
An AI Auditor Missed the Linux Bug That Gives Root
Bad Epoll (CVE-2026-46242) hands any local user root on Linux 6.4 and newer, including Android. The fix has been in mainline since April but many distros have not shipped it.

Bad Epoll (CVE-2026-46242) hands any local user root on Linux 6.4 and newer, including Android. The fix has been in mainline since April but many distros have not shipped it.

Squidbleed (CVE-2026-47729) is a one-line flaw that let any user of a shared Squid proxy read other people's cleartext HTTP requests, including passwords and session tokens. It hid in default configs for 29 years, and an AI agent found it, not a human audit.

A new attack kit called Avalon hunts your backup servers and deletes Windows shadow copies before its CrownX ransomware encrypts anything. It sat undetected for four months while evading nine major security tools.

CVE-2026-46242, Bad Epoll, lets any local user become root on Linux 6.4+ servers and Android at 99 percent reliability. What owners of Linux fleets should do now.

Seven FatFs bugs, six of them unpatched, ship inside cameras, drones, ATMs and crypto wallets via ESP-IDF, STM32Cube and Zephyr. Why owners must audit their device bill of materials.

CISA added SharePoint flaw CVE-2026-45659 to its exploited-vulnerabilities list on 1 July. Microsoft rated it unlikely to be attacked. The patch has existed since May, and under NIS2 the clock is yours.

A password-spray campaign threw 81 million login attempts at Microsoft 365 in two weeks and got past multi-factor authentication - not with a new exploit, but by abusing a legacy sign-in path that skips MFA.

Microsoft has pulled its quantum-safe deadline forward four years to 2029. The reason is not future quantum computers. It is the data being stolen today.

Two critical Cursor flaws rated 9.8 let a poisoned web page or tool result seize a developer's machine. What DuneSlide means for owners, and what to do this week.

Black Kite's 2026 report shows one supplier breach drove over half of Europe's third-party ransomware victims. Under NIS2 and DORA, the liability is yours.

Anthropic's Cyber Jailbreak Severity scale turns AI safety into a procurement and audit criterion, the way CVSS did for software bugs. What owners should demand.

Google and the FBI disrupted NetNut, a residential proxy network of at least 2 million home devices used by 316 threat clusters in one week. Why IP reputation is dead and your devices are the new perimeter.
Page 15 / 17
One considered note on infrastructure, governance, and measurement, most mornings. No theory.