CVE-2026-8933 porta snap-confine sotto la lente, mostrando come un bug nel percorso di avvio di un sandbox possa trasformarsi in un fallimento completo del confine dei privilegi.
Una nuova falla tracciata in XFS mostra come un bug di temporizzazione nel codice di storage in kernel-space possa trasformare un accesso locale in un controllo completo dell'host.
Una race nella gestione dei reflink XFS può consentire a un utente non privilegiato di ottenere root sui sistemi interessati, e il danno può sopravvivere a un riavvio.
Una falla in snap-confine trasforma un normale aggiornamento di Ubuntu Desktop in un promemoria: i confini dei privilegi locali sono spesso l'ultima linea tra l'uso normale e il controllo completo del sistema.
Il ciclo di patch di Serv-U di SolarWinds mostra come un'autorizzazione difettosa nei flussi di lavoro amministrativi possa trasformare una piattaforma di managed file transfer in un bersaglio ad alto rischio, soprattutto su Linux.
Un importante aggiornamento di Serv-U chiude un insieme di falle critiche che potrebbero trasformare un normale file server in una piattaforma di lancio per l'esecuzione di codice remoto e, su alcune distribuzioni Unix-like, per il controllo a livello di root.
Una vulnerabilità di Windows appena resa pubblica, nota come LegacyHive, ha portato alla disponibilità di patch non ufficiali gratuite, con il rischio concentrato sull'escalation dei privilegi su sistemi aggiornati.
Una grave falla di autorizzazione in Gitea consentiva ai token destinati ai repository pubblici di scrivere indirettamente in quelli privati e di attivarne l'automazione.
Un avviso ad alta gravità su alcuni driver ASUS mostra come un livello software fidato possa diventare un percorso di escalation dei privilegi quando le sue autorizzazioni sono troppo ampie e i controlli troppo deboli.
A high-severity privilege escalation in Citrix’s Windows access software shows how a local user account can become a near-total compromise path inside endpoint trust tooling.
A pair of flaws in Citrix endpoint software shows how a local trust component can become a machine-level prize when standard-user access is enough to cross the boundary.
A newly disclosed Windows local privilege-escalation technique highlights how per-user registry state can become a delayed weapon if hive handling crosses trust boundaries.
A newly disclosed Windows local privilege-escalation issue called LegacyHive centers on profile loading and the per-user Classes hive, a boundary that can matter long after a user signs off.
A newly disclosed Windows zero-day associated with the handle Nightmare Eclipse puts the User Profile Service in the spotlight, showing how a local flaw can matter as much as a remote one.
A use-case guide turns into a sharper lesson: identity security tools only work when they match the way an organization actually authenticates, escalates privilege, and moves trust around.
Two Windows flaws in Citrix Secure Access Client and Endpoint Analysis Client put the spotlight on a quiet but high-value target: endpoint software that helps decide who gets into the corporate network.
Splunk and Zoom have patched critical flaws that could let an attacker reach credentials, data, accounts, and higher privileges, a reminder that the most dangerous bugs often sit closest to identity and administration.
A critical validation flaw in Zoom’s Windows ecosystem mattered not only for the desktop client, but also for VDI deployments and apps that embed the Meeting SDK.
LegacyHive arrives with a stripped proof-of-concept, a reminder that even partial exploit disclosure can sharpen defenders' focus on fragile Windows trust boundaries.
A Linux kernel weakness mapped to ABB Ability Edgenius shows how a local-only bug can matter just as much as a remote one when the affected system sits near operational data.