GhostLock is a tool tracked across 3 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed May 11, 2026; most recent activity July 13, 2026.
A severe Linux kernel vulnerability, CVE-2026-43499, known as GhostLock, has been publicly disclosed by Nebula Security's VEGA team. This flaw, present since 2011, allows any logged-in user to gain full root control of…
The GhostLock attack, disclosed on May 11, 2026, exploits a flaw in the Windows CreateFileW API, allowing attackers to lock SMB files without writing encrypted data to disk. This fundamentally challenges the traditional…
Nebula Security has disclosed a full-chain exploit named 'IonStack' that allows attackers to gain root access on Android 17 devices through a single click on a malicious URL. This exploit chains two zero-day…