~/greenteam/nerd

Sunday, May 31, 2026

Daily digest

cybersec BleepingComputer

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect, is now being actively exploited to breach corporate networks. Organizations relying on GlobalProtect for remote access — including those protecting CUI in CMMC environments — should apply patches or mitigations immediately and review VPN access logs for anomalous activity.

cybersec BleepingComputer

New CIFSwitch Linux flaw gives root on multiple distributions

A local privilege escalation vulnerability in the Linux kernel, dubbed 'CIFSwitch,' allows attackers to forge CIFS authentication key descriptions and abuse the kernel's key request mechanism to gain root privileges. This affects multiple Linux distributions and is directly relevant to environments running Linux-based hypervisors, containers, or automation platforms such as Nutanix AHV nodes or Ansible control hosts.