New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

2026-08-07T01:23:59Z455b8f0e7e3c7e131fa089a886e197aab7029ff06f9d14ef5c1a826feaf33cf7
CVE-2026-59774CVE-2026-63077CVE-2026-64531CVE-2026-64561AI securityCisco IOS XECisco SD-WANGiteaKVMLinux kernelMicrosoft device code phishingOpen vSwitchRockwell PLCTeamCityactive exploitationagent tool abusebrowser malwarecredential theftcritical vulnerabilitiesdata breachindustrial control systemsmalicious npm packagesphishingprivilege escalationransomwareremote code executionsupply-chain securityvirtualization escape弱 random number generator

What happened

The feed reports a broad set of cybersecurity developments, including actively exploited and critical vulnerabilities in TeamCity, Gitea, Linux KVM/Open vSwitch, Cisco SD-WAN and IOS XE, exposed industrial control systems, supply-chain and malicious package activity, AI-agent tool authorization flaws, credential theft, phishing, ransomware, and major data breaches. The most urgent items are CVE-2026-63077 in TeamCity, reportedly exploited in the wild; CVE-2026-59774 in Gitea, enabling unauthenticated file reads; and Linux kernel flaws enabling guest escape or local privilege escalation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
455b8f0e7e3c7e131fa089a886e197aab7029ff06f9d14ef5c1a826feaf33cf7
Enrichment time
2026-08-07T01:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.