#NebuSec
POC Root and Container Escape on Linux Distros
CyberMeowfia/IonStack/CVE-2026-43499 at main · NebuSec/CyberMeowfia
PoCs and exploits for CVEs discovered by VEGA. . Contribute to NebuSec/CyberMeowfia development by creating an account on GitHub.
github.com
July 9, 2026 at 8:21 PM
September 15, 2026 at 6:17 AM
Linuxカーネルのローカル脆弱性、root権限奪取につながる恐れ

ローカルで悪用可能なLinuxの脆弱性群が、root権限の完全な乗っ取りを狙った実戦投入可能なコードへと姿を変えました。NebuSecは一連の重大なカーネル脆弱性を公表するとともに、完全に機能するエクスプロイトを公開し、openSUSE、Debian、RHEL、Ubuntu、Fedora、Arch
Linuxカーネルのローカル脆弱性、root権限奪取につながる恐れ
ローカルで悪用可能なLinuxの脆弱性群が、root権限の完全な乗っ取りを狙った実戦投入可能なコードへと姿を変えました。NebuSecは一連の重大なカーネル脆弱性を公表するとともに、完全に機能するエクスプロイトを公開し、openSUSE、Debian、RHEL、Ubuntu、Fedora、Arch
blackhatnews.tokyo
September 14, 2026 at 7:23 AM
Feels like a Monday when you open the inbox and see "Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more".

https://www.openwall.com/lists/oss-security/2026/09/08/1

Various exploits/PoCs here:
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research

While I don't know how […]
Original post on mstdn.social
mstdn.social
September 8, 2026 at 1:11 PM
#後で読む 用メモです→
Linux Kernelの脆弱性 CVE-2026-68162SCTPのUse-After-Freeでローカル権限昇格のおそれ ...
Linux Kernelの脆弱性 CVE-2026-68162、SCTPのUse-After-Freeでローカル権限昇格のおそれ Ubuntu向けPoC公開|セキュリティニュースのセキュリティ対策Lab
Linux kernelのSCTPにUse-After-Free脆弱性CVE-2026-68162が公表され、NebuSecがUbuntu向けPoCを公開しました。CVSS 7.8で、低権限ローカルユーザーからroot権限昇格につながる可能性があります。影響kernel、修正版、Ubuntuの評価状況、PoC公開後の対応を整理します
rocket-boys.co.jp
September 4, 2026 at 12:14 PM
Original text: "IonStack Part I: Unsound IonBanana Peel in Ion Compiler, Slipping Through Firefox's SpiderMonkey JIT" — Nebula Security, NebuSec (July 10, 2026). Code, tables and figures below are reproduced verbatim w
https://core-jmp.org/2026/08/ionstack-part-1-cve-2026-10702-spidermonkey-jit-uaf/
IonStack Part I: An Unsound IonBanana Peel in the Ion Compiler — Slipping Through Firefox's SpiderMonkey JIT (CVE-2026-10702)
CVE-2026-10702 is a miscompilation bug in Firefox's SpiderMonkey Ion/Warp JIT. The MObjectToIterator instruction produced by scalar-replacing Object.keys() declares a load-only alias set, but it can actually allocate a fresh property buffer. Global value numbering trusts that model and reuses a now-dangling slots pointer, yielding a use-after-free that is escalated into addrof/fakeobj, a fake Uint8Array, and full arbitrary read/write in the renderer.
core-jmp.org
August 1, 2026 at 12:28 PM
Benutzt hier jemand Linux? Nebusec hat ein Stack-UAF im io_uring-Stack gefunden — GhostLock — das seit 15 Jahren in allen Distributionen steckt. Local Privilege Escalation, noch kein Patch in Sicht. Schöne Grüße an alle, die dachten Open-Source-Kernel wären von sowas gefeit.
GhostLock: 15-year-old Stack-UAF in Linux io_uring
nebusec.ai
July 13, 2026 at 7:09 AM
MT @nebusecurity@x.com
GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. #infosec
github.com/NebuSec/Cybe...
github.com
July 9, 2026 at 8:15 AM