Copy Fail: Universal Linux Local Privilege Escalation Vulnerability
CVE-2026-31431 (dubbed “Copy Fail”) is an easily exploitable vulnerability in the Linux kernel that allows escalation from an unprivileged local user account to root access.…
CVE-2026-31431 (dubbed “Copy Fail”) is an easily exploitable vulnerability in the Linux kernel that allows escalation from an unprivileged local user account to root access.…
AI-powered offensive security has made significant progress in finding flaws that would have seemed out of reach for automated testing just a year ago, and…
This is the first blog post in the Red Agent POV series, where we cover real-life examples of the Red Agent’s findings in production. In…
What we believe We’ve been thinking deeply about enterprise security. The operating model that served us for the past decade (collect telemetry, store it, query…
In our previous blog in this series, we walked you through a 90-day action plan to achieve complete visibility and start your path to Zero…
Microsoft 365 powers how many modern businesses collaborate, but it also connects deeply into the cloud environments that run those businesses. Today, we’re excited to…
Supply chain package compromises follow a familiar playbook: an attacker gains access to a maintainer account or build system, pushes a malicious update, and waits…
The goal of any offensive security team is to find the “open doors” before an attacker does. However, in most organizations, the results of these…
A critical vulnerability (CVE-2026-0300) has been identified in Palo Alto Networks PAN-OS that allows unauthenticated attackers to achieve remote code execution (RCE) with root privileges.…
In the new frontier AI era, models can autonomously discover vulnerabilities and generate working exploits, shrinking the window from discovery to exploitation to only hours.…
Jenkins is an open-source automation server widely used for CI/CD orchestration, pipeline automation, and infrastructure workflows. It integrates deeply with source control systems, container registries,…
It’s been a big few weeks for how we ship code securely. At Wiz we expanded AI-BOM visibility, secure guardrails baked into agentic coding flows,…