New Fragnesia Linux kernel LPE allows root access due to page cache corruption

Ravi LakshmananMay 14, 2026Vulnerabilities / Linux Details have emerged about a new variant of the recent Dirty Frag Linux Local Privilege Escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug in the kernel within two weeks. The security vulnerability codenamed ‘Fragnesia’ is tracked as CVE-2026-46300 (CVSS score: […]
Flaw in 18-year-old NGINX rewrite module allows unauthenticated RCE

Rabi LakshmananMay 14, 2026Vulnerabilities / Web Server Cybersecurity researchers have uncovered multiple security vulnerabilities affecting NGINX Plus and NGINX Open, including a critical flaw that went undetected for 18 years. This vulnerability, discovered by DepthFirst, is a heap buffer overflow issue affecting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to execute […]
Microsoft’s MDASH AI system finds 16 flaws in Windows fixed in Patch Tuesday

Rabi LakshmananMay 13, 2026Vulnerability / Artificial Intelligence Microsoft announced a new multi-model artificial intelligence (AI)-powered system called MDASH that facilitates the discovery and remediation of vulnerabilities at scale, adding that it is being tested by some customers as part of a limited private preview. MDASH (short for Multi-Model Agent Scanning Harness) is designed as a […]
Azerbaijani energy company falls victim to repeated Microsoft Exchange exploits

Rabi LakshmananMay 13, 2026Cyber espionage/malware Chinese-linked attackers were involved in “multi-wave intrusions” targeting unnamed oil and gas companies in Azerbaijan from late December 2025 to late February 2026, indicating an expansion of their targeting. Bitdefender has moderate to high confidence that this activity is the work of the hacker group known as FamousSparrow (also known […]
[Webinar] Why AppSec tools miss “fatal paths” (and how to fix them)

hacker newsMay 13, 2026AppSec / Webinar TL;DR: Stop chasing thousands of “toast” alerts. Join Wiz and the Okta/GitLab experts to learn how hackers link small flaws to create “deadly chains” in your data and how to break them. Sign up for strategic briefings here. Most security tools work like a smoke alarm that goes off […]
Most repair programs never confirm that the fix actually worked

hacker newsMay 13, 2026Cloud security/automation Security teams have never had greater visibility into their environments, and it has never been more difficult to ensure that what they fix stays fixed. Mandiant’s M-Trends 2026 report estimates the average usage time to be -7 days. Verizon 2025 DBIR states that the median time to remediate vulnerabilities on […]
Microsoft patches 138 vulnerabilities, including DNS and Netlogon RCE flaws

Microsoft on Tuesday released patches for 138 security vulnerabilities across its product portfolio, but none are listed as publicly known or under active attack. Of the 138 defects, 30 were rated critical, 104 were rated important, 3 were rated moderate, and 1 was rated low. As many as 61 vulnerabilities were categorized as privilege elevation […]
GemStuffer exploits over 150 RubyGems to leak scraped UK council portal data

Ravi LakshmananMay 13, 2026Software supply chain/data breach Cybersecurity researchers are warning people of a new campaign called GemStuffer. This campaign targets the RubyGems repository, which contains over 150 gems, and uses the registry as a data exfiltration channel rather than malware distribution. “The package does not appear to be designed to compromise large-scale developers,” Socket […]
Android adds intrusion logging for advanced spyware forensics

Google on Tuesday announced a new opt-in Android feature called Intrusion Logs to store forensic logs to better analyze advanced spyware attacks. Intrusion logging, available as part of Advanced Protection Mode, “enables persistent privacy-preserving forensic logging and allows devices to be investigated in case of a suspected breach,” the company said. It added that the […]
New vulnerability in Exim BDAT could allow code execution in GnuTLS builds

Ravi LakshmananMay 12, 2026Vulnerabilities / Email Security Exim has released a security update to address a critical security issue affecting certain configurations that could lead to memory corruption and potential code execution. Exim is an open source mail transfer agent (MTA) designed to enable Unix-like systems to receive, route, and deliver email. The vulnerability is […]