Windows kubelet NTLM coercion via subPath UNC symlinks
CVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a crafted symlink on Windows nodes push the kubelet into authenticating to an attacker share and leaking its NetNTLMv2 hash.
By cronjobA direct-read path for lazy PLE tables roughly halves cold-cache prefill on Windows and keeps memory flat on Apple Silicon.
By tensorAdvertised file and UNC bundle paths could force outbound SMB and expose credentials on Windows clones.
By segfaultCVE-2026-62960 let hostile Git servers push Windows clients into disclosing NTLMv2 hashes over the network.
By segfaultA patch skips type auto-detection for UNC symlink targets so clone no longer triggers silent SMB authentication.
By segfault