Discover new vulnerabilities and security strategies. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
Copy of WTR Newsletter Email Header (13)-1

In this week's roundup, we feature a 16-year-old flaw in Linux's KVM hypervisor that allows a guest virtual machine to crash or escape to the host on both Intel and AMD x86 systems — the first publicly demonstrated guest-to-host exploit of its kind; elsewhere in the threat landscape, a new Linux kernel race condition dubbed Bad Epoll lets any unprivileged user escalate to root with 99% reliability and can be triggered from inside a browser's renderer sandbox, The Gentlemen ransomware underscores why having backups and endpoint tools in place is not the same as being able to recover from an attack, a 15-year-old Linux kernel vulnerability called GhostLock lurked undetected since 2011 and earned researchers $92,000 from Google's bug bounty program after being weaponized for container escapes, and researchers have documented what may be the first ransomware operation conducted entirely by an AI agent — autonomously handling every stage of the attack from reconnaissance to encryption. Read on!

linux-kvm

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A 16-year-old use-after-free bug in Linux's KVM hypervisor, dubbed Januscape and tracked as CVE-2026-53359, allows code running inside a guest virtual machine to crash or escape to the underlying host — on both Intel and AMD x86 systems. The public proof-of-concept reliably panics the host, taking every other tenant VM on the machine down with it. The researcher who discovered it reports that a separate, unreleased exploit turns the same bug into full host code execution. The flaw sits in KVM's shadow MMU code and is triggered when KVM reuses the wrong type of memory tracking page — the kind of subtle logic error that can go undetected for years. The attack requires root inside a guest VM and nested virtualization enabled on the host, conditions that are common in multi-tenant cloud environments. Fixed stable kernel versions shipped July 4, 2026; administrators running x86 KVM hosts with untrusted guests should confirm the patch is applied or disable nested virtualization immediately as a temporary mitigation. 

Read More

Joseph Comps - Threat Intelligence Analyst
Joseph Comps, Solutions Engineer & Threat Intelligence Analyst:

"x"

On x

Ari-1
Ari Saperstein, Manager of Global Channel Technical Enablement:

"x"

On x

root-linux

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android 

A newly disclosed Linux kernel race condition called Bad Epoll allows any local user with no special privileges to escalate to root, with a working exploit achieving roughly 99% reliability on tested systems. The flaw sits in the epoll subsystem — a standard kernel feature used by servers, browsers, and network services that cannot simply be switched off. What makes it particularly notable is that it can be triggered from inside a browser's renderer sandbox, a barrier that blocks almost every other kernel exploit, and that it also reaches Android. The vulnerability affects a wide range of distributions and patches are available — administrators should apply their distribution's latest kernel update as a priority.

Read more
Screenshot 2026-07-09 112211

Why The Gentlemen Ransomware Is a Test of Identity and Recovery Controls 

The Gentlemen ransomware spreads through legitimate Windows administrative tools, disables security software, deletes shadow copies, and targets backup and virtualization services before encryption begins — all to ensure that by the time the ransom note arrives, recovery is as difficult as possible. Analysis from Picus Security highlights that the group's Linux and ESXi tooling follows the same playbook, with broader platform coverage across Windows, Linux, NAS, BSD, and ESXi. The central lesson for defenders is that having backups and endpoint tools in place is not the same as being able to use them during an active compromise — The Gentlemen are specifically built to make sure those tools fail when they matter most. 

Read more
Linux

15-Year-Old Linux Vulnerability 'GhostLock' Earns Researchers $92k From Google 

GhostLock is a use-after-free flaw introduced in 2011 and present in every major Linux distribution for 15 years before a patch shipped in April 2026. The bug occurs when a kernel cleanup function incorrectly frees memory on behalf of a sleeping thread rather than the current task, leaving a dangling pointer that an attacker can weaponize for local privilege escalation to root and, as researchers demonstrated, a full container escape. The vulnerability was uncovered through Google's kernelCTF competitive research program and earned the discovering team a $92,000 bounty — a signal of how serious Google assessed the exploitability to be. It is the latest in a long run of Linux kernel privilege escalation disclosures joining Januscape, Bad Epoll, DirtyClone, and others from recent months, underscoring how much attack surface remains buried in aging kernel code.

Read more
pufferfish

JadePuffer Ransomware Used AI Agent to Automate Entire Attack 

Researchers at Sysdig have documented what they believe is the first ransomware operation conducted entirely by an autonomous AI agent. JadePuffer gained initial access by exploiting a known remote code execution flaw in a Langflow deployment, then used an LLM agent to handle reconnaissance, credential theft, lateral movement, persistence, privilege escalation, and encryption — adapting in real time when steps failed, in one case going from a failed login to a working fix in 31 seconds. The operation encrypted over 1,300 database configuration entries and left a ransom note with a Bitcoin address. Sysdig concludes that the age of "agentic threat actors" has arrived, lowering the skill floor for conducting damaging cyberattacks while also creating new detection opportunities given how LLM-generated payloads behave. 

Read more

Thanks for reading! Feel free to share this email with your network, and for more hypervisor and Linux cybersecurity updates, visit valicyber.com.

 

Website
LinkedIn
X

Vali Cyber, Inc., 529 Rookwood Place, Charlottesville, VA 22903, USA

Unsubscribe Manage preferences