Tag: linux
-
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company’s own private code repositories.That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not…
-
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey was unintentionally committed to a private GitHub repository. The affected signing infrastructure includes selected release files, such as Linux tarballs, RPM packages, and checksum files. Mozilla’s investigation into available audit logs…
-
HP ThinPro TPM Flaw Lets Attackers Bypass Full Disk Encryption and Steal LUKS Keys
A security researcher has revealed a critical design flaw in HP ThinPro versions 8 and 9, which allows attackers with physical access to a thin client’s storage drive to extract TPM-sealed LUKS disk-encryption keys. This vulnerability arises from an incomplete measured-boot policy that validates the GRUB bootloader but fails to measure the Linux kernel and…
-
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address Reconfiguration implementation. Researchers at Tencent Zhuque Lab’s Corvus AI project reported that a local attacker could leverage the flaw to escalate privileges to root and, in certain configurations, to escape from containers to the host.…
-
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.”These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,”…
-
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone…
-
OVSwrap vulnerability allows local privilege escalation on Linux
First seen on scworld.com Jump to article: www.scworld.com/brief/ovswrap-vulnerability-allows-local-privilege-escalation-on-linux
-
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
-
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which…
-
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14…
-
PoC Released for Linux Kernel STP UseFree Vulnerability
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridge`. This vulnerability occurs within the Spanning Tree Protocol (STP) timer lifecycle. It can result in timer structures referencing freed bridge memory, potentially allowing for control-flow hijacking. The SSD Secure Disclosure technical team disclosed the issue…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of…
-
OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch (OVS) implementation. This vulnerability could allow unprivileged local users to gain root-level access on affected systems. Researcher Asim Viladi Oglu Manizada reported this issue on July 28 after coordinating with the Linux kernel security team…
-
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by…
-
RefluXFS – Nächste Linux-Lücke ermöglicht Root-Rechte
Tags: linuxFirst seen on security-insider.de Jump to article: www.security-insider.de/refluxfs-linux-xfs-root-exploit-cve-2026-64600-a-4513b1e303825187a5108d461f7a1714/
-
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively grading host hardware for cryptomining suitability, then exiting without dropping a single binary. Cowrie, which exposes a realistic fake Linux shell and records full command transcripts, logged a connection from 91.92.40.13 that…
-
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/
-
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.Tengu supports 25 distributed denial-of-service (…
-
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/
-
Debian-basiertes Pentesting – Was ist Kali Linux?
First seen on security-insider.de Jump to article: www.security-insider.de/was-ist-kali-linux-a-19bc6ecebeee60cb707eba4a3e8acf7c/
-
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in the Linux packet scheduling subsystem (net/sched) and arises from a use-after-free condition involving traffic-control action objects. AI-Discovered Linux Kernel Zero-Day Star Labs researcher developed a reliable exploit…
-
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel’s network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and…
-
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Tags: ai, cisco, cloud, crowdstrike, framework, group, ibm, intelligence, linux, microsoft, network, nvidia, open-source, software, toolNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux…
-
NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security
Tags: ai, crowdstrike, cyber, cybersecurity, linux, microsoft, nvidia, open-source, technology, toolNVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open…
-
Microsoft, tech companies throw weight behind spread of open-source AI
Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. First seen on cyberscoop.com Jump to article: cyberscoop.com/tech-leaders-open-source-ai-cybersecurity/

