A long-known Linux kernel weakness has resurfaced as a live container-escape risk, showing how one old bug can still threaten modern cloud and host isolation.
The alert centers on CVE-2022-0492, a cgroups v1 release_agent flaw in the Linux kernel that may let a local attacker escalate privileges in environments where the vulnerable path is reachable.
CVE-2022-0492 has been placed in CISA’s known-exploited catalog, pushing a legacy cgroups v1 flaw from dusty kernel history into active defensive priority.
A reported campaign ties a Chinese-nexus threat label to BRICKSTORM, a modular backdoor built to live inside appliances and move quietly through enterprise networks.
CVE-2022-0492 shows how a narrow authorization flaw in cgroups v1 can turn a container foothold into host-level privilege escalation, making legacy kernel paths a live defensive problem.
A campaign first detected in July 2025 used comments on Steam Community profiles as a command-and-control channel, with researchers identifying infections across approximately 1,980 WordPress sites.
The case shows how an exposed file-sharing service can be turned into an extortion channel without requiring a local encryptor, shifting the defender’s focus from malware hunting to exposure control and authentication hygiene.
A feature about a daily-driver desktop may sound casual, but it is a reminder that ordinary operating systems are where trust, identity, and risk meet every day.
A flaw in Claude Code’s GitHub Actions integration could have let hostile input reach privileged automation, turning a convenience feature into a repository security problem.
A claimed espionage effort against senior government phones is a reminder that the hardest part of mobile compromise is often not infection - it is proving what really happened.
Infosecurity Europe appears as an RX Global event listing, and that ordinary label is a reminder that public-facing event pages are part of the web ecosystem security teams still need to harden.
The acquisition is a sign that industrial defenders are chasing more than network visibility, with xOT security now stretching toward the device layer itself.
A cross-site scripting flaw in pretalx was patched in v2026.1.0, and the technical lesson is bigger than one event tool: privileged browser sessions remain a high-value target.
A 2026 look at Linux privilege escalation shows why quiet configuration flaws can matter more than the first foothold in a test or assessment.
A CISA warning about campaigns abusing CI/CD workflows shows how extensions and build tools can become a quiet path to code and credential theft.
A stored cross-site scripting weakness in a CP Plus recorder shows how a routine management interface can become a high-risk trust boundary for operators and defenders.
CVE-2026-45659 puts Microsoft SharePoint Server back in the spotlight, with a flaw that can let an authorized attacker push code over the network and force defenders to think beyond patching alone.
A victim listing tied to Hunter shows how modern extortion often turns on reputation, sensitive records, and uncertainty long before any forensic confirmation is public.
Verizon’s annual breach analysis is being read less as a threat parade and more as a blunt reminder that patching, identity, vendor oversight, and data governance still decide who gets hit first.
A ransomware leak-site entry can be noisy, incomplete, and still operationally serious: it signals pressure, not proof, and it can drag a business into a cycle of uncertainty before any forensic facts are public.