Overview
Description
Statistics
- 7 Posts
- 6 Interactions
Fediverse
Not sure if I'm late to that party on this one or not. Guest to host escape in Linux KVM.
Zapscape (CVE-2026-64561)
Zapscape is a use-after-free vulnerability in the shadow MMU emulation of KVM/x86, specifically in the recursive zap path that runs when shadow pages are reclaimed. It can trigger the bug with guest-side actions alone to corrupt the host kernel's shadow page, and it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization, particularly multi-tenant x86 public clouds.
‼️ New Linux KVM escape flaw disclosed with public PoC.
Zapscape (CVE-2026-64561) could let an attacker with guest root break out of a nested VM and execute code as root on the host when nested virtualization is exposed to untrusted guests.
Learn which KVM setups are exposed: https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
Bluesky
Overview
Description
Statistics
- 8 Posts
- 1 Interaction
Fediverse
CVE-2026-63077: CISA warnt vor aktiver Ausnutzung einer TeamCity-Sicherheitslücke
Angreifer können ohne Authentifizierung Schadcode auf dem Server ausführen.
🚨 CSUITE THREAT ADVISORY: CISA confirms active exploitation of CVE-2026-63077 in JetBrains TeamCity. Unauthenticated RCE threatens core build pipelines & supply chain integrity. Get the executive governance, risk management, and compliance brief now: https://thecybermind.co/jvee
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html
📰 JetBrains Patches Critical Unauthenticated RCE Flaw in TeamCity
🚨 CRITICAL ALERT: JetBrains patches CVE-2026-63077, a 9.8 CVSS unauthenticated RCE in TeamCity On-Premises. All versions affected. Exploit allows full server takeover. Upgrade immediately to prevent supply chain attacks! #TeamCity #CI/CD #CyberSecurity
Bluesky
Overview
- Cisco
- Cisco Unified Computing System (Standalone)
Description
Statistics
- 4 Posts
Fediverse
📰 Cisco Patches Critical IMC Flaw (CVE-2026-20200) with Public PoC
Cisco patches critical root-level RCE flaw (CVE-2026-20200) in its IMC server management software. A public PoC exploit is available, making attacks imminent. Unauthenticated attackers can take over UCS servers. Patch now! #Cisco #Vulnerability #PoC
PoC exploit code is public for CVE-2026-20200, a Cisco IMC argument injection flaw enabling root RCE. CVSS 8.8. Patch details inside.
#Cisco #RCE #CVE #InfoSec #CyberSecurity
https://securityonline.info/cisco-imc-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
Bluesky
Overview
- Zbtlink
- CPE2801 Firmware
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
CVE-2026-66747: a Zbtlink router backdoor named ENDLESSDOORS gives unauthenticated remote code execution as root. No fix exists. CVSS 9.8.
#Zbtlink #RouterBackdoor #CVE #IoT #CyberSecurity
https://securityonline.info/zbtlink-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
#Linux: a 13-year-old Linux kernel flaw dubbed #OVSWrap lets local users gain root privileges on most Linux distributions. CVE-2026-64531 vulnerability is in the Linux kernel’s Open vSwitch datapath:
#PrivilegeEscalation
👇
Overview
Description
Statistics
- 2 Posts
Overview
- paperclipai
- paperclip
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-41679 | Paperclip AI platform CRITICAL vuln: auth bypass let attackers register, obtain API tokens, & run code as server. DNS rebinding risk in dev mode. Patch now. https://radar.offseq.com/threat/critical-paperclip-flaw-allowed-admin-access-code-execution-09ee35c54d49b29b #OffSeq #CVE #Paperclip #vuln
Overview
Description
Statistics
- 4 Posts
Fediverse
Cl0p ransomware started listing victims from their campaign of exploitation of an RCE vuln in PTC Windchill PDMlink and PTC FlexPLM. The victims seem to be anonymised for now.
Exploited bug: https://www.cve.org/CVERecord?id=CVE-2026-12569
In fact, Ransomware-ISAC warned on 22 July about the campaign by Cl0p affiliates, targeting internet-exposed PTC Windchill and FlexPLM deployments: https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/
The vuln was added to CISA's KEV in the end of June.
Bluesky
Overview
Description
Statistics
- 3 Posts
- 22 Interactions
Fediverse
Yet another linux LPE to root. "CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape"
#CVE_2026_64564 mitigation:
echo install sctp /bin/true | sudo tee /etc/modprobe.d/sctp.conf
#Debian stable has a fix now: linux-image-6.12.101+deb13-amd64
- sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
🚨 CVE-2026-48282: una semplice Path Traversal può trasformarsi in una Remote Code Execution su Adobe ColdFusion.
Nel video spiego:
🔴 cos'è RDS
🔴 perché il CVSS è 10.0
🔴 come avviene la catena di attacco
🔴 cosa controllare dopo aver applicato la patch
🎥 Guarda il video:
👉 https://youtu.be/SHYU1ag3NsQ
#CyberSecurity #ColdFusion #CVE202648282 #InfoSec #BlueTeam
@sicurezza