Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • Linux Kernel 7.1 Reaches End of Life Do Son
    The Linux Kernel 7.1 EOL has officially arrived. Discover the final updates and learn why you must upgrade to the latest stable LTS releases immediately. Related Posts: CERN to Move 2,200 Accelerator Control Machines to Debian 13 Debian 11 Reaches End of Long Term Support Linux Nears USB4 Support for Apple Silicon The post Linux Kernel 7.1 Reaches End of Life appeared first on Daily CyberSecurity.
     

Linux Kernel 7.1 Reaches End of Life

Por:Do Son
7 de Setembro de 2026, 00:33

The Linux Kernel 7.1 EOL has officially arrived. Discover the final updates and learn why you must upgrade to the latest stable LTS releases immediately.

Related Posts:

The post Linux Kernel 7.1 Reaches End of Life appeared first on Daily CyberSecurity.

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash […]

The post Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Antes de ontemStream principal
  • ✇Cybersecurity News
  • CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation Do Son
    Security researchers released a Linux CVE-2026-52924 PoC exploit. Check flaw details and patch instructions to secure your systems against root takeovers. Related Posts: MikroTik RouterOS Vulnerability Exploited in the Wild: Patch and Defense Blueprint StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE The post CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CERN to Move 2,200 Accelerator Control Machines to Debian 13 Do Son
    CERN's Debian migration moves 2,200+ accelerator control machines off Red Hat, driven by RHEL's raised x86-64 CPU baseline. Related Posts: Debian 11 Reaches End of Long Term Support Linux Nears USB4 Support for Apple Silicon Debian AI Policy: Responsible Generative AI Use Wins Vote The post CERN to Move 2,200 Accelerator Control Machines to Debian 13 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Debian 11 Reaches End of Long Term Support Do Son
    Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version. Related Posts: Linux Nears USB4 Support for Apple Silicon Debian AI Policy: Responsible Generative AI Use Wins Vote California Exempts Linux from Age Verification The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.
     

Debian 11 Reaches End of Long Term Support

Por:Do Son
1 de Setembro de 2026, 22:18

Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version.

Related Posts:

The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Linux Nears USB4 Support for Apple Silicon Do Son
    Discover how the Asahi Linux project is successfully pushing vital USB4 protocol drivers for Apple Silicon directly into the mainline Linux kernel. Related Posts: Debian AI Policy: Responsible Generative AI Use Wins Vote California Exempts Linux from Age Verification Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes The post Linux Nears USB4 Support for Apple Silicon appeared first on Daily CyberSecurity.
     

Linux Nears USB4 Support for Apple Silicon

Por:Do Son
31 de Agosto de 2026, 23:31

Discover how the Asahi Linux project is successfully pushing vital USB4 protocol drivers for Apple Silicon directly into the mainline Linux kernel.

Related Posts:

The post Linux Nears USB4 Support for Apple Silicon appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Debian AI Policy: Responsible Generative AI Use Wins Vote Do Son
    Debian's AI policy vote picked "Responsible Use of Generative AI": AI is neither banned nor endorsed, with full accountability left to contributors. Related Posts: Linux Nears USB4 Support for Apple Silicon California Exempts Linux from Age Verification Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes The post Debian AI Policy: Responsible Generative AI Use Wins Vote appeared first on Daily CyberSecurity.
     

Debian AI Policy: Responsible Generative AI Use Wins Vote

Por:Do Son
31 de Agosto de 2026, 10:02

Debian's AI policy vote picked "Responsible Use of Generative AI": AI is neither banned nor endorsed, with full accountability left to contributors.

Related Posts:

The post Debian AI Policy: Responsible Generative AI Use Wins Vote appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw Do Son
    A public proof-of-concept for the CVE-2026-52933 privilege escalation flaw is available. This Linux kernel io_uring exploit carries a CVSS 7.8 score. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover The post PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • California Exempts Linux from Age Verification Do Son
    California passes AB-1856, exempting open-source operating systems like Linux from the burdensome age verification mandates of the Digital Age Assurance Act. Related Posts: Debian AI Policy: Responsible Generative AI Use Wins Vote Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes Framework Laptop 12: Upgraded with Intel Core Series 3 The post California Exempts Linux from Age Verification appeared first on Daily CyberSecurity.
     

California Exempts Linux from Age Verification

Por:Do Son
31 de Agosto de 2026, 04:55

California passes AB-1856, exempting open-source operating systems like Linux from the burdensome age verification mandates of the Digital Age Assurance Act.

Related Posts:

The post California Exempts Linux from Age Verification appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes Do Son
    Canonical releases Ubuntu 26.04.1 LTS, consolidating security patches and resolving critical desktop, hardware, and installation bugs for new deployments. Related Posts: Framework Laptop 12: Upgraded with Intel Core Series 3 WSL Ubuntu Installations Threaten Native Desktop Dominance Linux Kernel 7.2 Arrives with Extensive Updates The post Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes appeared first on Daily CyberSecurity.
     

Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes

Por:Do Son
28 de Agosto de 2026, 04:20

Canonical releases Ubuntu 26.04.1 LTS, consolidating security patches and resolving critical desktop, hardware, and installation bugs for new deployments.

Related Posts:

The post Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes appeared first on Daily CyberSecurity.

  • ✇Cyber Security News
  • CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks Abinaya
    The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks. The issue affects the Linux kernel’s IPv6 networking subsystem. It could allow a local attacker to gain elevated privileges on a vulnerable system. CVE-2026-53362 is currently described as an unspecified Linux kernel vulnerability. However, CI
     

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

28 de Agosto de 2026, 03:41

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks.

The issue affects the Linux kernel’s IPv6 networking subsystem. It could allow a local attacker to gain elevated privileges on a vulnerable system.

CVE-2026-53362 is currently described as an unspecified Linux kernel vulnerability. However, CISA said the flaw can enable privilege escalation through the IPv6 networking component.

Privilege escalation flaws are especially dangerous because an attacker with limited access to a Linux host may be able to obtain higher permissions, potentially including root-level control.

The vulnerability may affect Linux distributions and products that use the Linux kernel, including SUSE, Red Hat, and other vendor platforms.

Organizations should not assume that only these named distributions are affected, since the exposure depends on the kernel version, vendor build, configuration, and the availability of security fixes or mitigations.

Linux Kernel Privilege Escalation Vulnerability Exploited

CISA added CVE-2026-53362 to the catalog on August 27, 2026, and set a remediation deadline of August 30, 2026, for federal civilian executive branch agencies.

The agency has also marked the vulnerability as requiring forensic triage under Binding Operational Directive 26-04, indicating that affected organizations should assess whether exploitation has already occurred before or during patch application.

Although CISA has not linked the flaw to a specific ransomware operation, privilege-escalation vulnerabilities are often valuable to attackers once they have initial access.

A threat actor may exploit such weaknesses after gaining a foothold through stolen credentials, a vulnerable public-facing application, phishing, or a compromised cloud workload.

Elevated privileges can enable attackers to turn off security tools, access sensitive data, move laterally, and deploy ransomware across an environment.

CISA instructed organizations to apply mitigations in accordance with vendor guidance and to follow the risk-based security update requirements in BOD 26-04.

Where a vendor patch is unavailable, stakeholders should evaluate whether compensating controls can reduce exposure. CISA also stated that organizations should discontinue use of affected products if mitigations are not available.

Linux administrators should immediately identify internet-facing and business-critical systems running potentially affected kernel versions.

Security teams should review authentication activity, privilege changes, unexpected kernel-related errors, suspicious processes running as root, and endpoint detection alerts for signs of post-compromise activity.

Because details of exploitation remain limited, organizations should closely monitor updates from Linux distribution vendors and CISA.

The immediate priority is to determine which Linux assets rely on potentially affected kernels, apply vendor fixes, and conduct forensic triage on high-risk systems.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks appeared first on Cyber Security News.

  • ✇Cybersecurity News
  • CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution Do Son
    TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution appeared first on Daily C
     
  • ✇Securelist
  • Exploits and vulnerabilities in Q2 2026 Alexander Kolesnikov
    The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these can
     

Exploits and vulnerabilities in Q2 2026

26 de Agosto de 2026, 07:00

The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.

Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these can generate significant fallout, since they potentially open the door for attackers to target unprotected systems.

Statistics on registered vulnerabilities

This section provides statistical data on registered vulnerabilities. The data comes from Kaspersky’s vulnerability knowledge base, which draws on the CVE database as well as the Russian BDU database and GitHub Advisory (GHSA). As a result, the figures for previous reporting periods may differ from those published in earlier reports.

We examine the number of registered vulnerabilities for each month over the last five years. As the chart below shows, this number continues to surge, a trend reflected across all the databases we track. It’s driven primarily by the widespread adoption of AI tools: as we predicted in our previous report, these tools have played a major role in the discovery of vulnerabilities in third-party software. Meanwhile, these tools often contain security issues of their own. For example, OpenClaw, a popular AI project, ranked 12th among those with the highest number of vulnerabilities discovered and published in Q2, with over 200 CVEs registered during the reporting period. Finally, AI development tools are also contributing to the vulnerability landscape, since the quality of the code they produce can vary widely. Therefore, the rate at which new vulnerabilities are discovered will inevitably keep growing.

Total published vulnerabilities per month from 2022 through 2026 (download)

Next, we analyze the number of new critical vulnerabilities (CVSS > 9.0) over the same period.

Total critical vulnerabilities published per month from 2022 through 2026 (download)

As the chart shows, the number of published critical vulnerabilities jumped sharply in Q2. This is because using AI for vulnerability research makes it possible to analyze massive amounts of previously unexamined code, uncover new attack surfaces, and identify entire classes of vulnerabilities that have gone unnoticed for decades. In particular, AI was used to find a series of Dirty Frag vulnerabilities in the Linux kernel.

Exploitation statistics

This section presents statistics on vulnerability exploitation for Q2 2026. The data draws on open sources and our telemetry.

Windows and Linux vulnerability exploitation

Q2 2026 saw a new precedent in the publication of vulnerabilities in Windows components and exploits for these: researchers no longer waiting for CVE registration, let alone patches. A case in point: a researcher who goes by Nightmare Eclipse (also known as Chaotic Eclipse) published a list of new “named” vulnerabilities across various Windows subsystems. At the time the technical details were published, none of the vulnerabilities had been assigned a CVE identifier:

  • BlueHammer: a local privilege escalation vulnerability in Windows Defender. During signature database updates, a time-of-check to time-of-use (TOCTOU) race condition occurs, allowing an attacker to substitute the directory where temporary update files are written. The researcher published a fully functional exploit for the vulnerability.
  • RedSun: another logical vulnerability in Windows Defender with a working exploit. Suspicious and malicious files marked as “cloud” can be overwritten or restored to their original directory with elevated privileges. The exploit incorporates fragments of algorithms that make it possible to leverage various logical vulnerabilities in Windows, effectively combining a large number of popular exploitation techniques.
  • YellowKey: a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE). A fully functional exploit was also published.
  • GreenPlasma: a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows. The original publication included an exploit with limited functionality.
  • RoguePlanet: yet another Windows Defender vulnerability that, like BlueHammer, stems from a TOCTOU issue, this time in the engine responsible for real-time system scanning. The published exploit uses the vulnerability to overwrite the system file wermgr.exe with a malicious one.
  • UnDefend: another vulnerability in the Windows Defender service. This time, the exploit causes a denial of service and blocks updates.

Even though such cases remain isolated for now, we believe they’ll grow into a full-fledged trend. Early publication of exploits gives attackers an advantage over software developers, who are left with no time to fix the issues.

Veteran vulnerabilities in Windows software also remain relevant. These are the ones our solutions most frequently detect exploits for:

  • CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
  • CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
  • CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
  • CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
  • CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
  • CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218. The attackers used NTFS Streams to circumvent controls on the directory into which files are being unpacked

The vulnerabilities listed here can be leveraged to gain initial access to a vulnerable system and for privilege escalation. This underscores the critical importance of timely software updates.

That said, the number of Windows users who encountered exploits declined slightly in Q2, hitting an 18-month low.

Dynamics of the number of Windows users encountering exploits, Q1 2025 – Q2 2026. The number of users who encountered exploits in Q1 2025 is taken as 100% (download)

Linux also hit a rough patch in Q2 2026. Specifically, the period saw the disclosure of the Dirty Frag family of vulnerabilities, which lets an attacker reliably escalate privileges within the operating system.

All the vulnerabilities published in Q2 2026 were, in one way or another, related to the Linux caching subsystem. Here are the ones being most actively exploited:

  • CVE-2026-31431 (Copy Fail): a local privilege escalation vulnerability in the Linux kernel that lets an unprivileged user modify the page cache and gain root privileges. Especially dangerous for cloud and containerized environments
  • CVE-2026-43284, CVE-2026-43500 (Dirty Frag): a family of vulnerabilities in the Linux networking subsystem (IPsec ESP and RxRPC) that lets a local user overwrite the page cache and escalate privileges to root
  • CVE-2026-46300 (Fragnesia): a local privilege escalation vulnerability in the Linux kernel related to packet fragment handling and the page cache mechanism. It lets an unprivileged user gain root privileges and is also classified as part of the Dirty Frag family
  • CVE-2026-31635 (DirtyDecrypt): a Linux kernel vulnerability that lets a local attacker escalate privileges due to improper handling of decryption operations and page cache data modification
  • CVE-2026-43494 (PinTheft): a Linux kernel vulnerability that lets a local user gain elevated privileges due to errors in the memory page pinning mechanism
  • CVE-2026-46331 (pedit COW): a vulnerability in the Linux kernel’s traffic control subsystem (tc-pedit) that exploits a flaw in copy-on-write to modify the page cache and subsequently escalate privileges to root

The vulnerabilities described above were quickly embraced by attackers. At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:

  • CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
  • CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
  • CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
  • CVE-2023-32233: another Netfilter subsystem vulnerability that allows for Use-After-Free conditions and privilege escalation through improper processing of network requests

Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026. The number of users who encountered exploits in Q1 2025 is taken as 100% (download)

In Q2 2026, the number of Linux users who encountered exploits declined slightly compared to Q1. Given that a significant share of new vulnerabilities are tied to the operating system’s caching subsystem, we recommend installing patches as quickly as possible, or disabling vulnerable kernel modules if patching isn’t an option.

Most common published exploits

The distribution of published exploits by software type in Q2 2026 includes categories that haven’t appeared in the sample for a long time. For instance, we’re once again seeing exploits targeting SharePoint. It’s worth noting that while several vulnerability write-ups for Exchange and SharePoint were published during the quarter, most turned out to be fake, AI-generated research. While the articles and exploit source code themselves look fairly polished, they describe nonexistent problems in the software or its components — often close to genuinely vulnerable mechanisms — in order to mislead researchers. This type of attack is aimed at increasing the time it takes to detect real vulnerabilities. In some cases, the description of a nonexistent vulnerability came bundled with completely unrelated malware.

Distribution of published exploits by platform, Q1 2026 (download)

Distribution of published exploits by platform, Q2 2026 (download)

Vulnerability exploitation in APT attacks

We analyzed which vulnerabilities were exploited in APT attacks during Q2 2026. The rankings provided below include data based on our telemetry, research, and open sources.

TOP 10 vulnerabilities exploited in APT attacks, Q2 2026 (download)

In Q2 2026, a trend emerged in APT attacks toward exploiting new vulnerabilities right from the moment they’re published. As before, we’re also seeing a large number of zero-day vulnerabilities. The Langflow vulnerability deserves particular attention: it’s one of the first cases of an APT group exploiting AI technology, which many organizations are only just beginning to integrate. Because most of this tech is proprietary, it has a considerable number of security blind spots. Therefore, given the growing number of AI-based automation tools, we strongly recommend going beyond the usual patching and developing secure procedures for credential use and sensitive data handling in systems that rely on agents and LLMs.

C2 frameworks

In this section, we examine the most popular C2 frameworks used by APT groups and analyze the vulnerabilities targeted by the exploits that interacted with C2 agents in APT attacks.

The chart below shows the frequency of known C2 framework usage in attacks during Q2 2026, according to open sources.

TOP 10 C2 frameworks used by APTs to compromise user systems, Q2 2026 (download)

Sliver, Havoc, AdaptixC2, and Metasploit remain the most widely used C2 frameworks. After studying open sources and analyzing samples of malicious C2 agents that contained exploits, we determined that the following vulnerabilities were utilized in APT attacks involving the C2 frameworks mentioned above:

  • CVE-2026-35273: a vulnerability in Oracle PeopleSoft PeopleTools that security vendors classify as server-side request forgery (SSRF). The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
  • CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
  • CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
  • CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
  • CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
  • CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user

These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent. They include both zero-day vulnerabilities and fairly well-known security issues.

LLM/AI tool vulnerabilities

This section analyzes data published in Kaspersky’s vulnerability knowledge base. We reviewed the Q2 2026 version of the knowledge base.

As mentioned above, AI tools, plugins, and technologies have proven fairly effective at automating the search for problematic code and anomalous behavior. The high speed at which new vulnerabilities are being discovered has naturally created a need to fix them just as quickly. AI is often used for this too, which increases the volume of code being generated. However, neither code written without human involvement nor AI-generated advice is always correct.

The chart below covers registered vulnerabilities in AI tools for 2025–2026.

Number of published vulnerabilities in LLMs, AI tools, and plugins with similar functionality, 2025–2026 (download)

As the charts show, AI tools are racking up a substantial number of registered vulnerabilities, and that number keeps growing quarter over quarter. It’s also worth looking at how AI tool vulnerabilities break down by type, according to the CWE system:

TOP 6 vulnerability types in products that implement or use AI/LLM logic, 2025–2026

TOP 6 vulnerability types in products that implement or use AI/LLM logic, 2025–2026

Interestingly, vulnerabilities of an undetermined type have ranked first in every quarter since the start of 2025. Traditionally-made software has the same issue, and it doesn’t look like the growing number of AI tools will fix it. It’s also notable that the list includes classes CWE developers themselves don’t recommend using for vulnerability classification, since they lump together a whole range of more specific types. CWE-284 is an example of this.

Looking at the most common classes, the key issues found in AI-related software can be summed up as follows:

  • Inadequate access control over critical system objects
  • Improper implementation of authentication and authorization mechanisms
  • Injections

It’s worth noting that injection-related vulnerabilities were relatively rare before AI agents took off (previously, they mostly affected web apps). Recently, though, these security issues have become relevant again.

Looking back at a year and a half of the AI boom, one conclusion stands out regarding registered vulnerabilities: AI tool developers are more focused on expanding functionality than on security. This is worth keeping in mind when using these tools. Let’s look at the projects and applications that either integrated AI tools or offered them as the core product. Below is a list of the those with the highest number of registered vulnerabilities for 2025–2026.

TOP AI/LLM-related projects by number of published vulnerabilities, 2025–2026 (download)

Notable vulnerabilities

This section highlights the most significant vulnerabilities published in Q2 2026 that have publicly available descriptions. Since the above already covers several significant vulnerabilities published during the reporting period, this section consists mainly of LLM/AI tool vulnerabilities.

CVE-2026-25253: a gatewayUrl vulnerability in OpenClaw

The issue stems from the fact that the OpenClaw user interface trusts the value of the gatewayUrl parameter passed in the URL and automatically establishes a WebSocket connection to the specified address. During this connection process, it sends an authentication token without any additional user confirmation.

The attack algorithm exploiting this vulnerability works as follows:

  1. The application obtains a critical connection address from an external source (the gatewayUrl URL parameter), which is controlled by the attacker.
  2. There is no validation before use.
  3. The client automatically initiates a connection to the address specified in the parameter, which belongs to the attacker.
  4. While connected, the application sends credentials (an access token) to the specified address.

If the attacker obtains a valid token, the consequences depend on that token’s level of access within the system. In general, this could lead to:

  • User session compromise
  • Execution of operations on the user’s behalf
  • Modification of the AI agent configuration
  • Unauthorized access to tools and resources connected to the agent
  • Under certain OpenClaw configurations, further compromise of the host running the agent

It’s worth noting that the risk of exploitation arises from a combination of several factors: the automatic connection and token transmission, the lack of address trust verification, and the high privileges granted to the local AI agent.

CVE-2026-41948: a path traversal vulnerability in the Dify AI platform

The vulnerability lets an authenticated user craft a request that enables the application to escape its permitted tenant and gain access to internal REST APIs that weren’t meant for that user. The root cause is insufficient normalization and validation of the URL path before it’s passed to the internal service.

Depending on the Dify configuration, the consequences can include:

  • Unauthorized access to internal service interfaces
  • Breach of isolation between workspaces
  • Exposure of internal service information
  • Conditions favorable to further attacks when combined with other vulnerabilities

The use of Dify in enterprise AI platforms is particularly risky, since internal services there tend to hold elevated privileges.

CVE-2026-45386: an improper access control vulnerability in Open WebUI

In Open WebUI, pin/unpin operations on messages are write operations, since they modify that message’s metadata (is_pinned, pinned_by, pinned_at). In vulnerable versions, however, before performing these actions, the API only checked for read access to the channel (a chat between a user or group and the AI) containing the message, not permission to modify its content. As a result, a user with a role limited to viewing messages could still change a message’s pinned status.

The vulnerability’s mechanism works as follows:

  1. The user initiates an action that changes the state of an object.
  2. The application treats this action as a regular read request.
  3. Only channel view permission is checked.
  4. The application performs a write without verifying the required user authorization.

This violates one of the fundamental principles of access control models — namely, that any operation that changes the state of data must be checked for the appropriate write or moderation permissions, regardless of whether the object itself is readable.

Although the vulnerability doesn’t lead to arbitrary code execution or compromise of sensitive data, it can affect data integrity and collaborative workflows. Potential consequences of exploitation include unauthorized pinning or unpinning of messages, disruption of channel moderators’ and administrators’ activities, changes to the display order of important information, and even the potential spread of false or misleading information by altering the channel containing a pinned message.

Open WebUI is widely used as an interface for interacting with local and enterprise LLMs. In these systems, pinned messages often contain important instructions, announcements, or tips for users. The ability to modify them with minimal privileges can disrupt collaborative workflows, cause confusion, and undermine trust in information published by administrators and moderators.

CVE-2026-45501: a vulnerability in Microsoft Exchange

The vulnerability stems from improper neutralization of user input when generating Exchange web pages. As a result, the browser may interpret specially crafted data as active content instead of plain text.

Although Microsoft categorizes the potential impact of exploiting this vulnerability as spoofing, flaws like this can lead to alteration of displayed content, imitation of trusted interfaces, actions on behalf of the user within an active session, and abuse of user trust.

It’s worth noting that issues like this are still relevant in modern software, given that mechanisms like Content Security Policy and various parsers were specifically created to help developers neutralize dangerous parts of user page content.

Conclusion and advice

Q2 brought the first significant results of AI automation adoption in software development and vulnerability hunting tools. This research shows that beyond traditional patch management, organizations now need real-time monitoring of systems and access controls, since infrastructure and everyday applications now contain far more AI functionality that could lead to compromise.

Accordingly, besides quickly detecting infrastructure vulnerabilities and managing security patches, modern enterprise-grade security solutions need to provide a broad range of preventive measures for tracking the overall health of systems and workstations. Kaspersky Next meets these requirements by combining proactive mechanisms with the ability to respond promptly to emerging threats.

  • ✇Cybersecurity News
  • Public PoC for CVE-2026-52923 Allows Attackers to Escalate to Root Privilege Do Son
    A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details. Related Posts: CVE-2026-77136: TYPO3 Powermail RCE Flaw Exploited in the Wild Weidmueller Router Flaw CVE-2026-63586 With CVSS 9.8 Allows Attackers To Execute Arbitrary Commands With Root Privileges Fake AI PoCs Flood Exploit Repositories in 2026 The post Public PoC for CVE-2026-52923 Allows Attackers to Escalate to Root Privilege appeared fi
     
  • ✇Cybersecurity News
  • Framework Laptop 12: Upgraded with Intel Core Series 3 Do Son
    Discover the new Framework Laptop 12 featuring Intel Core Series 3 processors, a 70 percent battery boost, and default Fedora Linux OS configuration. Related Posts: WSL Ubuntu Installations Threaten Native Desktop Dominance Linux Kernel 7.2 Arrives with Extensive Updates Tails 7.10.1 Fixes Critical Linux Kernel Vulnerability The post Framework Laptop 12: Upgraded with Intel Core Series 3 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • WSL Ubuntu Installations Threaten Native Desktop Dominance Do Son
    Canonical reveals that Ubuntu installations on the Windows Subsystem for Linux (WSL) are surging, soon surpassing native desktop deployments due to AI tools. Related Posts: Linux Kernel 7.2 Arrives with Extensive Updates Tails 7.10.1 Fixes Critical Linux Kernel Vulnerability Proxmox VE Formally Launches Arm64 Architecture Support The post WSL Ubuntu Installations Threaten Native Desktop Dominance appeared first on Daily CyberSecurity.
     

WSL Ubuntu Installations Threaten Native Desktop Dominance

Por:Do Son
18 de Agosto de 2026, 01:30

Canonical reveals that Ubuntu installations on the Windows Subsystem for Linux (WSL) are surging, soon surpassing native desktop deployments due to AI tools.

Related Posts:

The post WSL Ubuntu Installations Threaten Native Desktop Dominance appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Linux Kernel 7.2 Arrives with Extensive Updates Do Son
    Following extensive testing, Linux Kernel 7.2 is now available. Discover the latest updates regarding hardware drivers, file systems, and kernel security. Related Posts: WSL Ubuntu Installations Threaten Native Desktop Dominance Tails 7.10.1 Fixes Critical Linux Kernel Vulnerability Proxmox VE Formally Launches Arm64 Architecture Support The post Linux Kernel 7.2 Arrives with Extensive Updates appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • New Mirai-Based Evooo1Bot Botnet Targets Linux Devices Pierluigi Paganini
    Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module on top. “FortiGuard Labs has been tracking a pr
     

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

18 de Agosto de 2026, 04:18

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services.

Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module on top.

“FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.” reads the report published by Fortinet. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities.”

The botnet targets 18 known CVEs, some of them dating back to 2007, including:

  • CVE-2007-3010: Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
  • CVE-2016-6277: NETGEAR Multiple Routers Remote Code Execution Vulnerability
  • CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
  • CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
  • CVE-2020-10987: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
  • CVE-2021-46422: Telesquare SDT-CW3B1 Command Injection vulnerability
  • CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability
  • CVE-2024-29269, Telesquare TLR-2005KSH Command Injection Vulnerability
  • CVE-2025-10123, D-Link DIR-823X Command Injection Vulnerability
  • CVE-2025-55583: D-Link DIR-868L B1 router Command Injection Vulnerability

The bot communicates exclusively over port 443, which is intentional: the traffic blends into expected HTTPS flows at the network perimeter. After gaining initial access through one of its exploit modules or via brute-forced SSH credentials, the bot runs a loader script that clears Bash history to erase evidence of the intrusion before pulling the architecture-appropriate binary from an external server.

The breadth suggests the operators are scanning opportunistically for anything unpatched rather than targeting specific organizations.

“This capability significantly increases the value of an infected host to attackers. The victim’s IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine.” continues the report. “In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services.”

Evooo1Bot stands out because of its proxy module. A network of compromised routers, cameras, and firewalls acting as SOCKS5 relays is a valuable commodity; operators can use it themselves to obscure attack traffic, or sell access to other criminals looking for residential or enterprise IP addresses that don’t trigger geographic blocks.

“Unlike typical botnet commands that focus on downloading payloads or launching attacks, the !socks module turns an infected host into a SOCKS5 proxy that the operator can use as a network relay. It supports two operating modes. In direct mode, it opens a SOCKS5 listener on the infected host on the default TCP port 1080 and waits for incoming client connections. The implementation first attempts to create a dual-stack IPv6 listener and falls back to IPv4 if that fails. Each accepted client is then passed to the session handler for proxying.” continues the report. “The botnet also implements a reverse relay mode. Instead of exposing a listening port, the bot establishes an outbound encrypted connection to an operator-specified relay server. This persistent control channel listens for commands such as RELAY_NEW:<session_id>, which indicate that a new proxy session should be created.”

After establishing C2 contact, the bot accepts commands covering the full post-compromise toolkit: file upload and download, interactive shell access, persistence installation, binary updates, HTTP Basic Auth and Cookie header interception, DDoS over DNS, TCP, and UDP, and the HTTP exploit dispatcher.

The credential sniffer intercepts authentication headers in transit, so any HTTP Basic Auth credentials passing through an infected device can be captured without any additional effort from the operator. If you’re still running devices with unpatched firmware from the CVE list above, or if any of your edge hardware is using default SSH credentials, Evooo1Bot is already scanning for you.

“Beyond traditional botnet functionality, it features encrypted C2 communications, multiple layers of string obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation, as well as a 28-command remote administration interface.” concludes the report. “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Evooo1Bot botnet)

  • ✇Cybersecurity News
  • ChatGPT for Linux Desktop Preview Launches for Ubuntu, Debian, and Fedora Do Son
    OpenAI launches ChatGPT for Linux desktop in preview, supporting Ubuntu, Debian, and Fedora with ChatGPT, Codex, and Work features. Related Posts: Apple Proposes New App Store Link-Out Fees of 5% to 15% in Epic Legal Battle Microsoft Copilot Super App: A Unified Platform Vision Mozilla Rotates Firefox and Thunderbird Linux GPG Signing Key After Private Repo Exposure The post ChatGPT for Linux Desktop Preview Launches for Ubuntu, Debian, and Fedora appeared first on Daily CyberSecurity.
     
❌
❌