exploit
4 stories
Public Exploits Released for Linux Kernel Root Privilege Flaws
Working exploit code has been released for four vulnerabilities in the Linux kernel that allow local users to gain administrative root access. While kernel maintainers have already issued fixes for these issues, systems running older, unpatched versions remain vulnerable. Users are advised to update their systems promptly to mitigate the risk.

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
A critical vulnerability in the Cosmos EVM module allowed attackers to drain funds from six blockchains between August 20-25, 2026. The flaw, related to balance handling in vesting accounts, was known to Cosmos Labs but initially underestimated. Despite patches being released on August 19, the exploit was successful due to a delayed and improperly handled disclosure and patching process, leading to an estimated loss of nearly $5.7 million.

July 2026 CVE Landscape
In July 2026, a significant increase in high-impact vulnerabilities was observed, with 85 critical flaws identified, 36 of which had a Very Critical Recorded Future Risk Score. A notable portion of these vulnerabilities were either already listed in CISA's Known Exploited Vulnerabilities catalog or were reported by vendors. The vulnerabilities affected a wide range of products from 61 vendors, with Microsoft products being the most frequently impacted.

Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more
Metasploit has released its weekly update, introducing several new modules and enhancements. Notably, a new module allows for the upgrade of SMB sessions to Meterpreter using PsExec. Additionally, the update includes an exploit for an unauthenticated remote code execution vulnerability in Peyara Remote Mouse 1.0.1 and a new command payload for LoongArch64 Linux systems. Several bug fixes and authentication support improvements for the MCP server's HTTP transport are also part of this release.