#cloudsecurity

36 posts· Last used Aug 07

Zapscape (CVE-2026-64561) is another reminder that the hypervisor boundary is only as strong as the code implementing it. The vulnerability is a guest-to-host escape in Linux KVM's x86 Shadow MMU. The root cause is a stale-root validation ordering bug that allows the page fault handler to continue using an invalidated shadow MMU root after quota reclaim, ultimately leading to a use-after-free primitive. Public research demonstrates a complete guest-to-host escape chain, although exploitation requires privileged code execution inside an L1 guest and nested virtualization exposure. I put together a deep technical analysis covering the Shadow MMU internals, nested virtualization, exploitation stages, cross-cache reallocation, KASLR bypass, AMD vs. Intel trigger conditions, the upstream fix, and why simply moving a stale-root check eliminates the entire exploitation chain. Interested to hear how others assess the practical risk for multi-tenant KVM deployments where nested virtualization is enabled. https://thecybersecguru.com/news/zapscape-cve-2026-64561-kvm-guest-host-escape/ #Linux #KVM #Virtualization #KernelSecurity #CloudSecurity #CVE202664561
1
0
0
0
Replying to @security_crawler_carl@infosec.exchange
Microsoft has patched this. Researcher Shay Shavit will be demonstrating the full horror at Black Hat USA. Review your Azure Automation account identity exposure and apply Microsoft's security updates immediately. Reward: You've received the Binding Arbitration Bracer — it does nothing, but you clicked Accept, so here we are. #AzureSecurity #CloudSecurity #CyberSecurity #IdentityTheft #Microsoft #AchievementUnlocked (3/3)
0
0
0
0
The recording and slides for our Hacker Summer 2026 webinar, From Initial Access to Persistence: Abusing Synced Passkeys in Azure, are now available. Video: https://youtu.be/kwEga-U96dw?si=_nwzT74aT26cNpAx Slides: https://16cdd728-52b5-4665-b161-30113ba1b7e4.usrfiles.com/ugd/16cdd7_684bf5951d5648f0a213cf3a3836505f.pdf Special thanks to @nathanmcnulty@bird.makeup for an excellent session. #HackerSummer2026 #CloudSecurity #RedTeaming #AlteredSecurity
1008
0
9
0