Tag

#privilege escalation

50 stories taggedprivilege escalation · page 3 of 4.

A system administrator's hands hovering over a keyboard at an empty desk, with a computer monitor displaying a terminal window showing file system logs and perm
Vulnerabilities

A Hidden Linux Flaw Lets Any Local User Seize Full Control of a Machine

A race condition buried in the Linux XFS filesystem since 2017 can hand a regular user complete administrative control. Patches are out. Reboots are required.

4 min read
A Red Hat Enterprise Linux desktop with file system permission indicators showing a regular user escalating to root-level access through a nine-year-old XFS vul
Vulnerabilities

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers

A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.

3 min read
Photoreal news-editorial image of a darkened office workstation showing a Windows-style login screen glowing on the monitor, with a faint blue reflection on the
Vulnerabilities

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs

A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

4 min read
A Windows operating system update notification screen with a calendar showing Patch Tuesday highlighted, and a zero-day vulnerability indicator badge glowing om
Vulnerabilities

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday

A prolific anonymous researcher drops another unpatched Windows flaw, this time one that lets ordinary users quietly read administrator account data.

3 min read
Four different security software vendor logos displayed on monitor screens in a security operations centre, each with urgent patch notification badges and versi
Vulnerabilities

Four Security Firms Patch Serious Flaws in Their Own Products

Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

3 min read
Photoreal news-editorial shot of a darkened server room with a single Windows laptop open on a rack shelf, screen glowing pale blue with abstract registry-tree
Vulnerabilities

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch

A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

3 min read
Photoreal news-editorial image of a dimly lit server rack in an enterprise data center, amber warning LEDs reflecting on brushed metal panels, shallow depth of
Vulnerabilities

Adobe Rushes Out Fixes for 88 Security Flaws, Eight of Them Critical in ColdFusion

Two weeks after hackers exploited a separate ColdFusion flaw within hours of its disclosure, Adobe is back with another urgent patch batch covering a dozen products.

2 min read
A photoreal editorial shot of a dimly lit server room aisle, one rack door left slightly ajar with a single amber warning light glowing inside, cables neatly bu
Threat Intelligence

The Boring Breaches: How Small Config Mistakes Keep Owning Big Companies

This week's roundup of incidents has a common thread: not clever attacks, just loose settings, reused names, and untouched defaults doing enormous damage.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network

A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

3 min read
Full-frame close-up of a modern laptop screen glowing blue in a dim office, showing an abstract Windows security shield icon partly fractured, dust motes catchi
Vulnerabilities

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat

The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

3 min read
Full-frame close-up of a dark server room aisle, rows of black rack-mounted machines with faint green and amber status LEDs, one open server tray showing a bare
Vulnerabilities

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access

Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

3 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Vulnerabilities

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw

A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. Unpatched Linux servers are now a much easier target.

3 min read
Vulnerabilities

Linux act_pedit OOB Write Poisons Page Cache, Hands Local Users Root

CVE-2026-46331 weaponizes a traffic-control bug to overwrite cached binaries. A working PoC dropped within a day of disclosure.

2 min read
Vulnerabilities

DirtyClone: New DirtyFrag-Family Kernel Bug Hands Local Users Root

CVE-2026-43503 (CVSS 8.8) corrupts file-backed memory through a cloned network packet. A working PoC is now public.

3 min read
Vulnerabilities

Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows

A Bluetooth eavesdropping patch, a quietly dangerous GCP authorization flaw, and a threat actor that spent ten years undetected, here is what you may have missed.

3 min read
© 2026 Threat Vectr