Overview
Description
Statistics
- 6 Posts
- 23 Interactions
Fediverse
Instale já a correção para vulnerabilidade em máquinas virtuais
Se você usa Proxmox ou apenas tem um VPS, atualize já seu sistema. O problema permite o escape de máquinas virtuais e acesso à máquina física.
Se usa Debian, saiu o kernel 6.12.101-1 que corrige o problema. O Proxmox também já lançou atualização mesmo para quem não é assinante com o kernel 7.0.14-9.
:debian: https://security-tracker.debian.org/tracker/CVE-2026-64561
:xp_secure_server: https://forum.proxmox.com/threads/proxmox-and-cve-2026-64561.185571/
:xp_sys_info: https://www.cve.org/CVERecord?id=CVE-2026-64561
:github: https://github.com/V4bel/Zapscape
「Zapscape KVMの新たな脆弱性により、特権を持つL1ゲストコードがLinuxホストに漏洩する可能性 」: #TheHackerNews
「Linuxカーネルの新たな脆弱性「Zapscape」 により、L1ゲスト仮想マシン(VM)内でカーネル権限を持つ攻撃者がKVM分離を回避し、ホスト上でコードを実行できる可能性があります。このリスクは、ネストされた仮想化が信頼できないゲストに公開されている場合に発生します。
この脆弱性は CVE-2026-64561 として追跡されており、ネストされたゲストメモリ変換に使用されるシャドウページテーブルを管理するKVM/x86のシャドウメモリ管理ユニット(MMU)に影響を与えます。
このバグを明らかにしたセキュリティ研究者の キム・ヒョヌ氏 は、実証されたエクスプロイト経路によって、カーネル権限、つまりroot権限でホスト上でコマンドを実行できると述べた。 」
https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
MT @v4bel@x.com
💥 Introducing "Zapscape" (CVE-2026-64561)
A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU's recursive "ZAP" path. Can escape to the host on x86 public clouds that expose nested virtualization.
Details: https://zapscape.io
Zapscape: A Technical Deep-dive of the CVE-2026-64561 KVM Guest-to-Host Escape
Discover how Zapscape (CVE-2026-64561) exploits Linux KVM's Shadow MMU to achieve guest-to-host escape, including root cause, exploitation and morehttps://thecybersecguru.com/news/zapscape-cve-2026-64561-kvm-guest-host-escape/
A new Linux Kernel KVM vulnerability threatens cloud servers with virtual machine escape risks. Learn about CVE-2026-64561 and secure your host machine now.
#LinuxKernel #KVMVulnerability #CVE202664561 #CloudSecurity #VMescape
Overview
- WordPress
- WordPress
Description
Statistics
- 6 Posts
- 1 Interaction
Fediverse
‼️ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version.
XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.
Update your WordPress sites ASAP 🠖 https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
New WordPress Pre-Authentication XSS Could Lead to PHP Code Execution, Patch Immediately
Learn how CVE-2026-64638 affects WordPress, why the pre-authentication XSS is dangerous, how researchers chained it to PHP code execution using XSS2Shellhttps://thecybersecguru.com/news/wordpress-cve-2026-64638-pre-auth-xss-php-code-execution/
#Wordpress: A Critical pre-auth #XSS to RCE vulnerability chain (CVE-2026-64638) dubbed #XSS2Shell is affecting all versions of WordPress Core. This vulnerability was discovered by AI (@pwn_ai). Patch to v7.0.3 ASAP - older versions backported:
👇
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
🚨 WordPress patches XSS2Shell flaw that could lead to server code execution
CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.
The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.
A successful chain could potentially allow attackers to:
• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials
WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.
NHS England says exploitation is likely following the release of technical details and a PoC.
WordPress has not reported confirmed exploitation in the wild as of August 7.
Update immediately.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
https://pwn.ai/blog/xss2shell
Overview
Description
Statistics
- 2 Posts
- 20 Interactions
Bluesky
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Bluesky
Overview
- WebPros
- cPanel
Description
Statistics
- 2 Posts
Bluesky
Overview
- Takayuki Miyauchi
- TinyMCE Templates
- tinymce-templates
Description
Statistics
- 1 Post
- 22 Interactions
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
- 3 Interactions
Fediverse
Tails 7.10.1 patches CVE-2026-64560 in the Linux kernel and expat library flaws that could let attackers deanonymize users and gain admin privileges.
#Tails #Linux #Privacy #CVE202664560 #Cybersecurity #AnonymousOS
Tails 7.10.1 patches CVE-2026-64560, a Linux kernel race condition letting a compromised Tor Browser gain root and deanonymize users via a malicious website.
#Tails #CVE202664560 #LinuxKernel #TorBrowser #Deanonymization #PrivilegeEscalation #AnonymityOS #TailsOS
Overview
- Microsoft
- Microsoft Teams
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-65667 - Critical privilege escalation in Microsoft Teams. Missing authorization enables network-based elevation. CVSS 10. Patch unavailable - monitor for updates. #CVE #Microsoft #infosec
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
📰 Linux Kernel Flaw "OVSwrap" Allows Root Privilege Escalation
New Linux kernel LPE flaw 'OVSwrap' (CVE-2026-64531) allows local users to gain root. The bug in Open vSwitch datapath poses a critical risk to multi-tenant and container environments. Patch now! #Linux #Kernel #Vulnerability #CyberSecurity