INTEL_REPORT
The Hacker News · published 7/8/2026, 6:16:44 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network 15-…
https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
sha256:7e9626c1c9bc92da75adfc04e8f2a61765cc33a4754ae02d4ebb4eb67a2a59a2
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| CVE-2026-10702 |
| Open → |