SCTPhantom: An 18-Year-Old Linux Kernel UAF That Escapes Containers to Root

Overview Attribute Value CVE CVE-2026-64564 Name SCTPhantom Type Use-After-Free (UAF) → Local Privilege Escalation + Container Escape CVSS 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Affected Linux kernel 2.6.25 → 7.1.x (introduced 2007, ~18 years) Fixed 6.6.148, 6.12.101, 6.18.42, 7.1.6, mainline 7.2-rc5 Researcher Tencent Zhuque Lab (via Corvus AI pipeline) PoC ✅ Public (reproducible exploit demonstrated) CISA KEV ❌ Not yet listed Patch ✅ Upstream (mainline commit 9b2854f86f0b) What Is SCTPhantom? SCTPhantom is a use-after-free in the Linux kernel’s SCTP (Stream Control Transmission Protocol) Dynamic Address Reconfiguration implementation. An attacker who can reach the SCTP stack can trigger a stale-pointer dereference that leads to full root on the host — and, critically, escape a container to compromise the underlying host. ...

GhostLock: The 15-Year-Old Linux Kernel Bug AI Found Hiding in Plain Sight

GhostLock: The 15-Year-Old Linux Kernel Bug AI Found Hiding in Plain Sight TL;DR An AI-powered security agent discovered a Linux kernel vulnerability that has existed in every major distribution since 2011. It allows any unprivileged local user to gain full root access with a 97% success rate. There is no practical mitigation — patch your kernel. Attribute Detail CVE CVE-2026-43499 CVSS 3.1 7.8 (HIGH) — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE CWE-416 (Use After Free) Affected Linux 2.6.39 through 7.0 Fixed Linux 7.1 (commit 3bfdc63936dd) Stable backports 6.1.177, 6.6.144, 6.12.95, 6.18.36, 7.0.13 Not backported 5.15.y, 5.10.y LTS Discovered by VEGA AI Agent (Nebula Security) Bounty $92,337 (Google kernelCTF) Prerequisites Local access, no special privileges, CONFIG_FUTEX_PI=y What Is GhostLock? GhostLock (CVE-2026-43499) is a use-after-free vulnerability in the Linux kernel’s real-time mutex (rtmutex) priority-inheritance code. Specifically, it lives in the remove_waiter() function in kernel/locking/rtmutex.c. ...

CVE-2022-0492: Linux Kernel Cgroups Release Agent Container Escape

CVE-2022-0492: Linux Kernel Cgroups v1 release_agent Container Escape Executive Summary CVE-2022-0492 is a privilege escalation vulnerability in the Linux kernel’s cgroup_release_agent_write function (kernel/cgroup/cgroup-v1.c). It allows a root process inside a container to escape to the host and gain full root privileges by abusing the cgroups v1 release_agent mechanism via user namespaces. Attribute Detail CVE CVE-2022-0492 CVSS 3.1 7.8 (HIGH) — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE CWE-862 (Missing Authorization) / CWE-287 (Improper Authentication) Affected Linux kernel v2.6.24 through v5.16.6 Fixed Linux 5.17-rc3 (commit 24f6008564183) Type Container escape via cgroups v1 release_agent CISA KEV ✅ Added June 2, 2026 — actively exploited Public PoC ✅ Multiple (GitHub) Background: What is release_agent? cgroups v1 has a feature called release_agent — a path to a binary the kernel executes as root when a process in a child cgroup terminates (if notify_on_release is enabled). It lives in any cgroup v1 root directory: ...

Weekly Threat & Lab Roundup: Microsoft Defender Zero-Days, Qualcomm BootROM Write-What-Where, Fox Tempest Malware Signing Service, and GitHub Supply Chain Siege

This week the theme is trust erosion — in the tools that protect us, the chips that boot our devices, the certificates that vouch for software, and the platforms that host our code. Microsoft Defender, the very security product meant to protect Windows endpoints, has two actively exploited zero-days: one that grants SYSTEM and another that kills antimalware. Qualcomm’s BootROM — the immutable root of trust in billions of devices — has a write-what-where condition that turns a phone repair into a persistence attack. Fox Tempest operated a malware-signing-as-a-service that generated over a thousand fraudulent code-signing certificates, enabling ransomware operators to dress their payloads in legitimate Microsoft signatures. And GitHub is under coordinated assault from multiple directions: Megalodon hijacks repositories through malicious workflows, TeamPCP poisons VSCode extensions, and Socket discovers malicious postinstall hooks across 700+ repositories. Meanwhile in the lab, OpenClaw got a feature-heavy upgrade, Obsidian CLI integration landed, the package tracker got a rewrite, and the homelab held steady with new Proxmox snapshots. ...

Cybersecurity alert

Microsoft Defender Double Zero-Day: LPE + DoS Actively Exploited in the Wild

Overview Attribute CVE-2026-41091 CVE-2026-45498 Type Local Privilege Escalation Denial of Service Component Malware Protection Engine Antimalware Platform Affected Engine ≤ 1.1.26030.3008 Platform ≤ 4.18.26030.3011 CWE CWE-59 (Link Following) — Impact Standard user → SYSTEM Defender disabled / system unresponsive Exploit ✅ Active in the wild ✅ Active in the wild Patch Engine 1.1.26040.8 Platform 4.18.26040.7 CISA KEV ✅ Added 2026-05-20 ✅ Added 2026-05-20 FCEB Deadline June 3, 2026 June 3, 2026 Microsoft has started rolling out patches for two actively exploited zero-day vulnerabilities in Microsoft Defender. Both were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on May 20, with federal agencies ordered to patch within two weeks. ...

Windows privilege escalation exploit visualization

MiniPlasma — The Ghost Patch: A 5-Year-Old Windows LPE That Never Died

TL;DR MiniPlasma is a Windows local privilege escalation exploit that achieves standard user → SYSTEM on fully patched Windows 11 systems (including the May 2026 Patch Tuesday updates). The jaw-dropper? It targets the exact same vulnerability that Google Project Zero reported in September 2020 and Microsoft claimed to fix in December 2020. CVE: CVE-2020-17103 (CVSS 7.0) — supposedly patched Component: cldflt.sys — Windows Cloud Files Minifilter driver Flaw: TOCTOU race condition in HsmOsBlockPlaceholderAccess Impact: Full SYSTEM shell from standard user Affected: All Windows versions (confirmed on Win11 with May 2026 updates) Not affected: Latest Windows 11 Insider Preview Canary builds (suggests a fix may be incoming) Researcher: Chaotic Eclipse / Nightmare-Eclipse Public PoC: github.com/Nightmare-Eclipse/MiniPlasma The Ghost Patch Problem In cybersecurity, few things are more unsettling than a patch that never actually landed. That’s exactly what happened here. ...

Weekly Threat & Lab Roundup: NGINX Rift, Exim Dead.Letter, PAN-OS IKEv2 RCE, Patch Tuesday 137 CVEs, and Pupy Python 3 Migration Milestone

This week proves that old vulnerabilities never die — they just wait for someone to look. NGINX Rift is an 18-year-old heap buffer overflow in the rewrite module that delivers RCE, discovered by an autonomous code analysis system. Exim’s Dead.Letter achieves unauthenticated remote code execution through a use-after-free triggered by a single stray byte in GnuTLS. Palo Alto ships a second PAN-OS RCE in two weeks — this time in IKEv2 processing. Microsoft’s May Patch Tuesday delivers 137 CVEs including critical Windows Netlogon and DNS overflows. And GreenPlasma (SB2026051378) continues Chaotic Eclipse’s disclosure campaign with a ctfmon.exe section hijack that escalates standard users to SYSTEM on Windows 11. Meanwhile in the lab, Pupy C2 completed its Python 3 migration, Nextcloud got a major version upgrade, Tailscale funnel replaced port forwarding for Plex remote access, and Max’s weekly audit found critical firewall gaps across two homelab hosts. ...

GreenPlasma CTFMON EoP exploit chain diagram

GreenPlasma — CTFMON Section Hijack LPE: Standard User → SYSTEM on Windows 11

TL;DR GreenPlasma (SB2026051378) is an unpatched Windows privilege escalation that chains a ctfmon.exe section creation bug with registry symlink hijacking and DACL relaxation to go from standard user → SYSTEM with zero interaction. No CVE assigned yet. No patch available. Affected: Windows 11, Windows Server 2022/2026 Not affected: Windows 10 (different ctfmon implementation) Requires: Standard user, interactive session Impact: Full SYSTEM shell Researcher: Chaotic Eclipse / Nightmare-Eclipse Public PoC: github.com/Nightmare-Eclipse/GreenPlasma The Context: Chaotic Eclipse’s Disclosure Campaign This is the fifth zero-day from the researcher Chaotic Eclipse (aka Nightmare-Eclipse), who has been publicly releasing Windows vulnerabilities after disputes with Microsoft’s MSRC over bug bounty responses. ...

Damned OOB — Linux Kernel io_uring ZCRX Freelist LPE (CVE-2026-43121)

Overview Attribute Value CVE ID CVE-2026-43121 Related CVE-2026-23263 (page array leak, same subsystem) CVSS Score ~7.8 (est., NVD enrichment pending) Vendor Linux Kernel Component io_uring/ZCRX (zero-copy receive) Vulnerability Type Missing bounds check → OOB heap write; Race condition → double-free Affected Linux kernel 6.12–6.19 (CONFIG_IO_URING_ZCRX=y) Patched ✅ Commit 770594e (bounds check) + 003049b1c4fb (atomic race fix), backported to v6.18.16 Exploit Status ⚠️ PoC demonstrated (kernel module + userspace harness) KEV Added Not yet What Is ZCRX? io_uring’s ZCRX (zero-copy receive) is a subsystem new to Linux 6.15 that lets userspace receive network packets directly into a registered memory region — no kernel copy needed. The NIC DMAs into the region, the kernel posts a completion event, and the user returns the slot when done via a refill queue. ...

Weekly Threat & Lab Roundup: PAN-OS Zero-Day, Canvas Mass Breach, DigiCert Code Signing Compromise, and vm2 Sandbox Escape

This week is a gut check for anyone who thinks patching is optional. A Palo Alto firewall zero-day gives unauthenticated root — and it’s been exploited since April 9. ShinyHunters breached Canvas LMS, stole data from 8,800 schools, then defaced 330 university login portals during finals week. DigiCert, one of the world’s largest certificate authorities, was compromised through a malicious screensaver file that led to stolen code-signing certificates. RansomHouse hit Trellix, the cybersecurity firm born from the McAfee/FireEye merger. Ivanti dropped another EPMM zero-day — their third this year — and CISA gave agencies just three days to patch. And the vm2 Node.js sandboxing library has another escape, this time via WebAssembly. Meanwhile in the lab, we deployed Termix + Apache Guacamole for browser-based remote access, killed Gmail’s Smart Features, and took a hard look at homelab attack surfaces after Max’s weekly audit. ...