Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIResearchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Security researchers have demonstrated a critical vulnerability in Windows 11's Plug and Play functionality that allows attackers to achieve SYSTEM-level access by exploiting the automatic installation process for emulated USB devices. The attack leverages signed vendor software fetched through PnP mechanisms and can be executed remotely via Remote Desktop when USB redirection is enabled, affectin
AI18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A critical 18-year-old use-after-free vulnerability in Linux's SCTP networking code enables local privilege escalation to root access and container escape. Tencent researchers demonstrated successful exploitation to break out of containers and compromise the underlying host system. Patches are available in stable kernel versions released August 3, 2025, making immediate updates essential for syste
AIAttackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers exploited a SQL injection vulnerability in a public-facing web application to compromise an Oracle database, then deployed a post-exploitation toolkit called 'khunt' by compiling Java source code directly within the database engine rather than writing executables to disk. This technique allowed them to execute commands from inside Oracle and escalate privileges to Windows SYSTEM level ac
AINew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A critical memory corruption vulnerability (CVE-2026-64531, dubbed 'OVSwrap') in the Linux kernel's Open vSwitch datapath allows local users to escalate privileges to root access. The flaw affects numerous default-configured Linux distributions, with a public exploit already available covering approximately 800 kernel builds, posing significant risk to enterprise environments running Open vSwitch.
AINew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has released a critical security patch addressing CVE-2026-58048, a vulnerability that allowed authenticated hosting customers to execute SQL commands with database root privileges, effectively bypassing account-level security boundaries. The targeted security release also fixes two additional vulnerabilities that could enable privilege escalation beyond account boundaries.
AI'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Microsoft has patched a high-severity vulnerability dubbed 'Certighost' in Active Directory Certificate Services that enables threat actors to escalate privileges and potentially compromise entire AD environments. The flaw represents a significant security risk for enterprise organizations relying on Microsoft's identity and access management infrastructure.
AIResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs disclosed CVE-2026-53264, a high-severity Linux kernel vulnerability in the network traffic-control subsystem that allows local privilege escalation to root on CentOS Stream 9. The researcher utilized AI to accelerate both vulnerability discovery and exploit development, demonstrating AI's growing role in security research.
AIMicrosoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Microsoft has officially acknowledged a zero-day vulnerability in Microsoft Defender, designated CVE-2026-50656 with a CVSS score of 7.8. The flaw, codenamed RoguePlanet, is a privilege escalation vulnerability affecting the Microsoft Malware Protection Engine, and Microsoft is actively developing a patch to address it.
AICISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
CISA has added CVE-2026-54420, a high-severity privilege escalation vulnerability in the LiteSpeed cPanel Plugin, to its Known Exploited Vulnerabilities catalog. The flaw, with a CVSS score of 8.5, is being actively exploited to gain root-level access, prompting CISA to mandate Federal Civilian Executive Branch agencies remediate by June 18, 2026.
AILiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
Obsidian Security researchers discovered a critical vulnerability chain in LiteLLM, a widely-used open-source AI gateway, that allows low-privilege accounts to escalate to full admin access and execute arbitrary code on servers. The exploit chains three separate vulnerabilities and could expose all provider API keys and secrets stored on compromised LiteLLM proxy servers, which broker calls to ove
AIMicrosoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
Security researcher Chaotic Eclipse has disclosed a zero-day vulnerability in Microsoft Defender called RoguePlanet that exploits a race condition to grant SYSTEM-level access on fully updated Windows systems. The proof-of-concept exploit has been published on GitHub, with the researcher claiming a 100% success rate under certain conditions. This represents a critical privilege escalation vulnerab
AIOne-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
A critical use-after-free vulnerability (CVE-2026-23111) in the Linux kernel's nf_tables packet-filtering code allows unprivileged local users to escalate privileges to root and escape containers. The flaw was patched upstream in February 2026, but detailed working exploits have now been publicly released by Exodus Intelligence in June, significantly increasing the risk for unpatched systems.
AICritical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
A critical security vulnerability in WP Maps Pro, a popular WordPress plugin with over 15,000 sales, is being actively exploited by threat actors to create unauthorized administrator accounts on vulnerable websites. The plugin, which enables site owners to embed customizable Google Maps and OpenStreetMap features, presents significant risk to organizations using WordPress for their web presence.
AIWith Complex Cloud Integrations, Small Errors Lead to Major Compromises
Security researchers uncovered a critical exploit chain in a widely-used automation service that leveraged over-permissioned roles, exposed secrets, and compromised non-human identities. The discovery highlights how seemingly minor misconfigurations in complex cloud integrations can cascade into major security vulnerabilities. This case underscores the growing risk surface created by interconnecte
