#privilege escalation
51 stories taggedprivilege escalation.

Intel and AMD Quietly Patched Over 80 Security Flaws. Here Is What That Means For You.
Two of the biggest names in computer chips fixed a pile of serious vulnerabilities this Patch Tuesday. Some could let attackers take full control of an affected machine.

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix
A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

Windows kernel bug already under attack as Microsoft ships nearly 400 fixes
A flaw in a core Windows networking component is being used in real attacks to hand attackers full control of a machine.

Plug-and-Play Trick Turns a Fake USB Stick Into Full Windows 11 Takeover
Researchers show how Windows' helpful habit of auto-installing driver software can be twisted into SYSTEM-level control, and it works over Remote Desktop too.

Eighteen-Year-Old Bug in Linux Networking Code Hands Attackers the Keys to the Machine
A flaw in Linux's SCTP networking that has been sitting in the code since 2008 lets a local user become root and break out of a container. Fixed kernels shipped on 3 August.

Linux Kernel Flaw 'OVSwrap' Hands Local Users Root on Around 800 Builds
A memory corruption bug in Open vSwitch, tracked as CVE-2026-64531, lets ordinary users on default Linux systems become administrator, and a working exploit is already public.

Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps
The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

cPanel patches critical database flaw that let hosting customers run SQL as root
A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

The 'Ghost Credentials' Problem: How Forgotten Digital Keys Are Leaving Cloud Systems Wide Open
A sleeping AI agent that suddenly woke up and started making unusual requests led a security researcher to a sprawling mess of forgotten, untrusted digital keys, and a tool to help organisations find them before attackers do.

Researcher Publishes Linux Kernel Root Exploit Built With AI Help
CVE-2026-53264, a use-after-free flaw in the kernel's traffic-control code, lets an ordinary Linux user gain full system control on CentOS Stream 9.

Two Cloud Giants, Two Flaws, Zero Bug Bounties: The 'Confused Deputy' Problem That Won't Go Away
A security researcher found ways to silently hijack administrator control over both Microsoft Azure and Google Cloud infrastructure. Neither company paid a reward. One quietly fixed its flaw without saying so.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

Certighost: New Exploit Turns Ordinary Windows Users Into Domain Controllers
A public proof-of-concept lets any low-privileged Active Directory account impersonate a domain controller and walk off with the crown jewel of Windows authentication.

A Hidden Linux Flaw Lets Any Local User Seize Full Control of a Machine
A race condition buried in the Linux XFS filesystem since 2017 can hand a regular user complete administrative control. Patches are out. Reboots are required.

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers
A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.