Securityweek $1 Million Sandbox Challenge Reveals Linux Kernel Vulnerabilities
Article Content
- •Vercel's bug-bounty program yielded 1,285 reports, including critical Linux kernel flaws.
- •Two major defects were found, one leaking memory and another causing host crashes.
- •The program highlighted the increasing role of AI in cybersecurity research and reporting.
Vercel's two-week bug-bounty program identified 1,285 reports, revealing critical flaws in the Linux kernel's networking stack. The program, which ran from August 18 to September 1, offered a $1 million reward and involved both black box and white box testing. Among the findings, one critical defect leaks memory from the host kernel, while another causes deterministic crashes. No reports indicated access to customer data, but the findings will help improve Vercel's product. The vulnerabilities have significant implications for major cloud providers that rely on the same Linux kernel layer for workload isolation. Vercel plans to publish details once fixes are under review and CVEs are assigned. The report triage process utilized AI assistance to manage the high volume of submissions, demonstrating the evolving role of AI in cybersecurity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Vercel and CVE-2026-53362 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw affects numerous applications…
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic…