⤷ Title: Root Access Unlocked: How a pam_namespace Flaw Lets Attackers Elevate Privileges on Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:39:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Linux #Local Privilege Escalation #LPE #PAM #pam_namespace #Pluggable Authentication Modules #privilege escalation #race condition #Symlink Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:39:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Linux #Local Privilege Escalation #LPE #PAM #pam_namespace #Pluggable Authentication Modules #privilege escalation #race condition #Symlink Attack
Daily CyberSecurity
Root Access Unlocked: How a pam_namespace Flaw Lets Attackers Elevate Privileges on Linux
A high-severity flaw (CVE-2025-6020) in Linux PAM's pam_namespace allows unprivileged users to gain root via symlink attacks and race conditions.
⤷ Title: Anthropic MCP Server Flaws: Path Traversal & Symlink Attacks Allow RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:19:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Anthropic #CVE_2025_53109 #CVE_2025_53110 #cybersecurity #MCP #Model Context Protocol #Path Traversal #privilege escalation #rce #Remote Code Execution #Symlink #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:19:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Anthropic #CVE_2025_53109 #CVE_2025_53110 #cybersecurity #MCP #Model Context Protocol #Path Traversal #privilege escalation #rce #Remote Code Execution #Symlink #Vulnerability
Daily CyberSecurity
Anthropic MCP Server Flaws: Path Traversal & Symlink Attacks Allow RCE
Cymulate reveals two flaws (CVE-2025-53110, CVE-2025-53109) in Anthropic's Filesystem MCP Server, allowing path traversal, symlink attacks, and RCE, exposing AI developer machines.
⤷ Title: Hack The Box: Usage Walkthrough
════════════════════════
𐀪 Author: packetsniper
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 13:23:26 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #hackthebox #sql_injection #symlink_backup_exploit #sqlmap
════════════════════════
𐀪 Author: packetsniper
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 13:23:26 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #hackthebox #sql_injection #symlink_backup_exploit #sqlmap
Medium
Hack The Box: Usage Walkthrough
Submitting a random email followed by a ' triggers a 500 SERVER ERROR indicating potential SQL injection. Also, note that clicking on Admin redirects to https://admin.usage.htb/, so make sure to add…
⤷ Title: Podman Patches Symlink Traversal Vulnerability in kube play Command (CVE-2025-9566)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:13:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #container security #CVE_2025_9566 #kube play #Kubernetes #Podman #symlink traversal #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:13:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #container security #CVE_2025_9566 #kube play #Kubernetes #Podman #symlink traversal #Vulnerability
Daily CyberSecurity
Podman Patches Symlink Traversal Vulnerability in kube play Command (CVE-2025-9566)
A high-severity flaw (CVE-2025-9566) in Podman allows malicious containers to overwrite host files via a symlink traversal attack. A patch is available in Podman v5.6.1.
⤷ Title: Critical AWS VPN Client Flaw CVE-2025-11462 (CVSS 9.3) Allows Root Privilege Escalation on macOS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 04:03:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS #Client VPN #CVE_2025_11462 #macOS #privilege escalation #root access #Symlink #Zero Trust
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 04:03:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS #Client VPN #CVE_2025_11462 #macOS #privilege escalation #root access #Symlink #Zero Trust
Daily CyberSecurity
Critical AWS VPN Client Flaw CVE-2025-11462 (CVSS 9.3) Allows Root Privilege Escalation on macOS
AWS patched a Critical (CVSS 9.3) local flaw (CVE-2025-11462) in its Client VPN for macOS. A non-admin user can gain root privileges via a symlink manipulation attack.
⤷ Title: PoC Exploit Releases for Windows Privilege Escalation Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 07:58:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #Patch Tuesday #privilege escalation #Recall #Symlink Attack #Windows LPE #WindowsAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 07:58:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #Patch Tuesday #privilege escalation #Recall #Symlink Attack #Windows LPE #WindowsAI
Daily CyberSecurity
PoC Exploit Releases for Windows Privilege Escalation Vulnerability
A High-severity LPE flaw (CVE-2025-60710) in the WindowsAI Recall Policy Configuration scheduled task allows local users to gain SYSTEM privileges via a symlink arbitrary delete attack.
⤷ Title: Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
Penetration Testing Tools
Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
NHS Digital warns that a high-severity 7-Zip symbolic link flaw (CVE-2025-11001) is being actively weaponized to execute arbitrary code. Update to 7-Zip 25.00 now!
⤷ Title: Gogs Zero-Day (CVE-2025-8110) Risks RCE for 700+ Servers via Symlink Path Traversal Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:16:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_8110 #Git Service #Gogs #Path Traversal #rce #SUPERSHELL #Symlink #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:16:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_8110 #Git Service #Gogs #Path Traversal #rce #SUPERSHELL #Symlink #zero_day
Daily CyberSecurity
Gogs Zero-Day (CVE-2025-8110) Risks RCE for 700+ Servers via Symlink Path Traversal Bypass
A Gogs zero-day (CVE-2025-8110) bypasses a previous patch, enabling RCE via symlink path traversal. Over 50% of exposed instances are compromised, deploying the Supershell C2. Disable open registration immediately.
⤷ Title: HTB: Outbound
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
Medium
HTB: Outbound
| Roundcube | PHP Deserialization | CVE-2025–49113 | 3DES Hash Decryption | Below | Symlink Attack |
⤷ Title: Sandbox Escape: Critical Flatpak Flaw Grants Full Host Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 09:15:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_34078 #cybersecurity #Flatpak #Flatpak Portal #infosec #Linux Security #rce #Sandbox Escape #Symlink Attack #systemd #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 09:15:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_34078 #cybersecurity #Flatpak #Flatpak Portal #infosec #Linux Security #rce #Sandbox Escape #Symlink Attack #systemd #Vulnerability
Daily CyberSecurity
Sandbox Escape: Critical Flatpak Flaw Grants Full Host Access
Critical 9.3 CVSS flaw (CVE-2026-34078) in Flatpak allows apps to escape sandboxes and access all host files. Secure your Linux system—update to v1.16.4 now!