BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

2026-07-07T07:24:09Zd2f011a49686cf1ef5a015f5261e24c2bb3a39a6ffdfc31aa883d3be6b709f83
APTBeyondTrustC2 frameworkCVECitrix BleedGiteaKVM escapeLinux kernelRATair‑gap exfiltrationcriticalmacOS stealernpm compromiseprivilege escalationproxy networkransomwareremote access trojansupply chainvulnerability

What happened

This collection summarizes a wave of high‑impact security news: multiple critical vulnerabilities disclosed and patched (notably BeyondTrust pre‑auth auth bypass CVE-2026-40138, Gitea Docker header trust CVE-2026-20896 under active probing, Linux KVM guest→host escape tracked as CVE-2026-53359, and a local root escalation Bad Epoll kernel flaw CVE-2026-46242), plus ongoing exploitation and reconnaissance. Threat actor activity includes Iran‑linked Cavern/Cav3rn C2 targeting Israeli organizations, supply‑chain and repo poisoning by North Korea‑linked packages (PolinRider), ToddyCat’s Umbrij exf

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
d2f011a49686cf1ef5a015f5261e24c2bb3a39a6ffdfc31aa883d3be6b709f83
Enrichment time
2026-07-07T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.