A curated dispatch from GajShield

The GajShield Gazette

Lead story

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

The newly disclosed Linux kernel vulnerability, CVE-2026-46333, is a strong reminder that local privilege escalation flaws should never be treated as “low priority” just because they require local access. According to the report, the flaw existed for nearly nine years in the L…

Also today
In brief

Microsoft shares mitigation for YellowKey Windows zero-day

The YellowKey Windows zero-day is a serious reminder that disk encryption is only as strong as the boot and recovery chain around it. Accor…

May 20, 2026

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

The Webworm campaign highlights how advanced threat actors are increasingly abusing legitimate cloud and collaboration platforms for comman…

May 20, 2026

GitHub investigates internal repositories breach claimed by TeamPCP

The reported GitHub incident is a serious reminder that developer ecosystems are now one of the most attractive targets for cybercriminal g…

May 20, 2026

Max-severity flaw in ChromaDB for AI apps allows server hijacking

The ChromaDB vulnerability is a serious warning for organizations building AI applications: AI infrastructure is now part of the attack sur…

May 20, 2026

Cybercrime service disrupted for abusing Microsoft platform to sign malware

The disruption of the Fox Tempest malware-signing-as-a-service operation shows how attackers are abusing trust itself as an attack vector. …

May 20, 2026

FBI: Americans lost over $388 million to scams using crypto ATMs in 2025

The FBI’s warning on crypto ATM scams highlights how cybercrime is not always about sophisticated malware or zero-day exploits. Sometimes i…

May 20, 2026

Microsoft Self-Service Password Reset abused in Azure data theft attacks

The Storm-2949 campaign shows how identity recovery workflows can become an attack path when social engineering is added to the mix. Accord…

May 20, 2026

Kieback & Peter DDC Building Controllers

CISA’s advisory on Kieback & Peter DDC Building Controllers is another reminder that building automation systems are now part of the cyber-…

May 20, 2026

The New Phishing Click: How OAuth Consent Bypasses MFA

The Hacker News article highlights an important shift in phishing: attackers are no longer always trying to steal passwords. They are incre…

May 20, 2026

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

The Drupal advisory is a clear reminder that CMS platforms remain high-value targets because they sit directly on the public internet and o…

May 20, 2026

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

The SEPPMail Secure E-Mail Gateway vulnerabilities are a strong reminder that security gateways themselves must be treated as high-value at…

May 20, 2026