-of-concept code available, though no active attacks on B&amp;R products have been detected. The vendor recommends immediate software updates when available and interim mitigation through strict access control policies.</description><pubDate>Tue, 23 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more</title><link>https://rapid7.com/blog/post/pt-metasploit-wrap-up-19-06-2026</link><guid isPermaLink="false">cst-370</guid><description>Rapid7 released five new Metasploit modules this week, including a full remote code execution chain for Paperclip AI using six API calls, an NTLM relay technique for privilege escalation to SYSTEM on Windows, VS Code extension persistence, and exploits for Xerte Online Toolkits and Linux kernel vulnerabilities. The update also includes an MCP server plugin enabling AI tool integration within msfconsole and improved module check codes with richer diagnostic detail.</description><pubDate>Fri, 19 Jun 2026 17:08:23 GMT</pubDate></item><item><title>High-severity vulnerability in Linux caused by a single faulty character</title><link>https://arstechnica.com/security/2026/06/a-single-errant-character-in-the-linux-kernel-allows-attacker-to-gain-root</link><guid isPermaLink="false">cst-438</guid><description>A high-severity vulnerability in the Linux kernel's nf_tables subsystem, tracked as CVE-2026-23111, allows unprivileged users to escalate privileges to root. The flaw stems from a single errant character in the code that introduces a use-after-free vulnerability, which corrupts memory by writing malicious code to improperly freed memory addresses. The nf_tables subsystem provides packet filtering and firewall rule management functionality.</description><pubDate>Tue, 09 Jun 2026 15:12:43 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Pwn2Own Berlin 2026: Day Three Results and Master of Pw</title><link>https://thezdi.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn</link><guid isPermaLink="false">cst-392</guid><description>Pwn2Own Berlin 2026 concluded on Day Three with security researchers demonstrating 47 unique zero-day vulnerabilities across the three-day competition. DEVCORE won the Master of Pwn title with 50.5 points and $505,000, followed by STARLabs SG and Out Of Bounds, with a total of $1,298,250 awarded for all disclosed vulnerabilities.</description><pubDate>Sat, 16 May 2026 10:38:50 GMT</pubDate></item><item><title>Panic at the Distro</title><link>https://huntress.com/blog/linux-kernel-flaws-copyfail-dirty-frag-fragnesia</link><guid isPermaLink="false">cst-693</guid><description>Three critical Linux kernel vulnerabilities—CopyFail, Dirty Frag, and Fragnesia—allow unprivileged users to escalate privileges to root access. Security teams need to identify and patch affected systems to close this privilege escalation pathway.</description><pubDate>Thu, 14 May 2026 11:00:00 GMT</pubDate></item><item><title>Pwn2Own Berlin 2026: The Full Schedule</title><link>https://thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule</link><guid isPermaLink="false">cst-393</guid><description>Pwn2Own Berlin 2026 is a competitive hacking event held at OffensiveCon featuring security researchers attempting to exploit vulnerabilities in enterprise software across multiple categories including AI databases, coding agents, web browsers, and NVIDIA products. The competition schedule spans three days in May 2026, with researchers competing for prize pools ranging from $20,000 to $175,000 and Master of Pwn points based on vulnerability severity and impact.</description><pubDate>Wed, 13 May 2026 16:23:07 GMT</pubDate></item><item><title>Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP</title><link>https://wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp</link><guid isPermaLink="false">cst-1281</guid><description>Researchers have identified a page-cache corruption vulnerability in the Linux kernel's Dirty Frag family that allows unprivileged local attackers to escalate privileges to root level. The vulnerability exploits issues in how the kernel handles fragmented data structures in memory. This represents a significant local privilege escalation pathway that affects Linux systems across multiple distributions.</description><pubDate>Wed, 13 May 2026 12:13:44 GMT</pubDate></item><item><title>Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild</title><link>https://elastic.co/security-labs/copy-fail-dirtyfrag-linux-page-bugs-in-the-wild</link><guid isPermaLink="false">cst-619</guid><description>Linux kernel vulnerabilities Copy Fail (CVE-2026-31431), Copy Fail 2, and DirtyFrag enable local privilege escalation through page cache corruption bugs exploitable via legitimate kernel interfaces like AF_ALG socket and splice() syscalls. Copy Fail has been observed in active exploitation and added to CISA's Known Exploited Vulnerabilities catalog, while DirtyFrag extends the attack surface to the networking stack with multiple exploitation paths that bypass some existing mitigations.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>Copy Fail: Universal Linux Local Privilege Escalation Vulnerability</title><link>https://wiz.io/blog/copyfail-cve-2026-31431-linux-privilege-escalation-vulnerability</link><guid isPermaLink="false">cst-1295</guid><description>A Linux kernel vulnerability identified as CVE-2026-31431, named Copy Fail, enables unprivileged local users to escalate privileges to root through relatively straightforward exploitation. The flaw affects universal Linux distributions and poses a direct path to complete system compromise for attackers with local access.</description><pubDate>Fri, 01 May 2026 12:38:09 GMT</pubDate></item><item><title>A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)</title><link>https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746</link><guid isPermaLink="false">cst-562</guid><description>A 32-year-old pre-authentication remote code execution vulnerability (CVE-2026-32746) was discovered in GNU inetutils Telnetd by the DREAM Security Research Team. The BSS-based buffer overflow exists in the LINEMODE SLC negotiation handler and affects multiple operating systems and distributions that derive from the same codebase, including Ubuntu, Debian, FreeBSD, NetBSD, and others. Despite the severity and wide impact, the vulnerability had received minimal public analysis at the time of reporting.</description><pubDate>Thu, 19 Mar 2026 20:21:07 GMT</pubDate></item><item><title>A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave</title><link>https://projectzero.google/2026/01/pixel-0-click-part-2.html</link><guid isPermaLink="false">cst-572</guid><description>A security researcher discovered three bugs in the BigWave driver on Google Pixel 9, including a use-after-free vulnerability accessible from the mediacodec sandbox context. The most severe bug allows an attacker to achieve kernel-level arbitrary read and write capabilities by exploiting a race condition where the driver accesses job objects on a worker thread after the file descriptor has been closed and memory freed. Google released fixes for all three vulnerabilities on January 5, 2026.</description><pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate></item><item><title>Wiz achieves Red Hat Vulnerability Scanner Certification</title><link>https://wiz.io/blog/wiz-achieves-red-hat-vulnerability-scanner-certification</link><guid isPermaLink="false">cst-1592</guid><description>Wiz has obtained Red Hat Vulnerability Scanner Certification, which allows its vulnerability scanning capabilities to be recognized as certified for assessing vulnerabilities in Red Hat products. This certification indicates that Wiz's scanning tool meets Red Hat's standards for vulnerability detection in their environment.</description><pubDate>Mon, 20 May 2024 13:03:32 GMT</pubDate></item><item><title>GameOver(lay): Easy-to-exploit local privilege escalation vulnerabilities in Ubuntu Linux affect 40% of Ubuntu cloud workloads</title><link>https://wiz.io/blog/ubuntu-overlayfs-vulnerability</link><guid isPermaLink="false">cst-1694</guid><description>Wiz Research identified two privilege escalation vulnerabilities, CVE-2023-2640 and CVE-2023-32629, in Ubuntu Linux' OverlayFS module that are straightforward to exploit. These flaws impact approximately 40 percent of Ubuntu cloud workloads, creating a significant exposure across deployed instances.</description><pubDate>Thu, 27 Jul 2023 19:33:45 GMT</pubDate></item></channel></rss>