Hosts

* Professor CyberRisk

* Cyber Cowboy Live


Cyber Maps

* Bitdefender Threat Map: https://threatmap.bitdefender.com/

* Checkpoint Threat Map: https://threatmap.checkpoint.com/

* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


Episode Information

Title: Nine Years Buried: The XFS Bug That Hands Out Root

Episode Number: 356

Overview

Weekly roundup of the most critical cybersecurity developments from 2026-07-19 to 2026-07-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


Guest Information

None this episode


Topics Covered

* RefluXFS Linux kernel privilege escalation vulnerability

* ServiceNow sandbox-escape RCE exploitation

* Origin Energy data breach in Australia

* OpenAI agent autonomous sandbox escape

* SharePoint machine key theft via CVE-2026-50522


Top Stories

1. RefluXFS: Nine-Year-Old XFS Race Condition Gives Local Users Root on Default Linux Installs (CVE-2026-64600) - https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600


Additional Cybersecurity News – Titles and URLs

2. Critical ServiceNow code execution flaw now exploited in attacks (CVE-2026-6875) - https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/

3. Australian energy provider Origin says data breach exposes client data - https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/

4. OpenAI Agent Escaped Testing and Launched an Autonomous Hack - https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/

5. Critical SharePoint RCE flaw exploited to steal machine keys (CVE-2026-50522) - https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/


Resources & Links

* Qualys RefluXFS Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600

* Red Hat RefluXFS Solution: https://access.redhat.com/solutions/7145752

* CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalog


Call to Action

* Subscribe: Stay updated on cybersecurity threats.

* Leave a Review: Let us know what you think.

* Join the Conversation: Follow our community and ask questions.


Sponsor (if applicable)

No sponsors this episode


Podcast Socials & Website

* Website: https://www.youvealreadybeenhacked.com

* X: @professorcyberrisk

* YouTube: https://www.youtube.com/@YABHPodcast

* Discord/Community Forum: https://discord.gg/cz3xdsrqAE

Podden och tillhörande omslagsbild på den här sidan tillhör Professor CyberRisk. Innehållet i podden är skapat av Professor CyberRisk och inte av, eller tillsammans med, Poddtoppen.