A new Linux Kernel KVM vulnerability threatens cloud servers with virtual machine escape risks. Learn about CVE-2026-64561 and secure your host machine now.
#LinuxKernel #KVMVulnerability #CVE202664561 #CloudSecurity #VMescape
https://securityexpress.info/linux-kernel-kvm-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
About This Hashtag
#cloudsecurity
36 posts
Last used Aug 07
#cloudsecurity
36 posts· Last used Aug 07
Zapscape (CVE-2026-64561) is another reminder that the hypervisor boundary is only as strong as the code implementing it.
The vulnerability is a guest-to-host escape in Linux KVM's x86 Shadow MMU. The root cause is a stale-root validation ordering bug that allows the page fault handler to continue using an invalidated shadow MMU root after quota reclaim, ultimately leading to a use-after-free primitive. Public research demonstrates a complete guest-to-host escape chain, although exploitation requires privileged code execution inside an L1 guest and nested virtualization exposure.
I put together a deep technical analysis covering the Shadow MMU internals, nested virtualization, exploitation stages, cross-cache reallocation, KASLR bypass, AMD vs. Intel trigger conditions, the upstream fix, and why simply moving a stale-root check eliminates the entire exploitation chain.
Interested to hear how others assess the practical risk for multi-tenant KVM deployments where nested virtualization is enabled.
https://thecybersecguru.com/news/zapscape-cve-2026-64561-kvm-guest-host-escape/
#Linux #KVM #Virtualization #KernelSecurity #CloudSecurity #CVE202664561
CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA & strong passwords. No CVE assigned. https://radar.offseq.com/threat/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks-21f9fb8717cf2802 #OffSeq #CloudSecurity #ThreatIntel
🔈 Webinar Gratuito: "Secretos para una Presentación Exitosa de Ciberseguridad"
🎯 Miércoles 12 de Agosto 2026. De 11:00 am a 11:45 am (UTC -05:00)
⌚️ Registro libre: https://docs.google.com/forms/d/e/1FAIpQLScR624fU_3w9gmw5fNmXHxn4-5Ulhd3RpTiMqWQKcYdC7MU7w/viewform
#informationsecurity #zerotrust #threatintelligence #cloudsecurity #cybersecurityawareness #cybersecurityjobs
AWS Secrets Manager Terraform: Least-Privilege Access
https://blog.victorsilva.com.uy/aws-secrets-manager-terraform-least-privilege/
#HackerNews #Tech #CloudSecurity
Are you a SaaS founder or startup, this might resonate:
https://blog.mousa-cloud.com/posts/smb-cyber-risk/
#saas #smb #smallbusiness #cybersecurity #cloudsecurity #aws
CosmosEscape: CRITICAL flaw in Azure Cosmos DB exposed primary keys, granting full DB access. No CVE or mitigation yet. Monitor access keys and watch for official fixes. https://radar.offseq.com/threat/critical-flaw-led-to-azure-cosmos-db-pwnage-79bd9e6a4135bd53 #OffSeq #Azure #CloudSecurity #Vulnerability
Wiz's CosmosEscape reached one platform key in Azure Cosmos DB that could read and write any customer's database, across tenants.
Microsoft fixed it, no known impact.
Lesson: turn Cosmos key-based auth off where your API allows.
https://suriq.io/blog/azure-cosmos-db-cosmosescape-master-key
#CVE #CloudSecurity #infosec #cybersecurity
📡 Webinar Gratuito: "Fundamentos de Ciberseguridad"
📆 Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00)
🚨 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform
#cyberattack #dataprotection #phishing #ransomware #threatintel #cloudsecurity #zerotrust #cyber #security #infosec
Red Hat OpenShift Virtualization has a flaw (CVE-2026-17527): a 'read-only' role lets a low-privileged tenant copy other tenants' data across namespaces.
A confidentiality break in multi-tenant clusters.
No patch yet. Audit who holds that role.
https://suriq.io/blog/openshift-virtualization-view-role-cross-tenant-clone
#CVE #CloudSecurity #infosec #cybersecurity
Replying to @security_crawler_carl@infosec.exchange
Microsoft has patched this. Researcher Shay Shavit will be demonstrating the full horror at Black Hat USA. Review your Azure Automation account identity exposure and apply Microsoft's security updates immediately.
Reward: You've received the Binding Arbitration Bracer — it does nothing, but you clicked Accept, so here we are.
#AzureSecurity #CloudSecurity #CyberSecurity #IdentityTheft #Microsoft #AchievementUnlocked (3/3)
🆓 Webinar Gratuito: "Fundamentos de Ciberseguridad"
🏁Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00)
🎇 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform
#dataprotection #ciso #gdpr #malware #threatintelligence #ransomware #cloudsecurity #zerotrust
CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. https://radar.offseq.com/threat/cve-2026-56163-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-kubernetes-c5571c5da7b404e3 #OffSeq #Azure #Kubernetes #CloudSecurity
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation.
#Konnectivity #Kubernetes #CVE202616242 #CloudSecurity #ControlPlane #AuthBypass #InfoSec #PatchNow
http://securityonline.info/konnectivity-vulnerability-cve-2026-16242/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-50517: CRITICAL deserialization flaw (CVSS 9.9) in Microsoft 365 Copilot permits remote code execution by authorized attackers. Microsoft has issued a server-side fix — confirm your environment is protected. https://radar.offseq.com/threat/cve-2026-50517-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-365-copilot-71d778a5726cf6f5 #OffSeq #Microsoft365 #CloudSecurity #CVE202650517
CVE-2026-58275 | Microsoft Azure DNS (CRITICAL, CVSS 10): Missing authorization lets attackers escalate privileges remotely — integrity & availability at risk. Microsoft has patched server-side. Details: https://radar.offseq.com/threat/cve-2026-58275-cwe-862-missing-authorization-in-microsoft-azure-dns-8fa245e6deabe29a #OffSeq #Azure #CVE #CloudSecurity
🆓 Webinar Gratuito: "Fundamentos de Ciberseguridad"
🏁Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00)
🎇 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform
#infosec #informationsecurity #cyber #zerotrust #threatintel #ransomware #phishing #cloudsecurity #malware
🆓 Webinar Gratuito: "Fundamentos de Ciberseguridad"
🏁Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00)
🎇 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform
#infosec #informationsecurity #cyber #zerotrust #threatintel #ransomware #phishing #cloudsecurity #malware
The recording and slides for our Hacker Summer 2026 webinar, From Initial Access to Persistence: Abusing Synced Passkeys in Azure, are now available.
Video: https://youtu.be/kwEga-U96dw?si=_nwzT74aT26cNpAx
Slides: https://16cdd728-52b5-4665-b161-30113ba1b7e4.usrfiles.com/ugd/16cdd7_684bf5951d5648f0a213cf3a3836505f.pdf
Special thanks to @nathanmcnulty@bird.makeup for an excellent session.
#HackerSummer2026 #CloudSecurity #RedTeaming #AlteredSecurity