New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

Details have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug to be identified in the kernel within a span of two weeks.
Codenamed Fragnesia, the security vulnerability is tracked as CVE-2026-46300 (CVSS score: 7.8) and is rooted in the Linux kernel’s XFRM

The Hacker News – ​Read More

Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

YellowKey is a BitLocker bypass that requires physical access. GreenPlasma enables elevation of privileges to System.

The post Researcher Drops YellowKey, GreenPlasma Windows Zero-Days appeared first on SecurityWeek.

SecurityWeek – ​Read More

TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack

TeamPCP claims to be selling alleged Mistral AI repositories on a hacker forum after the Mini Shai-Hulud attack targeted npm and PyPI ecosystems.

Hackread – Cybersecurity News, Data Breaches, AI and More – ​Read More

You may qualify for Amazon Prime at 50% off without even knowing – here’s how

There are a couple of lesser-known ways to get Amazon Prime at a discount right now. I break down the details.

Latest news – ​Read More

I’m following the 60-60 rule for headphone listening, and my future self will thank me for it

Wearing headphones every day has a greater effect on your ears than you might think. But your devices likely have features to help.

Latest news – ​Read More

Tables Turn on ‘The Gentlemen’ RaaS Gang With Data Leak

An OPSEC failure provides a window into what helped the ransomware group rise: a generous affiliate model, opportunistic TTPs, and an effective organizational structure.

darkreading – ​Read More

Adobe Express vs Canva: Which design tool is better?

I tested Adobe Express and Canva to compare value and workflow fit so you can choose the right design tool for your needs.

Latest news – ​Read More

Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak

Instructure has reached an agreement with the ShinyHunters group to return and destroy stolen Canvas data, protecting millions of student records from a public leak.

Hackread – Cybersecurity News, Data Breaches, AI and More – ​Read More

Attackers Weaponize RubyGems for Data Dead Drops

Threat actors are publishing RubyGems packages that include scrapers targeting public-facing UK government servers, but with no clear objective.

darkreading – ​Read More

Checkbox Assessments Aren’t Fit to Measure to Risk

Security governance needs to be more than an annual compliance exercise. New companies are emerging to address risk-management gaps in current audit tools.

darkreading – ​Read More