“kernel vulnerabilities” — 40 distilled results

CISA warns of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency warned on September 18–21, 2026, that hackers are actively exploiting three Linux kernel vulnerabilities, including one rated critical, and added them to its Known Exploited Vulnerabilities catalog.

CISA adds three critical Linux kernel vulnerabilities to exploited catalog

The US Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2025-39964, CVE-2026-53266) to its Known Exploited Vulnerabilities catalog on September 21, 2026, after observing active exploitation. The flaws affect kTLS, AF_ALG socket, and ebtables SNAT with CVSS scores up to 9.8, including public exploits available for privilege escalation and container escape.

CISA flags three Linux kernel CVEs with three-day patch deadline

The U.S. Cybersecurity and Infrastructure Security Agency added three actively exploited Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to its Known Exploited Vulnerabilities catalog on 2026-09-19, giving federal agencies a three-day deadline to patch. The report also noted four additional kernel flaws with public root exploits.

🐛 NEW SECURITY CONTENT 🐛 💻 macOS Golden Gate 27 - 210 bugs fixed https:// support.apple.com/en-us/149035 💻 macOS Sequoia 15.8 - 155 bugs fixed https:// support.apple.com/en-us/149043 💻 macOS Taho

🐛 NEW SECURITY CONTENT 🐛 💻 macOS Golden Gate 27 - 210 bugs fixed https:// support.apple.com/en-us/149035 💻 macOS Sequoia 15.8 - 155 bugs fixed https:// support.apple.com/en-us/149043 💻 macOS Tahoe 26.7 - 154 bugs fixed https:// support.apple.com/en-us/149042 📱 iOS and iPadO

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.

rss:arxiv-cscr 27d ago · rss:arxiv-cscr 29d ago

Tech firms launch coalition against AI cyberattacks

OpenAI led an open letter signed by more than 100 organizations, including Anthropic, Microsoft, Google, Amazon, and others, on August 27–29, 2026, calling for coordinated defense against rising AI-enabled cyberattacks. Nvidia's new safety platform received cautious praise by November 2026, with experts noting no single solution exists to AI security risks.

Wave of cybersecurity vulnerabilities disclosed across platforms

Between August 6 and August 20, 2026, multiple critical security flaws were disclosed: the Clop extortion group exploited CVE-2026-12569 in PTC Windchill to steal engineering data; Microsoft patched CVE-2026-24301 affecting Copilot Personal; and a high-severity vulnerability (CVE-2026-0075) in Android's ContactsProvider was made public, affecting Android versions 14–16.

New Signal Check is live: Episode 170 - September 18, 2026. This episode covers six critical signals from the cybersecurity landscape, including emergency patches for exploited Cisco vulnerabilities,

New Signal Check is live: Episode 170 - September 18, 2026. This episode covers six critical signals from the cybersecurity landscape, including emergency patches for exploited Cisco vulnerabilities, Iranian state malware targeting dissidents, and a devastating Check Point management flaw that grants attackers root access.

Samsung Galaxy S27 redesign rumors and technology updates

Leaked CAD renders from August 24–25, 2026, suggest Samsung's upcoming Galaxy S27 Ultra will feature a redesigned wide rear camera plateau. Anthropic linked Claude's memory system between chat and Cowork on August 25, 2026. Separate reports cover systemd SSD damage claims, Thai flooding, kelvin wave ocean phenomena, and NRC workforce assessments.

CISA adds seven exploited vulnerabilities to KEV catalog

On 2026-08-24, CISA added CVE-2026-21962 (Oracle HTTP Server and Weblogic Server Proxy Plug-in improper access control) to its Known Exploited Vulnerabilities catalog. On 2026-08-25 and 2026-08-26, CISA added six additional known exploited vulnerabilities including CVE-2026-60004 (Gitea code injection) and CVE-2015-3246 (Red Hat Libuser race condition).