September 23 | 24h Recap: Ubuntu container escape, F5 OAuth RCE and Windows process injection
Three technical stories from today’s recap: Ubuntu container escape: DepthFirst released an exploit for CVE-2026-80521 that reaches host root from a container on Ubuntu 26.04. The AF_UNIX flaw was fixed upstream, but affected distribution kernels still need the patch. F5 BIG-IP APM RCE: CVE-2026-94127 is being exploited against vulnerable OAuth authorization-server configurations. Management-interface access is not required. Hotfixes are available. Process Parameter Poisoning: Flashpoint tested Windows code injection through process initialization structures, avoiding common memory-writing APIs. The technique produced no alerts from the EDR controls tested in its lab. More technical details and source links in today’s recap on CyberRecaps, and have an amazing day 🙂 submitted by /u/FishingTechnical453 [link] [comments]Technical Information Security Content & DiscussionRead More