Four Linux Network Flaws Can Turn a Local User Into Root, and One Evades the Easy Mitigation
DirtyAH6, TUNderflow, PPPoEject and DiagSpill reach different kernel subsystems. One mitigation does not cover all four.
DirtyAH6, TUNderflow, PPPoEject and DiagSpill reach different kernel subsystems. One mitigation does not cover all four.
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.
Gyazo stored far more than pictures. Attackers obtained user records, OCR text, location data and information used to construct image URLs.
The attackers reached operational settings. Operators disabled remote access, while officials said water delivery and public safety were not affected.
The employee had left. The token had not. GitHub traced the access path back to the wider TanStack supply-chain incident.
Four coding agents trusted a commit hash but did not verify the code that Git actually placed in the working tree.
The repositories copied more than 40 brands. The payload then used a trusted driver to remove the tools most likely to stop it.
The systems that manage firewalls and collect their logs have a network-reachable stack overflow before authentication.
The workflow definition became the payload. Exposed Conductor servers could accept an unauthenticated task and run it with the service's operating-system privileges.

The catalogue entries share a deadline, not necessarily an attacker or exploit chain. Each Linux kernel flaw needs its own exposure check.