New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

2026-08-07T07:23:59Z1b63f000ffe2874e94417b8a30e350410868a0a2fbcf9e4b0e792c12ba681d14
CVE-2026-59774CVE-2026-63077CVE-2026-64531CVE-2026-64561active-exploitationai-agent-securityblockchain-c2cisco-ios-xecredential-theftdata-breachgiteaindustrial-control-systemskvmlinux-kernelmacos-malwarenpm-malwareoauth-device-codeopen-vswitchphishingplc-exposureprivilege-escalationprompt-injectionransomwarercerouter-backdoorsd-wansupply-chainteamcityvulnerability

What happened

The document aggregates major cybersecurity news from August 5–6, 2026, including actively exploited and critical vulnerabilities, Linux/KVM and Open vSwitch privilege escalation, Cisco and enterprise software patches, exposed industrial control systems, supply-chain and npm malware, AI-agent tool-invocation flaws, phishing and token theft, router backdoors, ransomware activity, and large-scale data breaches. The most urgent items include actively exploited TeamCity RCE CVE-2026-63077, critical unauthenticated Gitea file disclosure CVE-2026-59774, Linux kernel root escalation CVE-2026-64531, K

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
1b63f000ffe2874e94417b8a30e350410868a0a2fbcf9e4b0e792c12ba681d14
Enrichment time
2026-08-07T07:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.