Tag

#privilege escalation

52 stories taggedprivilege escalation · page 2 of 4.

Aerial view of a large industrial fuel storage facility at dusk, rows of cylindrical metal tanks reflecting low amber light, pressure gauges and pipe networks v
Vulnerabilities

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers

A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.

3 min read
Photoreal news-editorial image of a darkened office workstation showing a Windows-style login screen glowing on the monitor, with a faint blue reflection on the
Vulnerabilities

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs

A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

4 min read
Extreme close-up of a glowing green padlock icon cracking apart on a dark laptop screen, shards of digital light scattering across a desk surface, shallow depth
Vulnerabilities

Zoom patches a flaw that could hand strangers full control of your account

A critical bug in Zoom's Windows software let attackers take over accounts without a password, a click, or any help from the victim. Zoom found it first and patched it. Here is what you need to know.

3 min read
Photoreal editorial shot of a dimly lit server rack with amber warning LEDs reflecting off polished metal, rows of patch cables in soft focus, cool blue ambient
Vulnerabilities

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday

A prolific anonymous researcher drops yet another unpatched Windows flaw, this time one that lets ordinary users quietly take control of administrator accounts.

3 min read
Photoreal news-editorial 16:9 image of a dense tangle of fiber optic cables glowing under pressure in a dark server room, light fragmenting through the cables a
Vulnerabilities

Four Security Firms Patch Serious Flaws in Their Own Products

Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

3 min read
Photoreal news-editorial shot of a darkened server room with a single Windows laptop open on a rack shelf, screen glowing pale blue with abstract registry-tree
Vulnerabilities

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch

A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

3 min read
Photoreal news-editorial image of a dimly lit server rack in an enterprise data center, amber warning LEDs reflecting on brushed metal panels, shallow depth of
Vulnerabilities

Adobe Rushes Out Fixes for 88 Security Flaws, Eight of Them Critical in ColdFusion

Two weeks after hackers exploited a separate ColdFusion flaw within hours of its disclosure, Adobe is back with another urgent patch batch covering a dozen products.

3 min read
A photoreal editorial shot of a dimly lit server room aisle, one rack door left slightly ajar with a single amber warning light glowing inside, cables neatly bu
Threat Intelligence

The Boring Breaches: How Small Config Mistakes Keep Owning Big Companies

This week's roundup of incidents has a common thread: not clever attacks, just loose settings, reused names, and untouched defaults doing enormous damage.

3 min read
Full-frame photoreal editorial image of a close-up Windows laptop screen showing a generic blue security shield icon glowing, with faint reflection on a dark de
Vulnerabilities

Microsoft Patches 'RoguePlanet' Defender Flaw a Month After Public Disclosure

The privilege escalation bug in the Malware Protection Engine sat exposed for weeks before Redmond shipped a fix.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network

A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

3 min read
Full-frame close-up of a modern laptop screen glowing blue in a dim office, showing an abstract Windows security shield icon partly fractured, dust motes catchi
Vulnerabilities

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat

The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

4 min read
Full-frame close-up of a dark server room aisle, rows of black rack-mounted machines with faint green and amber status LEDs, one open server tray showing a bare
Vulnerabilities

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access

Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

3 min read
Photoreal editorial shot of a dense server rack in a cool-lit data centre, rows of blinking green and amber status LEDs, one rack panel showing a faint red warn
Vulnerabilities

16-Year-Old Linux Bug Lets Attackers Escape Virtual Machines on Intel and AMD

Researcher Hyunwoo Kim's 'Januscape' flaw (CVE-2026-53359) sat in KVM for over a decade and threatens shared cloud servers at Google Cloud, AWS and beyond.

4 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Vulnerabilities

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw

A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. That raises the urgency for every organisation running Linux servers to patch now.

3 min read
Vulnerabilities

DirtyClone: New Linux Kernel Flaw Hands Unprivileged Users the Root Keys

A page-cache manipulation bug related to DirtyFrag lets local, unprivileged attackers escalate to root — no credentials required beyond a shell.

2 min read
© 2026 Threat Vectr