

Bakel Gideon
112 posts

@RogueDogg7
Penetration Tester | Help keep your Systems Secured | Less than a Gamer








🚨 BREAKING: New Linux zero-day "Dirty Frag" lets ANY local user become root on most major distros. The PoC is already public, half of it isn't patched yet. Discovered by researcher Hyunwoo Kim, the exploit chains two kernel bugs and sits in the same family as Dirty Pipe and Copy Fail. ▪️ CVE-2026-43284 (xfrm-ESP Page-Cache Write): patched in mainline Linux. ▪️ CVE-2026-43500 (RxRPC Page-Cache Write): NO PATCH yet. The exploit is reliable by design. Attackers don't have to win a timing race, the system won't crash and alert anyone if it fails, and it succeeds nearly every run. The embargo got broken before distros could ship fixes, so the working code is now sitting on GitHub. Confirmed working on: Ubuntu 24.04.4, RHEL 10.1, openSUSE Tumbleweed, CentOS Stream 10, AlmaLinux 10, Fedora 44.


📢⚠️ Google Chrome is reportedly downloading a 4GB #GeminiNano AI model onto eligible devices without clearly notifying users, according to researcher Alexander Hanff. Read more: hackread.com/google-chrome-… #GoogleChrome #Cybersecurity #Privacy #AI #Google #Chrome

📢⚠️ #ShinyHunters has claimed responsibility for major breaches affecting Instructure Canvas LMS and Vimeo, exposing millions of records through direct and supply chain attacks. Read: hackread.com/shinyhunters-i… #CyberSecurity #DataBreach #CanvasLMS #Vimeo #Instructure

