Certighost Exploit Enables Low-Privileged AD Users to Impersonate Domain Controllers
On July 24, 2026, researchers H0j3n and Aniq Fakhrul published a working exploit for a Microsoft Active Directory Certificate Services (AD CS)…
On July 24, 2026, researchers H0j3n and Aniq Fakhrul published a working exploit for a Microsoft Active Directory Certificate Services (AD CS)…
CVE-2026-54121 is a critical vulnerability in Microsoft's Active Directory Certificate Services (AD CS) that allows low-privileged users to impersonate a Domain Controller.…
A standard Linux privilege escalation enumeration script. The attacker used a customized version that checked for four 2026 kernel vulnerabilities (Copy Fail,…
A local privilege escalation vulnerability in polkit's pkexec utility. The attacker staged exploit code for this older flaw alongside the AI agent…
Cybersecurity researchers at Accomplish AI have disclosed a sandbox escape vulnerability in Anthropic's Claude Cowork, tracked as SharedRoot, that allows an AI…
A critical Linux kernel vulnerability in XFS filesystem reflink handling, allowing local privilege escalation to root. Affects Linux 4.11+ with reflink-enabled XFS.…
A critical Linux kernel vulnerability, tracked as CVE-2026-64600 and named RefluXFS, has been disclosed by Qualys. The flaw, present in Linux kernels…
Check Point has released security updates to address multiple vulnerabilities in its Security Management and Multi-Domain Management (MDSM) products, including a critical…
An improper privilege management vulnerability in Check Point Gaia Portal (CVSS 7.5) allowing authenticated read-only users to execute commands with root privileges.
Web-based management interface for Check Point Gaia operating system. Affected by CVE-2026-62145 privilege management vulnerability.