Tag: linux
-
Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor
Meet ClingSTUN, a new Linux backdoor that exploits IoT vulnerabilities, gives attackers remote command access and turns infected devices into proxy nodes. First seen on hackread.com Jump to article: hackread.com/hackers-exploit-iot-vulnerabilities-clingstun-linux-backdoor/
-
New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/smtp-linux-backdoors-network-edge/
-
Vom Garagenprojekt zum Milliardengeschäft der Aufstieg von Open Source
Linux begann 1991 als unfertiger Kernel für wenige Rechner. Heute trägt Open Source Rechenzentren, Clouds, Behördenportale und KI-Plattformen. Der offene Code allein erklärt diesen Erfolg jedoch nicht. Entscheidend waren professionelle Betriebsmodelle, verlässlicher Support und die Erkenntnis, dass technologische Wahlfreiheit einen messbaren strategischen Wert besitzt. Für CIOs lautet die Kernfrage deshalb nicht mehr, ob Open Source……
-
Malicious Linux Implants Mimic Asian Mail Security Products
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it’s hard to tell they’re not. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security
-
TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning. The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler named jscrawl-amd64. All three components retrieve targets from a central HTTP hub, execute assigned collection tasks, and submit status reports and…
-
Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation
TeamViewer has issued security bulletin TV-2026-1010 to address five high-severity vulnerabilities found in the TeamViewer Full Client, Host, and related services. These vulnerabilities affect deployments on Windows, Linux, and macOS, and include issues such as remote code execution, session permission bypass, arbitrary privileged file writes, and local privilege escalation. Multiple TeamViewer Vulnerabilities CVE-2026-19743 Path […]…
-
TU Graz entdeckt Sicherheitsrisiken in File Notifications von Windows, Linux, Android und macOS
TU Graz zeigt Sicherheitsrisiken in File Notifications: Über Seitenkanäle lassen sich Nutzeraktivitäten beobachten und Passwortdialoge manipulieren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/tu-graz-entdeckt-sicherheitsrisiken-in-file-notifications-von-windows-linux-android-und-macos/a46587/
-
Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access
A high-severity Linux kernel vulnerability, tracked as CVE-2026-72018, lets a local attacker with CAP_NET_ADMIN privileges escalate to root. This exploitation involves an out-of-bounds write in the Shared Memory Communications Direct (SMC-D) DIBS loopback implementation. Researchers at XBOW discovered and demonstrated the flaw, creating a local privilege escalation proof of concept using a constrained 16-byte zero-write…
-
Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-is-rolling-out-linux-container-support-to-wsl/
-
Signal adds encypted local backup support to iOS, desktop apps
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/signal-adds-encypted-local-backup-support-to-ios-desktop-apps/
-
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
-
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A group of academics from VUSec and Scuola Superiore Sant’Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR).”The key insight is that, while…
-
Octopus Server Flaw Lets Authenticated Attackers Execute Arbitrary Code
Octopus Deploy has announced a high-severity vulnerability in Octopus Server that could allow authenticated users with project or environment editing permissions to execute arbitrary code within the Octopus Server process. Tracked as CVE-2026-101169, this issue stems from insecure JSON deserialization and affects multiple Octopus Server releases running on both Linux and Microsoft Windows. Organizations using…
-
File Notification Attacks Let Hackers Track Keystrokes and Website Visits on Linux, Windows and macOS
Researchers have disclosed a new class of cross-platform side-channel attacks that exploit file-notification mechanisms in Linux, Windows, macOS, and Android to infer sensitive user and system activities. These attacks can expose details such as keystroke timing, application launches, website visits, USB usage, VPN activity, printing, and other behaviors, even when the attacker lacks administrative privileges.…
-
Other users can watch your browsing and time your keystrokes through OS file notifications
Researchers at Graz University of Technology have used the file-notification systems in Windows, Linux, and macOS to spy on activity in other accounts. On Windows, a standard … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/cve-2025-68788-file-notification-attacks/
-
Updates erforderlich – CISA warnt vor aktiv ausgenutzten Linux-Kernel-Fehlern
First seen on security-insider.de Jump to article: www.security-insider.de/linux-kernel-drei-aktiv-ausgenutzte-sicherheitsluecken-a-401d4b555c96c2f28277663087f45b6a/
-
Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit
Tags: access, cve, cyber, data-breach, exploit, flaw, Internet, linux, remote-code-execution, threat, vulnerabilityA threat actor tracked as Red Heron has exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to steal source-code repositories, establish persistent access, and deploy a covert Linux toolset consisting of the JITTERLY implant and SIXZUT LD_PRELOAD rootkit. Acronis reported that the actor rapidly weaponized the flaw against internet-exposed Gitea environments, turning initial access…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
Der Aufstieg von Open Source – 35 Jahre Linux: Vom Garagenprojekt zum Milliardengeschäft
First seen on security-insider.de Jump to article: www.security-insider.de/35-jahre-linux-vom-garagenprojekt-zum-milliardengeschaeft-a-566fb3b1cc3b99bd3aa13e47c1e18233/
-
Der Aufstieg von Open Source – 35 Jahre Linux: Vom Garagenprojekt zum Milliardengeschäft
First seen on security-insider.de Jump to article: www.security-insider.de/35-jahre-linux-vom-garagenprojekt-zum-milliardengeschaeft-a-566fb3b1cc3b99bd3aa13e47c1e18233/
-
Sudo Vulnerability Lets Attackers Bypass Time-Based Authorization Controls
A recently disclosed high-severity vulnerability in Sudo could allow local, unprivileged Linux users to manipulate time-based authorization restrictions in sudoers policies. Tracked as CVE-2026-96512, this vulnerability arises from how Sudo handles the attacker-controlled TZ environment variable when evaluating NOTBEFORE and NOTAFTER constraints. Red Hat is monitoring this flaw under Bug 2539327, which is currently categorized…
-
Acronis untersucht internationale N-Day-Kampagne – Red Heron nutzt Gitea-Schwachstelle und versteckt sich mit Linux-Rootkit
First seen on security-insider.de Jump to article: www.security-insider.de/red-heron-gitea-cve-2026-60004-rootkit-a-8bb42f76f7eb155b74367327b6731fd9/
-
Critical Linux KVM Flaw Enables GuestHost Escape on ARM64 Systems
A critical vulnerability in the Linux Kernel-based Virtual Machine (KVM) for ARM64 systems could let attackers escape a virtual machine and gain read and write access to host kernel memory. This flaw, tracked as CVE-2026-89775, specifically affects ARM64 hosts with nested virtualization enabled and has been addressed in the mainline Linux kernel. Security researcher Hyunwoo…
-
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it…
-
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell commands, and transfer files through broker-mediated topics. Analysis of a statically linked x86-64 ELF sample shows that its configuration, task routing, and network payloads are obfuscated with separate XOR routines. The examined sample, SHA-256…
-
Umstellung auf Linux: Staatskanzlei Kiel fast vollständig weg von Windows
Die Umstellung auf Linux ist nur eine von vielen Maßnahmen Schleswig-Holsteins, um sich von proprietärer Software zu lösen. First seen on golem.de Jump to article: www.golem.de/news/umstellung-auf-linux-staatskanzlei-kiel-fast-vollstaendig-weg-von-windows-2609-213307.html
-
CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/
-
Behörde warnt: Linux-Systeme werden über Kernel-Lücken attackiert
Die Cisa warnt vor laufenden Angriffen auf Linux-Systeme über drei gefährliche Sicherheitslücken in Kernel-Komponenten. Korrekturen sind verfügbar. First seen on golem.de Jump to article: www.golem.de/news/behoerde-warnt-angriffe-auf-luecken-im-linux-kernel-beobachtet-2609-213261.html

