Tag: linux
-
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
-
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which…
-
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14…
-
PoC Released for Linux Kernel STP UseFree Vulnerability
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridge`. This vulnerability occurs within the Spanning Tree Protocol (STP) timer lifecycle. It can result in timer structures referencing freed bridge memory, potentially allowing for control-flow hijacking. The SSD Secure Disclosure technical team disclosed the issue…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of…
-
OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch (OVS) implementation. This vulnerability could allow unprivileged local users to gain root-level access on affected systems. Researcher Asim Viladi Oglu Manizada reported this issue on July 28 after coordinating with the Linux kernel security team…
-
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by…
-
RefluXFS – Nächste Linux-Lücke ermöglicht Root-Rechte
Tags: linuxFirst seen on security-insider.de Jump to article: www.security-insider.de/refluxfs-linux-xfs-root-exploit-cve-2026-64600-a-4513b1e303825187a5108d461f7a1714/
-
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively grading host hardware for cryptomining suitability, then exiting without dropping a single binary. Cowrie, which exposes a realistic fake Linux shell and records full command transcripts, logged a connection from 91.92.40.13 that…
-
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/
-
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.Tengu supports 25 distributed denial-of-service (…
-
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/
-
Debian-basiertes Pentesting – Was ist Kali Linux?
First seen on security-insider.de Jump to article: www.security-insider.de/was-ist-kali-linux-a-19bc6ecebeee60cb707eba4a3e8acf7c/
-
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in the Linux packet scheduling subsystem (net/sched) and arises from a use-after-free condition involving traffic-control action objects. AI-Discovered Linux Kernel Zero-Day Star Labs researcher developed a reliable exploit…
-
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel’s network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and…
-
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Tags: ai, cisco, cloud, crowdstrike, framework, group, ibm, intelligence, linux, microsoft, network, nvidia, open-source, software, toolNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux…
-
NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security
Tags: ai, crowdstrike, cyber, cybersecurity, linux, microsoft, nvidia, open-source, technology, toolNVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open…
-
Microsoft, tech companies throw weight behind spread of open-source AI
Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. First seen on cyberscoop.com Jump to article: cyberscoop.com/tech-leaders-open-source-ai-cybersecurity/
-
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet.XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing’s image tier, not on one bad machine.…
-
RefluXFS: Kernel-Bug verleiht auf Millionen von Linux-Systemen Root-Zugriff
Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. First seen on golem.de Jump to article: www.golem.de/news/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux-2607-211245.html
-
RefluXFS: Gefährlicher Kernel-Bug verleiht Root-Zugriff unter Linux
Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. First seen on golem.de Jump to article: www.golem.de/news/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux-2607-211245.html
-
RefluXFS: Kritische Linux-Kernel-Lücke verschafft lokalen Nutzern Root-Rechte
Tags: linuxAdministratoren sollten deshalb zeitnah einen korrigierten Kernel der jeweiligen Linux-Distribution installieren und das System anschließend vollständig neu starten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/refluxfs-kritische-linux-kernel-luecke-verschafft-lokalen-nutzern-root-rechte/a45862/
-
Unprivilegierte lokale Nutzer erlangen Root-Rechte durch Linux-Kernel-Schwachstelle ‘RefluXFS”
Da in Unternehmen, Behörden und KRITIS-Umgebungen im DACH-Raum Linux und davon abgeleitete Distributionen in großem Umfang im Einsatz haben vielfach in Standardkonfiguration mit XFS-Dateisystem , betrifft die Linux-Kernel-Schwachstelle ‘RefluXFS” (CVE-2026-64600) einen erheblichen Teil der hiesigen Linux-Serverlandschaft unmittelbar. Qualys Threat Research Unit (TRU) veröffentlicht Details Patchen und Neustart sind die einzigen verlässliche Gegenmaßnahmen. […] First seen…
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of…
-
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/

