#privilege escalation
50 stories taggedprivilege escalation.

Microsoft fixes a perfect-10 flaw in Azure AI Foundry that let strangers take control
A missing authentication check in Microsoft's flagship AI development platform earned the rare CVSS 10.0 rating. Microsoft patched it on its side, but the bug says a lot about how fast AI services are shipping.

Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks
A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

cPanel Patches Bug That Let One Mail Account Hijack a Whole Server
A flaw in cPanel's EmailTrack tool let any authenticated mailbox user write files and run commands as root, the top-level administrator with total control of the machine.

LiteSpeed Flaw Lets a Single Hosting Account Take Over a Shared Server
cPanel warns that a critical bug in LiteSpeed Web Server Enterprise gives a low-privilege user a path to full root control, putting every website on the same machine at risk.

Apple Fixes Around 200 Security Flaws in iOS 27 and macOS Golden Gate 27
The updates patch kernel vulnerabilities that could let attackers take control of a device, crash it, or quietly read private data.

Acronis backup add-on carries a Linux privilege flaw, and someone is already using it
A high-severity bug in Acronis backup plugins for cPanel, WHM and Plesk is being exploited in what the vendor calls limited, targeted attacks. Patches are out.

Parallels Desktop Bug Hands Root to Any Mac User, and Older Macs Can't Get the Patch
A flaw in Parallels Desktop for Mac lets a normal user seize full control of the machine. The fix ships only in Parallels Desktop 27, which won't install on Intel-based Macs.

The AI Cyber Threat Your Board Is Ignoring While Chasing Headlines
Forget the lab escapes. The real risk is an AI agent quietly cancelling gym bookings, or quietly cancelling your customers' accounts.

One Researcher Just Published Working Hacks Against CrowdStrike, Avast, and Nvidia
A prolific security researcher dropped three zero-day exploits in a single week, targeting software that millions of people and businesses rely on to stay safe.

Researcher publishes FalconFlank zero-day targeting CrowdStrike Falcon Sensor
A privilege escalation flaw abuses Falcon's own Office macro cleanup routine to hand attackers SYSTEM-level access on Windows machines.

Researcher Drops 'HardBreacher' Exploit for Kaspersky Security Software
A bug-hunter who has repeatedly embarrassed Microsoft now has Kaspersky in the crosshairs, releasing a proof-of-concept exploit that can hand an attacker near-total control of a Windows machine running Kaspersky Endpoint Security.

AI Agents Are Breaking Cloud Security Faster Than Human Hackers Ever Could
Automated attackers can test thousands of ways into a company's cloud systems in minutes. Most security teams are still thinking at human speed.

Critical cPanel Bug Lets a Single Hosting Customer Seize an Entire Server
A flaw in domain parking, tracked as CVE-2026-65643, could hand root control of a shared hosting server to any customer with an account on it.

Windows Named Pipes: The Hidden Back Channel Attackers Keep Prying Open
A quiet feature that lets Windows programs talk to each other becomes a privilege-escalation problem when developers skip the access checks.

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC
CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.