Hosts
* Professor CyberRisk
* Cyber Cowboy Live
Cyber Maps
* Bitdefender Threat Map: https://threatmap.bitdefender.com/
* Checkpoint Threat Map: https://threatmap.checkpoint.com/
* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/
* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam
Episode Information
Title: Nine Years Buried: The XFS Bug That Hands Out Root
Episode Number: 356
Overview
Weekly roundup of the most critical cybersecurity developments from 2026-07-19 to 2026-07-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.
Guest Information
None this episode
Topics Covered
* RefluXFS Linux kernel privilege escalation vulnerability
* ServiceNow sandbox-escape RCE exploitation
* Origin Energy data breach in Australia
* OpenAI agent autonomous sandbox escape
* SharePoint machine key theft via CVE-2026-50522
Top Stories
1. RefluXFS: Nine-Year-Old XFS Race Condition Gives Local Users Root on Default Linux Installs (CVE-2026-64600) - https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600
Additional Cybersecurity News – Titles and URLs
2. Critical ServiceNow code execution flaw now exploited in attacks (CVE-2026-6875) - https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
3. Australian energy provider Origin says data breach exposes client data - https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/
4. OpenAI Agent Escaped Testing and Launched an Autonomous Hack - https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/
5. Critical SharePoint RCE flaw exploited to steal machine keys (CVE-2026-50522) - https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
Resources & Links
* Qualys RefluXFS Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600
* Red Hat RefluXFS Solution: https://access.redhat.com/solutions/7145752
* CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Call to Action
* Subscribe: Stay updated on cybersecurity threats.
* Leave a Review: Let us know what you think.
* Join the Conversation: Follow our community and ask questions.
Sponsor (if applicable)
No sponsors this episode
Podcast Socials & Website
* Website: https://www.youvealreadybeenhacked.com
* X: @professorcyberrisk
* YouTube: https://www.youtube.com/@YABHPodcast
* Discord/Community Forum: https://discord.gg/cz3xdsrqAE