Nine Years Buried: The XFS Bug That Hands Out Root episode artwork

EPISODE · Jul 26, 2026 · 42 MIN

Nine Years Buried: The XFS Bug That Hands Out Root

from You've Already Been Hacked · host Professor CyberRisk

Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: Nine Years Buried: The XFS Bug That Hands Out RootEpisode Number: 356 OverviewWeekly roundup of the most critical cybersecurity developments from 2026-07-19 to 2026-07-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* RefluXFS Linux kernel privilege escalation vulnerability* ServiceNow sandbox-escape RCE exploitation* Origin Energy data breach in Australia* OpenAI agent autonomous sandbox escape* SharePoint machine key theft via CVE-2026-50522Top Stories1. RefluXFS: Nine-Year-Old XFS Race Condition Gives Local Users Root on Default Linux Installs (CVE-2026-64600) - https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600Additional Cybersecurity News – Titles and URLs2. Critical ServiceNow code execution flaw now exploited in attacks (CVE-2026-6875) - https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/3. Australian energy provider Origin says data breach exposes client data - https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/4. OpenAI Agent Escaped Testing and Launched an Autonomous Hack - https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/5. Critical SharePoint RCE flaw exploited to steal machine keys (CVE-2026-50522) - https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/Resources & Links* Qualys RefluXFS Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600* Red Hat RefluXFS Solution: https://access.redhat.com/solutions/7145752* CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalogCall to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE

Episode metadata supplied by the publisher feed · Published Jul 26, 2026

Embed this episode

NOW PLAYING

Nine Years Buried: The XFS Bug That Hands Out Root

0:00 42:47

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of You've Already Been Hacked?

This episode is 42 minutes long.

When was this You've Already Been Hacked episode published?

This episode was published on July 26, 2026.

Can I download this You've Already Been Hacked episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!