#lpe — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #lpe, aggregated by home.social.
-
A public PoC named VsockDrop turns CVE-2026-53365 into unprivileged local privilege escalation to root on Linux.
#CVE202653365 #VsockDrop #LinuxKernel #PrivilegeEscalation #vsock #LPE
-
A public PoC named VsockDrop turns CVE-2026-53365 into unprivileged local privilege escalation to root on Linux.
#CVE202653365 #VsockDrop #LinuxKernel #PrivilegeEscalation #vsock #LPE
-
A "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF:
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#cybersecurity #infosec #informationsecurity #lpe #linux #kernelctf #exploitation
-
A "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF:
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#cybersecurity #infosec #informationsecurity #lpe #linux #kernelctf #exploitation
-
A "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF:
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#cybersecurity #infosec #informationsecurity #lpe #linux #kernelctf #exploitation
-
A "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF:
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#cybersecurity #infosec #informationsecurity #lpe #linux #kernelctf #exploitation
-
A "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF:
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#cybersecurity #infosec #informationsecurity #lpe #linux #kernelctf #exploitation
-
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
-
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
-
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
-
A public PoC exploits a Linux AF_PACKET race for local privilege escalation to root. No CVE is assigned yet.
#AFPACKET #LinuxKernel #PrivilegeEscalation #LPE #KernelExploit #PoC
-
A public PoC exploits a Linux AF_PACKET race for local privilege escalation to root. No CVE is assigned yet.
#AFPACKET #LinuxKernel #PrivilegeEscalation #LPE #KernelExploit #PoC
-
📢 Vipere : outil LPE + persistance SYSTEM via l'Elevation Service de Visual Studio Installer
Il cible les environnements Windows disposant de Visual Studio Installer.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-vipere-outil-lpe-persistance-system-via-l-elevation-service-de-visual-studio-installer/
🌐 source : https://github.com/0xaled/Vipere
🟡 vérification factuelle moyenne
#LPE #Vipere #Cyberveille -
Gentlemen! Here's another one! https://github.com/sgkdev/bad_garbage
-
Gentlemen! Here's another one! https://github.com/sgkdev/bad_garbage
-
Gentlemen! Here's another one! https://github.com/sgkdev/bad_garbage
-
Gentlemen! Here's another one! https://github.com/sgkdev/bad_garbage
-
Gentlemen! Here's another one! https://github.com/sgkdev/bad_garbage
-
📢 wp2root : chaîne d'exploitation WordPress de PHP à root via Copy Fail (LPE Linux 2026)
Cet article présente wp2root, une chaîne post-exploitation développée par l'équipe Calif pour faire suite à wp2shell (RCE pré-authentifiée WordPress Core d'AssetNote). L'article est accompagné d'un dépôt PoC public.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-08-wp2root-chaine-d-exploitation-wordpress-de-php-a-root-via-copy-fail-lpe-linux-2026/
🌐 source : https://blog.calif.io/p/the-wordpress-chain-massacre
🟢 vérification factuelle haute
#LPE #WordPress #Cyberveille -
Another KVM guest escape to root (read LPE) just got disclosed https://zapscape.io
I'll log my findings in replies
-
Another KVM guest escape to root (read LPE) just got disclosed https://zapscape.io
I'll log my findings in replies
-
Another KVM guest escape to root (read LPE) just got disclosed https://zapscape.io
I'll log my findings in replies
-
Another KVM guest escape to root (read LPE) just got disclosed https://zapscape.io
I'll log my findings in replies
-
Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
-
Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
-
Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
-
Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
-
A macOS privilege escalation flaw gives an unprivileged user root with no user interaction. A full public PoC is out; Apple fixed it in 26.6 with no CVE.
#macOS #PrivilegeEscalation #LPE #DesktopServicesHelper #PublicPoC #RootExploit #AppleSecurity #InfoSec #CyberSecurity
-
🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability
#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb -
🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability
#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb -
CVE-2026-8933 is a snap-confine privilege escalation flaw. It gives any user root on default Ubuntu Desktop 26.04, 25.10, and 24.04. Update snapd now.
#snapconfine #CVE20268933 #Ubuntu #PrivilegeEscalation #LPE #Linux #Qualys
http://securityonline.info/snap-confine-cve-2026-8933/?utm_source=mastodon&utm_medium=jetpack_social
-
CVE-2026-8933 is a snap-confine privilege escalation flaw. It gives any user root on default Ubuntu Desktop 26.04, 25.10, and 24.04. Update snapd now.
#snapconfine #CVE20268933 #Ubuntu #PrivilegeEscalation #LPE #Linux #Qualys
http://securityonline.info/snap-confine-cve-2026-8933/?utm_source=mastodon&utm_medium=jetpack_social
-
Брешь в защите: Война Nightmare Eclipse. Часть 2
Хабр, привет! На связи Александр Бек, аналитик-исследователь угроз кибербезопасности R‑Vision. В первой части мы разобрали три PoC от Nightmare Eclipse — YellowKey, GreenPlasma и MiniPlasma. Это были совершенно разные техники: обход BitLocker через WinRE, низкоуровневый примитив на стыке CTF и Windows Object Managerи цепочка локального повышения привилегий (LPE), основанная на взаимодействии Cloud Files с Windows Error Reporting. Тогда стало понятно, что защищаться от этих техник приходится по-разному. В одних случаях телеметрии практически нет, в других — можно строить вполне рабочие детекты по реестру, процессам и файловой системе. В этой статье мы разберем оставшиеся пять PoC. Среди них — четыре уязвимости в Microsoft Defender (три LPE и одна DoS), а также еще один вариант обхода BitLocker через WinRE. Что особенно важно, три из этих техник уже были замечены в реальных атаках. В отличие от первой части, здесь мы сосредоточимся не только на механике эксплуатации, но и на том, какие артефакты оставляют эксплойты в системе, какие изменения происходят на устройствах Windows и на что стоит обратить внимание SOC- и threat hunting-командам при поиске следов компрометации.
https://habr.com/ru/companies/rvision/articles/1058972/
#информационная_безопасность #кибербезопасность #microsoft_defender #windows #уязвимости #threat_hunting #soc #bitlocker #lpe
-
Брешь в защите: Война Nightmare Eclipse. Часть 2
Хабр, привет! На связи Александр Бек, аналитик-исследователь угроз кибербезопасности R‑Vision. В первой части мы разобрали три PoC от Nightmare Eclipse — YellowKey, GreenPlasma и MiniPlasma. Это были совершенно разные техники: обход BitLocker через WinRE, низкоуровневый примитив на стыке CTF и Windows Object Managerи цепочка локального повышения привилегий (LPE), основанная на взаимодействии Cloud Files с Windows Error Reporting. Тогда стало понятно, что защищаться от этих техник приходится по-разному. В одних случаях телеметрии практически нет, в других — можно строить вполне рабочие детекты по реестру, процессам и файловой системе. В этой статье мы разберем оставшиеся пять PoC. Среди них — четыре уязвимости в Microsoft Defender (три LPE и одна DoS), а также еще один вариант обхода BitLocker через WinRE. Что особенно важно, три из этих техник уже были замечены в реальных атаках. В отличие от первой части, здесь мы сосредоточимся не только на механике эксплуатации, но и на том, какие артефакты оставляют эксплойты в системе, какие изменения происходят на устройствах Windows и на что стоит обратить внимание SOC- и threat hunting-командам при поиске следов компрометации.
https://habr.com/ru/companies/rvision/articles/1058972/
#информационная_безопасность #кибербезопасность #microsoft_defender #windows #уязвимости #threat_hunting #soc #bitlocker #lpe
-
Брешь в защите: Война Nightmare Eclipse. Часть 2
Хабр, привет! На связи Александр Бек, аналитик-исследователь угроз кибербезопасности R‑Vision. В первой части мы разобрали три PoC от Nightmare Eclipse — YellowKey, GreenPlasma и MiniPlasma. Это были совершенно разные техники: обход BitLocker через WinRE, низкоуровневый примитив на стыке CTF и Windows Object Managerи цепочка локального повышения привилегий (LPE), основанная на взаимодействии Cloud Files с Windows Error Reporting. Тогда стало понятно, что защищаться от этих техник приходится по-разному. В одних случаях телеметрии практически нет, в других — можно строить вполне рабочие детекты по реестру, процессам и файловой системе. В этой статье мы разберем оставшиеся пять PoC. Среди них — четыре уязвимости в Microsoft Defender (три LPE и одна DoS), а также еще один вариант обхода BitLocker через WinRE. Что особенно важно, три из этих техник уже были замечены в реальных атаках. В отличие от первой части, здесь мы сосредоточимся не только на механике эксплуатации, но и на том, какие артефакты оставляют эксплойты в системе, какие изменения происходят на устройствах Windows и на что стоит обратить внимание SOC- и threat hunting-командам при поиске следов компрометации.
https://habr.com/ru/companies/rvision/articles/1058972/
#информационная_безопасность #кибербезопасность #microsoft_defender #windows #уязвимости #threat_hunting #soc #bitlocker #lpe
-
https://nebusec.ai/research/ionstack-part-2/
Ladies and gentlemen! Another one!
A new new LPE. It even got his own name #GhostLock -
https://nebusec.ai/research/ionstack-part-2/
Ladies and gentlemen! Another one!
A new new LPE. It even got his own name #GhostLock -
https://nebusec.ai/research/ionstack-part-2/
Ladies and gentlemen! Another one!
A new new LPE. It even got his own name #GhostLock -
https://nebusec.ai/research/ionstack-part-2/
Ladies and gentlemen! Another one!
A new new LPE. It even got his own name #GhostLock -
https://nebusec.ai/research/ionstack-part-2/
Ladies and gentlemen! Another one!
A new new LPE. It even got his own name #GhostLock -
Dirty Clone – kolejny sposób na roota pod Linuksem
Nie tak dawno pisaliśmy o serii podatności Dirty Frag występujących w większości nowoczesnych dystrybucji Linuksa. I choć mogłoby się wydawać, że deweloperzy naprawili błędy, to najnowsze badania pokazują, że problem nie został jednak wyeliminowany. W jądrze pozostała bowiem niezałatana luka, którą badacze z JFrog ochrzcili mianem Dirty Clone (CVE-2026-43503). Podobnie...
#Aktualności #Eskalacja #Hacking #Kernel #Linux #LocalRoot #Lpe #PageCache
https://sekurak.pl/dirty-clone-kolejny-sposob-na-roota-pod-linuksem/
-
Dirty Clone – kolejny sposób na roota pod Linuksem
Nie tak dawno pisaliśmy o serii podatności Dirty Frag występujących w większości nowoczesnych dystrybucji Linuksa. I choć mogłoby się wydawać, że deweloperzy naprawili błędy, to najnowsze badania pokazują, że problem nie został jednak wyeliminowany. W jądrze pozostała bowiem niezałatana luka, którą badacze z JFrog ochrzcili mianem Dirty Clone (CVE-2026-43503). Podobnie...
#Aktualności #Eskalacja #Hacking #Kernel #Linux #LocalRoot #Lpe #PageCache
https://sekurak.pl/dirty-clone-kolejny-sposob-na-roota-pod-linuksem/
-
Dirty Clone – kolejny sposób na roota pod Linuksem
Nie tak dawno pisaliśmy o serii podatności Dirty Frag występujących w większości nowoczesnych dystrybucji Linuksa. I choć mogłoby się wydawać, że deweloperzy naprawili błędy, to najnowsze badania pokazują, że problem nie został jednak wyeliminowany. W jądrze pozostała bowiem niezałatana luka, którą badacze z JFrog ochrzcili mianem Dirty Clone (CVE-2026-43503). Podobnie...
#Aktualności #Eskalacja #Hacking #Kernel #Linux #LocalRoot #Lpe #PageCache
https://sekurak.pl/dirty-clone-kolejny-sposob-na-roota-pod-linuksem/
-
Dirty Clone – kolejny sposób na roota pod Linuksem
Nie tak dawno pisaliśmy o serii podatności Dirty Frag występujących w większości nowoczesnych dystrybucji Linuksa. I choć mogłoby się wydawać, że deweloperzy naprawili błędy, to najnowsze badania pokazują, że problem nie został jednak wyeliminowany. W jądrze pozostała bowiem niezałatana luka, którą badacze z JFrog ochrzcili mianem Dirty Clone (CVE-2026-43503). Podobnie...
#Aktualności #Eskalacja #Hacking #Kernel #Linux #LocalRoot #Lpe #PageCache
https://sekurak.pl/dirty-clone-kolejny-sposob-na-roota-pod-linuksem/
-
Dirty Clone – kolejny sposób na roota pod Linuksem
Nie tak dawno pisaliśmy o serii podatności Dirty Frag występujących w większości nowoczesnych dystrybucji Linuksa. I choć mogłoby się wydawać, że deweloperzy naprawili błędy, to najnowsze badania pokazują, że problem nie został jednak wyeliminowany. W jądrze pozostała bowiem niezałatana luka, którą badacze z JFrog ochrzcili mianem Dirty Clone (CVE-2026-43503). Podobnie...
#Aktualności #Eskalacja #Hacking #Kernel #Linux #LocalRoot #Lpe #PageCache
https://sekurak.pl/dirty-clone-kolejny-sposob-na-roota-pod-linuksem/
-
It received a CVE number: CVE-2026-53359. And there seems to be no mitigation until the fix arrives. You could unload the kvm module, but can you?
Also #AlmaLinux issued a blog post about it https://almalinux.org/blog/2026-07-06-januscape-bad-epoll/
-
It received a CVE number: CVE-2026-53359. And there seems to be no mitigation until the fix arrives. You could unload the kvm module, but can you?
Also #AlmaLinux issued a blog post about it https://almalinux.org/blog/2026-07-06-januscape-bad-epoll/
-
It received a CVE number: CVE-2026-53359. And there seems to be no mitigation until the fix arrives. You could unload the kvm module, but can you?
Also #AlmaLinux issued a blog post about it https://almalinux.org/blog/2026-07-06-januscape-bad-epoll/
-
It received a CVE number: CVE-2026-53359. And there seems to be no mitigation until the fix arrives. You could unload the kvm module, but can you?
Also #AlmaLinux issued a blog post about it https://almalinux.org/blog/2026-07-06-januscape-bad-epoll/
-
It received a CVE number: CVE-2026-53359. And there seems to be no mitigation until the fix arrives. You could unload the kvm module, but can you?
Also #AlmaLinux issued a blog post about it https://almalinux.org/blog/2026-07-06-januscape-bad-epoll/
-
woop woop. The bug is legit and w̶e̶ ̶a̶l̶l̶ ̶g̶o̶o̶n̶a̶ ̶d̶i̶e̶ expect a lot of hype around it. The blast is big: you need /dev/kvm accessible via guest (which is quite often)
I believe all major vendors have already prepared their fixes, so I guess it’s reboot time again.
-
woop woop. The bug is legit and w̶e̶ ̶a̶l̶l̶ ̶g̶o̶o̶n̶a̶ ̶d̶i̶e̶ expect a lot of hype around it. The blast is big: you need /dev/kvm accessible via guest (which is quite often)
I believe all major vendors have already prepared their fixes, so I guess it’s reboot time again.
-
woop woop. The bug is legit and w̶e̶ ̶a̶l̶l̶ ̶g̶o̶o̶n̶a̶ ̶d̶i̶e̶ expect a lot of hype around it. The blast is big: you need /dev/kvm accessible via guest (which is quite often)
I believe all major vendors have already prepared their fixes, so I guess it’s reboot time again.
-
woop woop. The bug is legit and w̶e̶ ̶a̶l̶l̶ ̶g̶o̶o̶n̶a̶ ̶d̶i̶e̶ expect a lot of hype around it. The blast is big: you need /dev/kvm accessible via guest (which is quite often)
I believe all major vendors have already prepared their fixes, so I guess it’s reboot time again.