» Tag
cve
31 postsCVE-2026-64560: Use-After-Free in Linux posix-cpu-timers
CVE-2026-64560 details a Linux kernel posix-cpu-timers use-after-free caused by an exec() race condition, along with its memory-ordering fix.
OVSwrap (CVE-2026-64531): AI-Assisted Discovery of a Linux Kernel LPE
OVSwrap (CVE-2026-64531): an AI-assisted discovery of a Linux kernel Open vSwitch LPE caused by a 16-bit nested action length wraparound.
Cursor Sandbox Escape Shows AI Agents Need Kernel Boundaries
Two critical bugs in Cursor's command sandbox let an attacker-controlled AI agent write outside it and reach RCE. Both are fixed in Cursor 3.0.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comBad Epoll Flaw Grants Root Access on Linux and Android
CVE-2026-46242, dubbed Bad Epoll, lets unprivileged local users gain root via a race-condition bug in the Linux kernel's epoll subsystem; a patch is already out.
Triage Is the Product: AI Agents Audit Ethereum's Protocol Code
Ethereum Foundation's security team runs parallel AI agents against protocol code, surfacing a real CVE—yet the hard part is filtering out false positives.
The Advisory Said It Was Fixed. I Didn't Believe It Until I Broke It Myself.
An engineer tested the CVE-2026-39973 vulnerability in apktool, emphasizing the importance of real testing over mere advisories.
Januscape: KVM/x86 Guest-to-Host Escape Flaw (CVE-2026-53359)
Januscape (CVE-2026-53359) is a critical KVM/x86 guest-to-host escape flaw in the shadow MMU, dormant for 16 years and exploitable on both Intel and AMD.
How a Russian-Speaking Operator Chained Camera and Router CVEs into a Proxy
Explore how an operator exploited camera and router CVEs against Ukraine.
KindaRails2Shell: Arbitrary File Read Leading to RCE in Rails Active Storage
Arbitrary file read vulnerability in Rails Active Storage via vips; patches available.
CVE-2026-63087: Grafana Oncall Reaches End of Life
CVE-2026-63087 reveals an authentication bypass vulnerability in Grafana OnCall.