Security
KVM zero-day lets guest VMs escape to host root, Vercel pays $50K
A critical KVM zero-day confirmed by Vercel allows full VM escape to host root across tenants, sparking debate over the $50,000 bounty.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Critical KVM zero-day enables full VM escape to host root
Independent researcher Paulos Yibelo discovered a critical KVM zero-day, confirmed by Vercel through its Sandbox bounty program. The flaw lets an attacker on any guest VM fully escape the virtual machine and gain root on the host, covering microVM to EC2 host escape with cross-tenant read, modify and remote code execution. Vercel CEO Guillermo Rauch confirmed the finding, calling KVM the industry gold standard for Linux virtualization. No exploit mechanism, affected versions or CVE identifier have been disclosed, and no exploitation has been reported. The $50,000 bounty drew criticism, with Vercel CTO Malte Ubl suggesting a fund rewarding researchers who find flaws affecting every hyperscaler and AI lab.
KVM zero-day vulnerability enables VM escape to host root | Cybernews →
Windows malware x47.c uses Grok AI to pick persistence methods
Qrator Research Labs uncovered Windows malware called x47.c while tracking cybercrime activity, based on a seller’s advertisement, documentation, screenshots and messages from a threat actor named WraithTools. Infected machines can be remotely controlled through a management panel and used in a botnet. Qrator found 18 advertised attack methods, including credential theft for browser passwords, cookies, Discord tokens, crypto wallets and AI-site tokens, plus a SOCKS5 proxy feature. An AI Stealth feature can use xAI’s Grok to examine the infected computer and select among predefined persistence methods such as startup programs and scheduled tasks, falling back on built-in methods if the AI request fails. x47.c also includes an AI API drain feature enabling a Denial of Wallet attack with a valid stolen API key. xAI did not respond before deadline.
Windows malware uses Grok AI to help stay hidden, researchers say →
FBI and Coast Guard found hackers breached tanker propulsion system
FBI and US Coast Guard investigators found evidence that hackers accessed the propulsion system of an oil supertanker as it approached the Texas coast in summer 2025, giving outsiders temporary access to the ship’s digital system. Officials are still examining how the breach occurred and who was responsible, and it was not immediately clear how long hackers had access or what they could control. The rare, invasive hack underscored the urgency that led US authorities to board the VL Prosperity in August; the fully laden carrier was bound for Galveston. The FBI said there were no reports of operational disruptions, vessel instability, physical danger to crews or environmental impacts. By September, agencies tracked cyber threats against nearly 20 shipping vessels worldwide.
Hackers Breached Propulsion System of US-Bound Oil Tanker →
Dell patches critical System Update flaw allowing root access
Dell warned customers to patch a critical vulnerability in its System Update command-line deployment tool, tracked as CVE-2026-86360. The path traversal weakness lets unauthenticated attackers with remote access execute arbitrary code with root privileges on unpatched devices, potentially compromising the application and underlying operating system. Dell also patched four high-severity DSU flaws: two enabling remote code execution (CVE-2026-63697 and CVE-2026-71168) and two enabling privilege escalation (CVE-2026-86361 and CVE-2026-86362). Dell recommends upgrading DSU to version 2.3.0.0 or later. The same day, Dell urged administrators to patch two maximum-severity Container Storage Modules vulnerabilities, CVE-2026-63688 and CVE-2026-63692. None have been flagged as actively exploited.
New Dell System Update flaw lets hackers gain root privileges →
Ransomware group BYOD leaks data of 3,615 Trump Mobile customers
A ransomware group called BYOD released personal data belonging to 3,615 Trump Mobile customers on its dark web leak site last week. No member of the Trump family was affected. The leaked data includes names, email addresses, telephone numbers, home addresses and order details. Among those listed is Eric Brunnett, vice president and chief information officer for the Trump Organization. BYOD said it gained access after infecting an employee of Florida-based Liberty Mobile, and claimed it still has access to Trump Mobile’s backend dashboard. Trump Mobile is owned by T1 Mobile, which uses a licensed brand from The Trump Organization. In a statement, BYOD said Trump Mobile replied to breach notification with „We have no team to handle this.” Trump Mobile did not immediately respond to a request for comment.
Trump Mobile’s latest problem: Hackers just released customer information →