🛑 A new #Linux kernel exploit (CVE-2026-46331) gets root without modifying a single file on disk.
It poisons the cached copy of /bin/su in memory. The binary on disk stays untouched. File-integrity checks come back clean.
The root shell is already open.
Details here ↓ https://t.co/y2FDVjcSEq
🚨 WARNING — New HTTP/2 Bomb exploit targets NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
A single client can consume 32GB of server memory in roughly 20 seconds, causing remote DoS conditions.
Details here: https://t.co/58xDxAKRcZ
🚨 PAN-OS firewalls hit by active exploitation of CVE-2026-0300, enabling unauthenticated RCE with root access.
The unpatched flaw targets publicly exposed User-ID portals, affecting multiple versions. Fixes expected May 13, 2026.
Read the full story: https://t.co/q5R3LOGbt7
Canonical’s web infrastructure is under a sustained, cross-border attack and we are working to address it.
We will provide more information in our official channels as soon as we are able to.
⚠️ UPDATE: #cPanel flaw now tracked as CVE-2026-41940 (CVSS 9.8)—an auth bypass granting unauthenticated admin access.
Reportedly exploited as a 0-day, with activity observed for at least 30 days before disclosure. Root cause: CRLF injection enabling session forgery.
🔗 Exploit mechanics and real-world impact → https://t.co/8mHLoqywHY
🔥 Un fallo en Linux estuvo 9 años sin que nadie lo detectara.
CVE-2026-31431 afecta Ubuntu, Debian, Fedora y más. Menos de 30 líneas de código para escalar a root desde cualquier usuario.
🚨Vulnerabilidad en el directorio raíz de todas las principales distribuciones de Linux
Error de copia: 732 bytes
Copy Fail (CVE-2026-31431)
https://t.co/FizvJ7LCM4
‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017.
Website: https://t.co/f5G6KnEv35
Write-up: https://t.co/W86Pz2PC6C
GitHub: https://t.co/zAMTC6nTRk
It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su.
Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise.
Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.
Security teams close hundreds of vulnerabilities and still can’t prove they’re safer.
Only ~2% of exposures matter when mapped to real attack paths and critical assets. The rest is noise from tools that miss context and exploitability.
🔗 Why most platforms miss real risk → https://t.co/exZ70dDI1g
🔥 GitHub RCE via single git push!
CVE-2026-3854: Unsanitized push options let attackers run commands on backend servers, bypassing sandboxing (cross-tenant risk).
🔗 Learn how header injection led to full compromise → https://t.co/YzdRbikpau
Patched within hours.
⚠️ Hackers are breaching companies through Microsoft Teams, posing as IT helpdesk staff.
They flood inboxes, then send a Teams message with a “fix” link. One click installs malware, steals credentials, and gives full remote access.
🔗Learn more → https://t.co/3uIKdLWiNl
Bitwarden CLI comprometido en ataque a la cadena de suministro mediante GitHub Actions
Socket ha confirmado que la versión 2026.4.0 de Bitwarden CLI fue comprometida como parte de la campaña en curso de Checkmarx
https://t.co/kfSkaOf2Zn
🛑 WARNING: Bitwarden CLI was compromised in a supply chain attack.
@bitwarden/[email protected] included malicious code after attackers hijacked GitHub Actions, stole secrets, and pushed a tampered version to npm.
🔗 Learn how the attack worked → https://t.co/xqqJ7a9REL