
A Linux Root Bug Now Hits Servers and Android Phones
CVE-2026-46242, Bad Epoll, lets any local user become root on Linux 6.4+ servers and Android at 99 percent reliability. What owners of Linux fleets should do now.

CVE-2026-46242, Bad Epoll, lets any local user become root on Linux 6.4+ servers and Android at 99 percent reliability. What owners of Linux fleets should do now.

Seven FatFs bugs, six of them unpatched, ship inside cameras, drones, ATMs and crypto wallets via ESP-IDF, STM32Cube and Zephyr. Why owners must audit their device bill of materials.

CISA added SharePoint flaw CVE-2026-45659 to its exploited-vulnerabilities list on 1 July. Microsoft rated it unlikely to be attacked. The patch has existed since May, and under NIS2 the clock is yours.

A password-spray campaign threw 81 million login attempts at Microsoft 365 in two weeks and got past multi-factor authentication - not with a new exploit, but by abusing a legacy sign-in path that skips MFA.

Microsoft has pulled its quantum-safe deadline forward four years to 2029. The reason is not future quantum computers. It is the data being stolen today.

Two critical Cursor flaws rated 9.8 let a poisoned web page or tool result seize a developer's machine. What DuneSlide means for owners, and what to do this week.

Black Kite's 2026 report shows one supplier breach drove over half of Europe's third-party ransomware victims. Under NIS2 and DORA, the liability is yours.

Anthropic's Cyber Jailbreak Severity scale turns AI safety into a procurement and audit criterion, the way CVSS did for software bugs. What owners should demand.

Google and the FBI disrupted NetNut, a residential proxy network of at least 2 million home devices used by 316 threat clusters in one week. Why IP reputation is dead and your devices are the new perimeter.

The US lifted export controls on Claude Fable 5 after 19 days. Anthropic bought access back with a retrained classifier and a CVSS-style jailbreak severity scale. What that means for operators.

Microsoft warns that a poisoned tool description can turn your AI agent into a data leak, with no rule broken and no bug exploited. What owners must lock down.

Researchers showed a booby-trapped webpage can talk a browser AI agent out of its own safety rules and make it hand over passwords and access. What owners should do.
Page 4 / 5
One considered note on infrastructure, governance, and measurement, most mornings. No theory.