TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Help Net Security

Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months

Help Net Security · 3 days ago · Read original ↗

ATT&CK techniques detected

4 predictions
T1068Exploitation for Privilege Escalation
86%
“% of self - hosted github servers exposed to rce, researchers warn ( cve - 2026 - 3854 ) when researchers at wiz reported an easily exploitable github remote code execution flaw ( cve - 2026 - 3854 ) on march 4, the company confirmed it within 40 minutes and pushed a fix to githu…”
T1190Exploit Public-Facing Application
69%
“cve - 2026 - 32202 ) attackers are exploiting cve - 2026 - 32202, a zero - click windows shell spoofing vulnerability that causes victims ’ systems to authenticate the attacker ’ s server, cisa and microsoft have warned. cve - 2026 - 32202 stems from an incomplete patch for cve -…”
T1195Supply Chain Compromise
61%
“organizations keep getting wrong in this help net security interview, scott schnoll, microsoft mvp for exchange, breaks down the shared responsibility model, where microsoft secures the cloud while organizations must protect their own data, identities, and configurations. the dis…”
T1566.002Spearphishing Link
47%
“mailbox repair utility ”. unc6692 is a newly identified threat group, documented by google ’ s threat intelligence group ( gtig ) following a campaign that began in late december 2025. cyber crooks got robinhood to send phishing emails to its own users an email phishing campaign …”

Summary

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: The AI criminal mastermind is already hiring on gig platforms Labor-hire platforms let anyone with a credit card post a task and pay a stranger to complete it. The RentAHuman platform extends that model to AI agents through a Model Context Protocol server, allowing an agent to post gigs directly. Listed tasks include attending in-person meetings, photographing locations, delivering items, … More

The post Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months appeared first on Help Net Security.