<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Cve on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/tags/cve/</link>
    <description>Recent content in Cve on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 09 Aug 2026 09:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.msbiro.net/tags/cve/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SCTPhantom (CVE-2026-64564): Threat-Modeling a High-Impact SCTP Kernel Flaw Without Panic</title>
      <link>https://www.msbiro.net/posts/sctphantom-cve-2026-64564-threat-modeling/</link>
      <pubDate>Sun, 09 Aug 2026 09:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/sctphantom-cve-2026-64564-threat-modeling/</guid>
      <description>CVE-2026-64564 (SCTPhantom) is a critical Linux kernel use-after-free in SCTP ASCONF with a high CVSS score and a demonstrated container escape. A DevSecOps threat-modeling walkthrough of when to care, who is actually at risk, and how to prioritize patching without panic, accounting for attacker-creatable SCTP associations.</description>
    </item>
    <item>
      <title>CVE-2026-31431 Copy Fail: A Nine-Year-Old Kernel Bug, a 732-Byte Script, and a Root Shell</title>
      <link>https://www.msbiro.net/posts/cve-2026-31431-copy-fail-linux-kernel-privilege-escalation/</link>
      <pubDate>Fri, 01 May 2026 09:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/cve-2026-31431-copy-fail-linux-kernel-privilege-escalation/</guid>
      <description>CVE-2026-31431 Copy Fail is a local privilege escalation in the Linux kernel exploitable with a 732-byte Python script. This post covers what it is, how to fix it, what to do when patching isn&amp;#39;t immediate, and why runtime detection is the control that actually matters.</description>
    </item>
    <item>
      <title>2025 CWE Top 25: Mitre&#39;s Critical Software Weakness Rankings and Trends</title>
      <link>https://www.msbiro.net/posts/top25mitre2025/</link>
      <pubDate>Wed, 17 Dec 2025 05:19:07 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/top25mitre2025/</guid>
      <description>Mitre&amp;#39;s 2025 CWE Top 25 reveals persistent threats like XSS and SQL Injection atop the list, with rising authorization flaws and memory bugs signaling DevSecOps priorities for cloud-native apps. Explore the top 10 changes from 2024, key trends, and how CWE root causes differ from CVEs.</description>
    </item>
    <item>
      <title>Urgent: Zero-Day CVEs Found in Two Major Secrets Managers — Have You Updated Yet?</title>
      <link>https://www.msbiro.net/posts/0day-cves-secrets-manager/</link>
      <pubDate>Mon, 11 Aug 2025 12:39:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/0day-cves-secrets-manager/</guid>
      <description>This article highlights recent zero-day vulnerabilities discovered in CyberArk and HashiCorp secrets managers, emphasizes the importance of timely software updates, and offers practical advice for staying proactive about security patches.</description>
    </item>
  </channel>
</rss>
