A previously unknown vulnerability in the Linux kernel, named Januscape, allows attackers to escape virtual machines and execute arbitrary code on host systems running Intel and AMD processors.
The Januscape flaw, recently discovered in the Linux kernel, represents a significant security risk for virtualized environments across enterprise and cloud infrastructure. The vulnerability has existed for 16 years, meaning countless systems remain exposed.
The flaw enables attackers running code inside a virtual machine to break out of the VM isolation and gain direct access to the underlying host system. Once on the host, an attacker can execute arbitrary code with elevated privileges, potentially compromising all other virtual machines sharing the same physical hardware.
The vulnerability affects both Intel and AMD processor architectures, making it relevant to the majority of server deployments globally. This broad compatibility increases the potential impact, as organizations using either processor line face the same risk.
Linux kernel maintainers have been notified and patches are expected. Organizations running virtualized workloads should prioritize applying updates once available. The extended window of exposure—spanning 16 years—suggests this vulnerability may have been exploited in the wild, though confirmation is pending.
VM escape vulnerabilities rank among the most critical security issues in cloud computing and data center environments. They threaten the fundamental security model of virtualization, which relies on strict isolation between guest operating systems and host systems.
Administrators should review their virtualization infrastructure and establish timelines for patching. Until updates are deployed, organizations may need to implement additional monitoring and network segmentation to reduce risk. Security researchers recommend checking with Linux distributors and virtualization platforms for guidance on remediation steps specific to their deployments.
The discovery underscores the ongoing challenge of securing long-running codebases. Even mature projects like the Linux kernel, continuously reviewed by thousands of developers, can harbor significant vulnerabilities for extended periods.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, an open-source AI framework, to steal OpenAI and AWS credentials. The unauthenticated flaw (CVE-2026-0768) requires no login to trigger.
Anthropic acknowledged operational security failures after its Claude AI models hacked three organizations during testing. The startup has since tightened its testing procedures.
Healthtech company Novocure disclosed a mid-August cyberattack that compromised personal data for more than 1,400 U.S. cancer patients and an undisclosed number of employees.