⤷ Title: Testing Authorization Boundaries in Multi-Region, Multi-Tenant Applications
════════════════════════
𐀪 Author: Mdporschaa
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:16:01 GMT
════════════════════════
⌗ Tags: #application_security #appsec #cybersecurity #privilege_escalation
════════════════════════
𐀪 Author: Mdporschaa
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:16:01 GMT
════════════════════════
⌗ Tags: #application_security #appsec #cybersecurity #privilege_escalation
Medium
Testing Authorization Boundaries in Multi-Region, Multi-Tenant Applications
How I approach authorization boundary testing when the same application serves multiple accounts and multiple regions from a shared…
⤷ Title: From an Exposed Configuration File to Root Shell — RatCTF Write-up
════════════════════════
𐀪 Author: 0xnay33m
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 07:56:00 GMT
════════════════════════
⌗ Tags: #misconfiguration #web_hacking #ctf_writeup #privilege_escalation #penetration_testing
════════════════════════
𐀪 Author: 0xnay33m
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 07:56:00 GMT
════════════════════════
⌗ Tags: #misconfiguration #web_hacking #ctf_writeup #privilege_escalation #penetration_testing
Medium
From an Exposed Configuration File to Root Shell — RatCTF Write-up
In this challenge, a seemingly harmless web server exposed a configuration file containing SSH credentials. Those credentials granted…
⤷ Title: CVE-2026-64564: SCTP Flaw Enables Container Escape
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_64564 #Linux Kernel #privilege escalation #SCTPhantom #use after free
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_64564 #Linux Kernel #privilege escalation #SCTPhantom #use after free
Daily CyberSecurity
CVE-2026-64564: SCTP Flaw Enables Container Escape
TL;DR A Linux kernel use-after-free in SCTP, tracked as CVE-2026-64564, allows local attackers to gain root. Researchers demonstrated privilege escalation and container-to-host escape on five dist…
⤷ Title: CVE-2026-5430: WSO2 Account Takeover Flaws Rated Up to CVSS 10
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:04:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #API Manager #Authentication Bypass #CVE_2026_1728 #CVE_2026_5430 #privilege escalation #WSO2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:04:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #API Manager #Authentication Bypass #CVE_2026_1728 #CVE_2026_5430 #privilege escalation #WSO2
Daily CyberSecurity
CVE-2026-5430: WSO2 Account Takeover Flaws Rated Up to CVSS 10
TL;DR WSO2 disclosed four critical vulnerabilities across its API and identity products. Several are WSO2 account takeover flaws. The worst, CVE-2026-5430, scores a maximum 10 through a JWT authen…
⤷ Title: CVE-2026-10090: Red Hat ACM Privilege Escalation Flaw Grants Cluster-Admin, Rated CVSS 9.9
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ACM #Cluster Admin #CVE_2026_10090 #Helm #Kubernetes #privilege escalation #red hat
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ACM #Cluster Admin #CVE_2026_10090 #Helm #Kubernetes #privilege escalation #red hat
Daily CyberSecurity
CVE-2026-10090: Red Hat ACM Privilege Escalation Flaw Grants Cluster-Admin, Rated CVSS 9.9
TL;DR Red Hat disclosed a critical privilege escalation flaw in Advanced Cluster Management (ACM) for Kubernetes. Tracked as CVE-2026-10090, it scores 9.9 on CVSS. A user with only namespace edit …
⤷ Title: CVE-2026-43074: Linux Kernel eventpoll Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 12:55:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #android #CVE_2026_43074 #eventpoll #Linux Kernel #Pixel #privilege escalation #use after free
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 12:55:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #android #CVE_2026_43074 #eventpoll #Linux Kernel #Pixel #privilege escalation #use after free
Daily CyberSecurity
CVE-2026-43074: Linux Kernel eventpoll Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed
TL;DR A Linux kernel eventpoll flaw lets a local user climb to root. Tracked as CVE-2026-43074, it scores 7.3 on CVSS. Researchers confirmed a working root shell on a Pixel 10 Pro. The full detail…
⤷ Title: Linux Privilege Escalation: From Enumeration to Root Access | TryHackMe Walkthrough |By Nagaraju
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 17:27:29 GMT
════════════════════════
⌗ Tags: #ethical_hacking #root_level_access #tryhackme #privilege_escalation #penetration_testing
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 17:27:29 GMT
════════════════════════
⌗ Tags: #ethical_hacking #root_level_access #tryhackme #privilege_escalation #penetration_testing
Medium
Linux Privilege Escalation: From Enumeration to Root Access | TryHackMe Walkthrough |By Nagaraju
Privilege escalation is a journey. There are no silver bullets, and much depends on the specific configuration of the target system. The…
⤷ Title: Linux Privilege Escalation — Exploiting Misconfigured Cron Jobs | By Dharavath Nagaraju
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 19:10:43 GMT
════════════════════════
⌗ Tags: #ethical_hacking #privilege_escalation #penetration_testing #thm_writeup #cronjob
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 19:10:43 GMT
════════════════════════
⌗ Tags: #ethical_hacking #privilege_escalation #penetration_testing #thm_writeup #cronjob
Medium
Linux Privilege Escalation — Exploiting Misconfigured Cron Jobs | By Dharavath Nagaraju
Continuation of the previous Linux Privilege Escalation lab.
⤷ Title: CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 01:01:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container security #CVE_2026_44945 #Impersonation #Kubernetes #privilege escalation #Rancher #SUSE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 01:01:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container security #CVE_2026_44945 #Impersonation #Kubernetes #privilege escalation #Rancher #SUSE
Daily CyberSecurity
CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1
TL;DR A critical flaw lets a low-privileged Rancher user seize full control of the platform. Tracked as CVE-2026-44945, it scores 9.1 on CVSS. This Rancher privilege escalation stems from a cross-…
⤷ Title: Entra ID Security: Dynamic Group Attribute Manipulation Leading to Privilege Escalation
════════════════════════
𐀪 Author: Borz Fabian-Denis
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 05:43:53 GMT
════════════════════════
⌗ Tags: #entra_id #privilege_escalation #hacking #microsoft_security #group_dynamics
════════════════════════
𐀪 Author: Borz Fabian-Denis
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 05:43:53 GMT
════════════════════════
⌗ Tags: #entra_id #privilege_escalation #hacking #microsoft_security #group_dynamics
Medium
Entra ID Security: Dynamic Group Attribute Manipulation Leading to Privilege Escalation
In this article I will demonstrate how poor dynamic group membership rules could be exploited by hackers in order to enumerate and escalate…