Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'local'

View all threats tagged with 'local'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: local

Threats Tagged 'local'

Click on any threat for detailed analysis and mitigation recommendations

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
0

A set of three vulnerabilities were discovered in the BigWave driver on the Pixel 9 device, which is accessible from the mediacodec sandboxed context. One of these bugs enables a use-after-free condition that allows escaping the mediacodec sandbox and achieving arbitrary kernel read/write on the Pixel 9. The vulnerabilities were fixed on January 5, 2026. The BigWave driver accelerates AV1 decoding and is exposed to userland processes in the mediacodec SELinux context, which is intended to be constrained. The use-after-free arises from a race condition between ioctl processing and a worker thread handling hardware jobs, leading to a kernel object being freed while still referenced.

Join the discussion
New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
0

New York State has awarded over $9 million in grants to 153 drinking water and wastewater systems to enhance their cybersecurity defenses. This initiative follows a recent multistate cyber campaign targeting water infrastructure, which caused operational disruptions in several states but did not affect New York utilities publicly. The funding supports cybersecurity assessments, upgrades, and compliance with new state cybersecurity standards for utilities. The campaign involved attacks on operational technology systems, including programmable logic controllers, and is suspected to be linked to Iranian threat actors. Federal agencies recommend removing exposed OT devices from the internet and securing remote access. The grants aim to improve resilience and compliance with mandatory cybersecurity measures for critical water infrastructure.

Join the discussion
What water utilities need to know about cybersecurity compliance
0

This content discusses the evolving cybersecurity compliance landscape for U.S. water and wastewater utilities amid increasing federal and state regulatory enforcement. It highlights the legal requirements under the America’s Water Infrastructure Act (AWIA) 2013 for community water systems to certify Risk and Resilience Assessments and Emergency Response Plans addressing cyber threats. The EPA is actively enforcing existing authorities and providing updated guidance and tools to improve cybersecurity posture. States like New York have implemented binding cybersecurity regulations for wastewater facilities, including mandatory incident reporting and access controls. The discussion is framed by recent cyber attacks on water utilities, underscoring the urgency of compliance and risk management.

Join the discussion
Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security
0

Canada’s Bill C-8, the Critical Cyber Systems Protection Act (CCSPA), mandates critical infrastructure operators to report cyber incidents within 72 hours and imposes heavy financial penalties for non-compliance. The law targets sectors such as telecommunications, energy, transportation, and banking, requiring formal cybersecurity programs and mitigation of supply chain risks. The act highlights the operational challenge of detecting and reporting breaches rapidly in environments where IT and OT systems converge. Bill C-8 emphasizes the need for unified visibility across IT, OT, and IoT assets to meet the strict reporting deadline and avoid penalties. Solutions that combine active and passive monitoring can help eliminate blind spots and prioritize vulnerabilities that threaten physical safety and uptime. The legislation aims to enhance national critical infrastructure security by enforcing timely incident reporting and comprehensive asset management.

Join the discussion
ZDI-26-477: (Pwn2Own) Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation VulnerabilityCVE-2026-18284
0

This vulnerability allows local attackers to escalate privileges on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18284.

HighVulnerability#local
Join the discussion
ZDI-26-485: (Pwn2Own) Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation VulnerabilityCVE-2026-18268
0

This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-18268.

HighVulnerability#local
Join the discussion
ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation VulnerabilityCVE-2026-18270
0

This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18270.

HighVulnerability#local
Join the discussion
ZDI-26-490: (Pwn2Own) Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation VulnerabilityCVE-2026-18273
0

This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.6. The following CVEs are assigned: CVE-2026-18273.

MediumVulnerability#local
Join the discussion
ZDI-26-496: Trend AI Cleaner One Pro Link Following Arbitrary File Deletion VulnerabilityCVE-2026-62660
0

This vulnerability allows local attackers to delete arbitrary files on affected installations of TrendLife Cleaner One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.6. The following CVEs are assigned: CVE-2026-62660.

MediumVulnerability#local
Join the discussion
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands… (CVE-2026-44093)CVE-2026-44093
0

CVE-2026-44093 is a local privilege escalation vulnerability in the init-script for user-applications. It allows a low-privileged local user to execute arbitrary commands as root, potentially leading to full system compromise. The vulnerability is related to improper neutralization of special elements used in OS commands (CWE-78). No patch or remediation information is currently available, and there are no known exploits in the wild at this time.

Join the discussion

Showing 1 to 10 of 36 results

Filters:Tag: local
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses