π° **Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape**
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7. 8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.
π [Source](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-80521
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7. 8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.
π [Source](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-80521
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9. 8), affects all versions of the Bifrost HTTP transport before 2.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-90898
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9. 8), affects all versions of the Bifrost HTTP transport before 2.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-90898
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
IonQ's new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction. The post IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
IonQ's new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction. The post IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU Decoder
IonQβs new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction.
π° This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts. The post Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts. The post Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts.
π° Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-93616
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-93616
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10. 0) - An operating system command injection vulnerability in ColdFusion that could.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-48362
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10. 0) - An operating system command injection vulnerability in ColdFusion that could.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-48362
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
π° Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3. 1 score: 9.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-58138
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3. 1 score: 9.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-58138
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6. 5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition.
π Source
#RSS #CVE #CyberSecurity #Security #Report CVE-2026-65660
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6. 5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition.
π Source
#RSS #CVE #CyberSecurity #Security #Report CVE-2026-65660
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-81963 CVE-2026-69829 CVE-2026-85880 CVE-2026-69730
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-81963 CVE-2026-69829 CVE-2026-85880 CVE-2026-69730
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
Microsoft Plugs Nearly 1,000 Security Holes β Krebs on Security
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilitiesβ¦
π° Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-85889
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-85889
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-93485
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-93485
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-87902
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-87902
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
π° GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-72971 CVE-2026-62832 CVE-2026-68820
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-72971 CVE-2026-62832 CVE-2026-68820
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
Microsoft Plugs Nearly 400 Security Holes β Krebs on Security
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
π° Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9. 2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-87902
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9. 2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-87902
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1. 2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Karen Vardanyan has also been ordered to pay over $1. 2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
π° Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the company's personnel and contacted its employees to gain access to Astrana Health's servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Hackers impersonated the company's personnel and contacted its employees to gain access to Astrana Health's servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the companyβs personnel and contacted its employees to gain access to Astrana Healthβs servers.