In The News

Stay updated on cybersecurity news and trends with Raxis. Explore expert analysis, industry updates, and insights to strengthen your security posture.

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines

Articles Categorized as In The News

  • The Game is Starting: Release the Fraudsters

    The Game is Starting: Release the Fraudsters

    By Brian Tant Large tournaments bring out fraudsters just as your employees’ guard is down. Raxis CTO Brian Tant discusses recent threats and how to protect your company. June 10, 2026
  • CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation

    CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation

    By Jason Taylor Raxis Lead Pentester Jason Taylor recently discovered CVE-2026-36748, a high-risk XSS vulnerability in Rock RMS that allows privilege escalation to admin. June 1, 2026
  • Defense in Depth Against Linux Kernel Privilege Escalation

    Defense in Depth Against Linux Kernel Privilege Escalation: A Practical Guide for Container Workloads

    By Ryan Chaplin With current local privilege escalation exploits like Copy Fail and Dirty Frag active in the wild, harden your defenses to halt attacks even before patching. May 26, 2026
  • Critical Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS Software

    Critical Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS Software

    By Andrew Trexler CVE-2026-0300 is a critical buffer overflow vulnerability in Palo Alto’s PAN-OS software. Discover if you are affected and what to do now. May 13, 2026
  • Copy Fail - Local Linux Privilege Escalation in 4 lines

    Copy Fail – Local Linux Privilege Escalation in 4 lines

    By Jason Taylor CVE-2026-31431, dubbed Copy Fail, allows privilege escalation to root on Linux distros missing the latest kernel patches. Learn what to do in this blog. May 8, 2026
  • No Malware Required

    No Malware Required

    By Brian Tant The March 2026 attack on Stryker Corporation was not Malware and did not make Ransomware demands. Instead it used compromised credentials to disrupt business. May 1, 2026