AI Tool Uncovers 15-Year-Old Linux Root Bug That Affects Millions of Machines

A security firm has discovered a critical Linux kernel vulnerability that went undetected for 15 years, allowing any logged-in user to gain full root access on an unpatched machine. Nebula Security published exploit code for the flaw, tracked as CVE-2026-43499 and named GhostLock, in July 2026.

The bug is a use-after-free vulnerability that has shipped by default in essentially every mainstream Linux distribution since 2011. It requires no special permissions or network access to exploit, and Nebula’s proof-of-concept code can also escape containers. In testing, the exploit was 97 percent reliable. Google’s kernelCTF program awarded Nebula $92,337 for the find.

Nebula discovered the flaw using VEGA, its AI-driven bug-hunting tool, as part of a broader 2026 effort in which automated tools have been combing old kernel code that few researchers had revisited in years. The vulnerability was patched in April, but patch availability remains uneven. As of early July, Ubuntu still listed versions 24.04, 22.04, and 20.04 LTS as vulnerable or in progress, meaning administrators should verify that a fixed package is actually installed rather than assume one has been applied.

In other security news this week, consulting firm Accenture confirmed a breach after a threat actor known as “888” claimed to have stolen 35 GB of data — including source code, RSA and SSH keys, Azure access tokens, and configuration files — and listed it for sale on a cybercrime forum. Accenture described it as an “isolated matter” and said it had remediated the source, but declined to detail what was taken or how attackers gained access. The breach is notable given that Accenture’s federal arm has held a roughly $56.5 million contract to provide 24/7 cyber defense and intrusion detection services for ICE since September 2021.

Also this week, a reporter for The Drive was surrounded by four armed police officers in a Plymouth, Minnesota, parking lot after Flock license plate cameras flagged his loaner Range Rover as stolen. The alert traced back to a data-entry typo made 2,000 miles away in Los Angeles, where a fleet plate had been entered into the system with two digits missing. Four other Land Rovers sharing the same plate format were being tracked in Minnesota that same week.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top