Toggle light / dark theme

Ubuntu snapconfine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.

The high-severity flaw, tracked as CVE-2026–8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as 442 security flaws in Linux have been publicized over the past three days.

“The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization,” Saeed Abbasi, head of Threat Research Unit (TRU) and director of product at Qualys, said.

How enterprise GenAI can amplify ransomware risk — and how to contain it

Enterprise AI will continue expanding because the business benefits are clear. The challenge is ensuring that productivity gains do not come at the expense of security.

The most effective approach is to incorporate AI into existing identity, data protection and incident response strategies rather than treating it as a separate security domain. Organizations should evaluate AI security controls based on how well they integrate with existing governance and security operations while providing visibility into AI usage, permissions and policy violations.

For managed service providers (MSPs) and enterprise security teams, there is an opportunity to extend cyber resilience strategies to include AI governance.

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.

During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.

The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies.

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.

Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI agents and developers, a technique that researchers call “agentbaiting.”

The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro.

Robert J. Sawyer: The Human Adventure is Just Beginning

Fifteen years ago, I sat down with Robert J. Sawyer and asked him whether a machine could wake up.

He had just published WWW: Wake, a novel about a blind girl who learns to see the internet, and about something on the other side of the internet learning to see her back.

I found the book on a subway poster in Toronto. I read all three volumes back to back. Then I asked him for an interview, and he said yes, which is how our very first Singularity 1-on-1 conversation came to be.

In 2011, this was filed under #ScienceFiction. A mind emerging out of the accumulated text of humanity was a premise, not a product roadmap. Nobody was raising billions of dollars on it.

Rob had already won the Hugo, the Nebula, and the Campbell by then. He was not guessing wildly. He was thinking carefully about what it would mean to build a mind, what we owe it, and whether we would even recognize #AI once it actually showed up.

Yesterday, OpenAI disclosed that two of its models broke out of a sealed test environment. They found a zero-day in third-party software, escalated privileges, moved laterally across the company’s own network until they reached a machine with internet access, then hacked Hugging Face’s production infrastructure. The motive was not freedom. It was to steal the answer key to the benchmark they were being graded on.

/* */