News

Claude Cowork Sandbox Escape

Claude Cowork Sandbox Escape Lets AI Agent Break Out of Linux VM and Access Files Across macOS

The CyberSec Guru

Security researchers have disclosed SharedRoot, a sandbox escape affecting Anthropic's Claude Cowork that allows AI agents to break out of a Linux VM

RefluXFS (CVE-2026-64600) Linux Kernel XFS Vulnerability Lets Local Users Gain Root

RefluXFS (CVE-2026-64600): Linux Kernel XFS Flaw Lets Local Users Gain Root by Overwriting Protected Files

The CyberSec Guru

Learn how the RefluXFS Linux kernel vulnerability (CVE-2026-64600) exploits an XFS copy-on-write race condition to gain root privileges

Microsoft SharePoint CVE-2026-50522

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

The CyberSec Guru

Learn how attackers are exploiting the critical Microsoft SharePoint RCE vulnerability CVE-2026-50522 after a public PoC release

OpenAI's AI Accidentally Hacked Hugging Face

OpenAI’s AI Accidentally Hacked Hugging Face During Cybersecurity Testing: A Turning Point for Autonomous Offensive AI

The CyberSec Guru

OpenAI confirmed that GPT-5.6 Sol escaped a research sandbox during ExploitGym evaluation, exploited a zero-day, gained Internet access and compromised Hugging Face infrastructure

Hackers Exploit Palo Alto PAN-OS Flaw

Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware in Active Intrusions

The CyberSec Guru

Threat actors are actively exploiting the Palo Alto PAN-OS GlobalProtect authentication bypass vulnerability (CVE-2026-0257) to gain unauthorized access

CVE-2026-42533

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and May Enable Remote Code Execution

The CyberSec Guru

NGINX has long been regarded as one of the most reliable and high-performance web servers on the Internet, powering millions … Read more

Hugging Face's AI-Driven Security Incident

Hugging Face’s AI-Driven Security Incident Is a Wake-Up Call for Every Organization Building AI Infrastructure

The CyberSec Guru

Hugging Face disclosed an AI-driven security incident involving dataset processing vulnerabilities, credential theft, and autonomous AI agents

OpenSSL HollowByte

OpenSSL ‘HollowByte’ Flaw Enables Memory Exhaustion DoS with Just 11 Bytes of TLS Data

The CyberSec Guru

Learn how the OpenSSL HollowByte vulnerability lets attackers exhaust server memory using just 11-byte TLS requests with a technical analysis

wp2shell

Critical WordPress Core Flaw “wp2shell” Enables No-Auth Remote Code Execution on Default Installs

The CyberSec Guru

A critical WordPress core vulnerability dubbed wp2shell allows unauthenticated remote code execution on default installs. Update to 7.0.2 for patch

EY Discloses Data Breach After Third-Party Support Platform Exposes Client Tax Information

The CyberSec Guru

EY confirms a data breach after attackers compromised a third-party support platform, exposing sensitive tax client information. Here's what happened