News Jul 10, 2026 👁 25

IT News Roundup: KVM VM Escape Vulnerability, Gitea Exploitation, and Mass Data Breach - July 10, 2026

Security researchers disclosed a critical Linux kernel vulnerability enabling VM escape on KVM systems, Gitea deployments face rapid in-the-wild exploitation of a Docker authentication bypass, a major US insurance breach exposed nearly 7 million driver records, and BeyondTrust patched critical authentication flaws.

The past 24 hours have been dominated by infrastructure-level security concerns. A newly disclosed Linux kernel vulnerability threatens virtualization isolation across Intel and AMD platforms, while Gitea repositories are under active attack from a critical authentication bypass. On the data breach front, an American insurance company disclosed the compromise of nearly 7 million driver records, and several critical vendor patches and hardware backdoor warnings round out a busy news cycle.

Linux Kernel Vulnerability Enables KVM VM Escape on Intel and AMD Systems

Security researchers at Januscape have disclosed a critical Linux kernel vulnerability that allows virtual machine escape on KVM (Kernel-based Virtual Machine) systems running on both Intel and AMD processors. The flaw breaks guest-to-host isolation, meaning a compromised virtual machine could potentially gain control of the underlying host system.

VM escape vulnerabilities are among the most severe in virtualization security because they undermine the fundamental isolation that virtualization is designed to provide. Any organization running KVM-based virtualization — which includes most Linux cloud platforms, OpenStack deployments, Proxmox setups, and many homelab configurations — should evaluate exposure and apply patches as soon as they become available.

Source: Cybersecurity Daily Recap via Hendry Adrian

Gitea Docker Flaw (CVE-2026-20896) Under Rapid In-the-Wild Exploitation

A critical vulnerability in Gitea, the popular self-hosted Git service, is being actively exploited in the wild shortly after disclosure. CVE-2026-20896 allows attackers to bypass authentication using a single HTTP header, granting unauthorized access to vulnerable repositories and any secrets stored within them.

Gitea is widely deployed in homelab and small-to-medium business environments as a lightweight alternative to GitLab. The speed of exploitation following disclosure underscores the importance of keeping self-hosted services updated. Administrators running Gitea — especially in Docker containers — should verify their installations are patched immediately and audit access logs for signs of compromise.

Source: SecurityWeek and Cybersecurity Daily Recap

AssuranceAmerica Data Breach Exposes Nearly 7 Million Driver Records

American insurance company AssuranceAmerica has disclosed a data breach affecting approximately 7 million drivers after threat actors gained unauthorized access to its systems earlier this year. The breach exposed sensitive personal information belonging to policyholders, raising concerns about data protection practices in the insurance sector.

Large-scale insurance breaches are particularly damaging because they typically contain detailed personal information including names, addresses, dates of birth, and financial data — all highly valuable on the dark web. Affected individuals should monitor their credit reports and consider fraud protection services.

Source: BleepingComputer

New GodDamn Ransomware Family Uses PoisonX Kernel Driver for Defense Evasion

Cybersecurity researchers have identified a new ransomware family dubbed GodDamn that employs the PoisonX kernel driver as part of its defense evasion strategy. The kernel-level driver is used to neutralize security software, effectively disabling endpoint protection before the ransomware encrypts victim systems.

The use of signed or abused kernel drivers for defense evasion has become an increasingly common tactic among ransomware operators. Kernel-mode access gives malware deep system-level privileges that are difficult for user-space security tools to detect or block. Organizations should review kernel driver loading policies and ensure endpoint detection solutions include kernel-level monitoring.

Source: The Hacker News

BeyondTrust Patches Critical Authentication-Bypass Vulnerabilities

BeyondTrust, a provider of privileged access management (PAM) solutions, has released security patches addressing critical authentication-bypass vulnerabilities in its products. Authentication bypass flaws in PAM systems are particularly dangerous because they can give attackers direct access to privileged credentials and administrative sessions.

PAM platforms manage some of the most sensitive credentials in an organization’s infrastructure. Any vulnerability that allows authentication bypass effectively nullifies the security controls the platform is designed to enforce. Administrators using BeyondTrust solutions should apply the patches without delay and review privileged session logs for anomalies.

Source: Cybersecurity Daily Recap

CERT/CC Warns of Hidden Admin Backdoor in Tenda Routers

The US Computer Emergency Response Team (CERT/CC) has issued a warning about a hidden administrative backdoor discovered in Tenda-branded routers. The backdoor could allow remote attackers to gain administrative access to affected devices without authentication.

Tenda routers are popular in budget networking and home/homelab environments. Hidden backdoors in consumer networking hardware are a persistent concern because they often go undetected by users and can serve as an initial foothold for lateral movement within a network. Users of Tenda equipment should check for firmware updates and consider replacing affected models if patches are unavailable.

Source: Cybersecurity Daily Recap

State-Sponsored Activity: Armored Likho Targets Government and Power Infrastructure

Intelligence reports indicate that the Armored Likho threat group continues its campaign targeting government agencies and electric power infrastructure. The group’s persistent focus on critical infrastructure raises concerns about the operational tempo of state-sponsored actors in this sector.

Electric grid and government targeting by APT groups remains one of the most significant long-term cybersecurity concerns. Organizations in the energy and public sector should maintain heightened vigilance, enforce strict network segmentation, and ensure incident response plans account for sophisticated, persistent adversaries.

Source: Cybersecurity Daily Recap


← Back to Blog