#privilege escalation
52 stories taggedprivilege escalation · page 2 of 4.

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers
A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs
A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

Zoom patches a flaw that could hand strangers full control of your account
A critical bug in Zoom's Windows software let attackers take over accounts without a password, a click, or any help from the victim. Zoom found it first and patched it. Here is what you need to know.

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday
A prolific anonymous researcher drops yet another unpatched Windows flaw, this time one that lets ordinary users quietly take control of administrator accounts.

Four Security Firms Patch Serious Flaws in Their Own Products
Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch
A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

Adobe Rushes Out Fixes for 88 Security Flaws, Eight of Them Critical in ColdFusion
Two weeks after hackers exploited a separate ColdFusion flaw within hours of its disclosure, Adobe is back with another urgent patch batch covering a dozen products.

The Boring Breaches: How Small Config Mistakes Keep Owning Big Companies
This week's roundup of incidents has a common thread: not clever attacks, just loose settings, reused names, and untouched defaults doing enormous damage.

Microsoft Patches 'RoguePlanet' Defender Flaw a Month After Public Disclosure
The privilege escalation bug in the Malware Protection Engine sat exposed for weeks before Redmond shipped a fix.

Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network
A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat
The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

16-Year-Old Linux Bug Lets Attackers Escape Virtual Machines on Intel and AMD
Researcher Hyunwoo Kim's 'Januscape' flaw (CVE-2026-53359) sat in KVM for over a decade and threatens shared cloud servers at Google Cloud, AWS and beyond.

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw
A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. That raises the urgency for every organisation running Linux servers to patch now.

DirtyClone: New Linux Kernel Flaw Hands Unprivileged Users the Root Keys
A page-cache manipulation bug related to DirtyFrag lets local, unprivileged attackers escalate to root — no credentials required beyond a shell.