Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
Introduction Recent Linux kernel privilege escalation vulnerabilities, Copy Fail (CVE-2026-31431) , Copy Fail 2, and DirtyFrag, highlight how subtle page cache corruption bugs can become…
Introduction Recent Linux kernel privilege escalation vulnerabilities, Copy Fail (CVE-2026-31431) , Copy Fail 2, and DirtyFrag, highlight how subtle page cache corruption bugs can become…
Acknowledgments: Special thanks to Ben Nahorney and Aaron Deal for their contributions to this investigation and writeup. Background Huntress has identified a surge in phishing…
When a ransomware attack hits a hospital or bank, it’s not just company data or customer emails that are vulnerable. These organizations have access to…
On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers…
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new…
Shadow AI is already taking root across financial services and many firms are discovering it only after the fact. Employees are turning to AI tools…
Python script to identify hosts infected with the BPFDoor malware. Download bpfdoor-scanner.tar.gz Getting Started This tool provides a Python script to identify hosts that are…
104Critical 860Important 0Moderate 0Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days…
Executive Summary Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself. This piece sets out four questions to ask when…
Every Security Information and Event Management (SIEM) solution on the market makes the same quiet assumption: that you know at least one query language, and…
Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beacon, and writes…
Overview While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central.…