FR
live
tag

#privilege-escalation

ShieldCrash bypasses Microsoft Defender’s ShieldBreak fix to read files as SYSTEM

On September 9, 2026, researcher Chaotic Eclipse published ShieldCrash, a proof of concept that bypasses CVE-2026-69414 (ShieldBreak), the privilege-escalation flaw Microsoft claimed to have patched in Defender’s antimalware engine. Check your Malware Protection Engine version and treat the EDR itself as attack surface to monitor.

CVE-2026-6471 lets a PostgreSQL replication account run code as the system user

Present since PostgreSQL 9.4 in 2014, CVE-2026-6471 (CVSS 7.2) lets an account holding the REPLICATION attribute load an arbitrary library through logical decoding and run code as the server’s operating-system user. Fixed on August 13, 2026 via the output_plugin_libraries parameter: update and make sure your output plugins are explicitly allowlisted.

A forged NTFS3 image gives any local user root the moment a USB drive is mounted

The Linux kernel’s NTFS3 driver restores setuid bits straight from untrusted on-disk data, letting a crafted NTFS image produce a setuid-root binary as soon as the volume mounts. Reported privately two months ago and still unpatched, the bug hits desktops whose automounter mounts NTFS volumes with suid on by default.

Type at least two characters.

navigate open esc dismiss