Un bug di durata nel controllo del traffico nel kernel Linux, tracciato come CVE-2026-53264, mostra come una vulnerabilità locale circoscritta possa diventare un problema di privilegi a livello di sistema, mentre l'IA entra sempre più nei flussi di lavoro della ricerca sugli exploit.
Una race nel percorso net/sched del kernel mostra come un piccolo bug di lifetime possa diventare un percorso di escalation locale ad alto valore, anche dopo che la correzione è già entrata nel ramo stabile.
Una nuova falla del kernel Linux tracciata nel traffic control mostra come un singolo errore di gestione del ciclo di vita nel codice privilegiato possa ancora mettere il pieno controllo del sistema alla portata di un attaccante locale.
Google ha distribuito un aggiornamento di Chrome per il canale Stable che chiude diverse vulnerabilità di memory-safety ad alta gravità, ma il rilascio graduale significa che la protezione arriva in più fasi, non tutta insieme.
Una normale tappa del browser porta con sé un messaggio di sicurezza fuori scala: sono state corrette sei vulnerabilità gravi di tipo use-after-free, a conferma di quanto spesso la difesa dei browser dipenda ancora dalla sicurezza della memoria.
A long-lived Linux privilege-escalation bug highlights how one local foothold, one stale pointer, and one delayed patch can still matter across servers, containers, and CI systems.
A wide 2026.1.2 patch cycle for Foxit Reader and Editor shows how parsing bugs, scripts, and rich media can turn routine PDFs into serious endpoint risk.
Google’s Stable channel update closes 27 security holes across desktop platforms, and the most sensitive fixes point back to memory safety rather than flashy new features.
Critical fixes for Foxit PDF Reader and Foxit PDF Editor highlight a familiar risk in document software: a malformed file can push a use-after-free bug toward remote code execution if the vulnerable path is reached.
A long-lived Linux privilege-escalation flaw, nicknamed GhostLock, shows how a mistake in locking logic can become a serious host takeover risk.
A new Stable-channel build fixes 27 flaws in Chrome, including two critical use-after-free bugs that keep browser security teams on alert.
A new Chrome security refresh closes 27 flaws, and the concentration of use-after-free bugs shows how stubborn browser memory errors remain.
A public proof of concept for CVE-2026-53359 has put the KVM hypervisor back under scrutiny, with the main concern shifting from theory to the stability of guest-host isolation.
A Linux privilege-escalation flaw tied to CVE-2026-43499 shows how a small mistake in lock state tracking can turn into a serious host-level security problem.
A newly disclosed use-after-free in Linux KVM’s x86 shadow MMU shows how a long-lived hypervisor flaw can turn guest-controlled paging into host kernel memory corruption.
A newly disclosed use-after-free issue in Microsoft Edge raises remote code execution risk and again turns browser patching into a race against exposure.
Microsoft’s Chromium-based Edge has a high-severity use-after-free bug, and the real risk is not the label but the time it takes organizations to move vulnerable builds off their endpoints.
A Linux kernel use-after-free in the epoll path shows how a narrow timing bug in object cleanup can become a serious privilege-escalation risk on unpatched systems.
CVE-2026-46242 shows how a use-after-free in a core kernel event path can turn local access into full control, with patch provenance now more important than the nickname attached to the bug.
A Linux epoll flaw described as a zero-day shows how a small race in kernel teardown can become a local privilege-escalation path on desktops, servers, and Android devices.