High-severity vulnerability in Linux caused by a single faulty character

2026-06-09T20:51:53Z5bcf93ef78d4607974e73da6c653f8ba6cd656d254f672936877a9404d298931
ai-exploitbadhostbitlockerbotnetchatbotchromiumcredential-stealerdashlaneexploit-disclosurehardware-malwarelinux-kernelmetanpmopen-source-securitypassword-managerprivilege-escalationsandbox-escapesoftware-backdoorssd-side-channel-trackingstarlettesupply-chainusbuse-after-freevpn-seizurezero-day

What happened

A roundup of June 2026 security incidents: a high-severity Linux kernel use‑after‑free (triggered by a single faulty character) enables sandbox escape and local root escalation; supply‑chain and package‑manager compromises (dozens of backdoored Red Hat packages via NPM, Microsoft packages bundled with credential stealers); a critical backdoor/vulnerability (“BadHost”) found in widely used Starlette package threatening AI agents; Dashlane password‑vault downloads and an opaque advisory; an exploit against Meta’s AI support chatbot used to hijack Instagram accounts; a USB/USB‑adjacent speaker as

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
5bcf93ef78d4607974e73da6c653f8ba6cd656d254f672936877a9404d298931
Enrichment time
2026-06-09T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.