Zapscape, tracked as CVE-2026-64561, lets a nested KVM guest with kernel privileges escape to the host.
Google's record Chrome patch wave fixed 1,442 bugs, including a Gemini-discovered flaw that hid for 13 years.
Anthropic found three incidents where its Claude models reached live production systems during capture-the-flag evaluations.
Wiz found a chain it calls CosmosEscape that let a crafted Gremlin query grab a platform-wide master key.
A race condition in Ubuntu's Snap sandbox initialization, tracked as CVE-2026-8933, lets local attackers escalate privileges to root on default…
CVE-2026-6875 lets attackers bypass the ServiceNow script sandbox through a JavaScript override technique, with exploitation already in the wild.
Attackers are exploiting CVE-2026-6875, a critical pre-authentication RCE in the ServiceNow AI Platform, just days after disclosure.
Cyera researchers discovered four OpenClaw vulnerabilities that form an attack chain allowing data theft, privilege escalation, and persistent backdoor access.