Anthropic's Project Glasswing CVE count is still guesswork
…27-year-old bug in OpenBSD, a 16-year-old FFmpeg bug, and Linux kernel privilege escalation chains. None of these have been assigned CVEs. "The full picture won't be known…
…27-year-old bug in OpenBSD, a 16-year-old FFmpeg bug, and Linux kernel privilege escalation chains. None of these have been assigned CVEs. "The full picture won't be known…
…In practice, the attack chain gives an adversary a route to lateral movement and privilege escalation, not just a limited information disclosure. The fix is included in the April 2026 cumulative update…
…For example, most every Linux distribution recently found itself on the wrong end of the Copy Fail and Dirty Frag privilege escalation vulnerabilities (gaining administrator access with a local account), for which…
…Allows Reading Root-Owned Files By Unprivileged Users Fragnesia Made Public As Latest Linux Local Privilege Escalation Vulnerability Linux Scheduler Work Helping Boost Gaming Performance On Old "Potato" Hardware Linux 7.0…
Slop-Amplified Fear of Privilege Escalation (Local, Not Remote) in Linux Kernel
Dirty Frag Linux kernel local privilege escalation vulnerability mitigations
Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP
Fragnesia: Linux kernel local privilege escalation via ESP-in-TCP
Dirty Frag: Ongoing Linux Kernel Privilege Escalation Vulnerability Since 2017
…Once they were inside networks, China’s bots found and abused valid credentials, escalated privileges, and moved laterally. In some cases, the agents even found and stole sensitive data. Machines don't…
…Allows Reading Root-Owned Files By Unprivileged Users Fragnesia Made Public As Latest Linux Local Privilege Escalation Vulnerability Linux Scheduler Work Helping Boost Gaming Performance On Old "Potato" Hardware Linux 7.0…
…Privilege escalation in Outline (CVE-2025-64487) Our information-gathering taskflows are optimized toward web applications, which is why we first pointed our audit taskflows to a collaborative web application called Outline…
…It's a local privilege escalation against the CTFMON subsystem that gets you SYSTEM from a normal user account, and the researcher published an analysis of the technique, but stripped out the…
…Detect when agents deviate from expected task flows, escalate privileges, or access unusual resources. Apply human-in-the-loop on pivots: Require manual validation for actions that change the agent’s operational…
…via exposed XPC interfaces," the researchers wrote. Finally, the attackers abuse CVE-2025-43520 to escalate privileges in the kernel and inject in-memory JavaScript implants into other system processes to extract…