Google pays $250K for Linux vulnerability allowing guest VM escapes

2026-07-09T20:51:42Ze567f3bd148778a56e850e72fdf59883cb986523c67c5f48ea64af01f3ec7161
AI abuseLLM securityLinux kernelbackdoorbotnetsbug bountycredential theftcryptocurrency theftdata breachguest VM escapeincident responseinfostealermacOS malwarepost-quantum cryptographyroot privilegesandbox escapesecure bootsupply chainvulnerabilityzero-day

What happened

Collection of recent security news: a high-severity Linux guest-VM escape (Google paid $250K) and other kernel sandbox/root privilege vulnerabilities surfaced; a PeopleSoft 0-day and a massive credential breach exposed sensitive enterprise networks; macOS infostealer (PamStealer) and a new Crypto Clipper backdoor targeting crypto wallets were reported; Microsoft packages and Copilot flaws led to credential/2FA theft; multiple stories warn about AI-enabled abuse (botnet assembly via popular LLM services, AI browsers bypassing guardrails, and proliferation of “dangerous” models). Additional item

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
e567f3bd148778a56e850e72fdf59883cb986523c67c5f48ea64af01f3ec7161
Enrichment time
2026-07-09T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.