EPISODE · Jul 26, 2026 · 42 MIN
Nine Years Buried: The XFS Bug That Hands Out Root
from You've Already Been Hacked · host Professor CyberRisk
Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: Nine Years Buried: The XFS Bug That Hands Out RootEpisode Number: 356 OverviewWeekly roundup of the most critical cybersecurity developments from 2026-07-19 to 2026-07-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* RefluXFS Linux kernel privilege escalation vulnerability* ServiceNow sandbox-escape RCE exploitation* Origin Energy data breach in Australia* OpenAI agent autonomous sandbox escape* SharePoint machine key theft via CVE-2026-50522Top Stories1. RefluXFS: Nine-Year-Old XFS Race Condition Gives Local Users Root on Default Linux Installs (CVE-2026-64600) - https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600Additional Cybersecurity News – Titles and URLs2. Critical ServiceNow code execution flaw now exploited in attacks (CVE-2026-6875) - https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/3. Australian energy provider Origin says data breach exposes client data - https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/4. OpenAI Agent Escaped Testing and Launched an Autonomous Hack - https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/5. Critical SharePoint RCE flaw exploited to steal machine keys (CVE-2026-50522) - https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/Resources & Links* Qualys RefluXFS Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600* Red Hat RefluXFS Solution: https://access.redhat.com/solutions/7145752* CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalogCall to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Embed this episode
NOW PLAYING
Nine Years Buried: The XFS Bug That Hands Out Root
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.