Skip to main content

Tag: linux

107 articles

Developer workstation with laptop, coding materials, and papers scattered on a desk in a bright, modern office space.

Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

Analyst 207
Empty computer workstation on a neutral-colored desk in a generic office setting with a laptop and peripherals.

CISA Flags Six Exploited Flaws in Microsoft, Linux, Citrix Products

The US Cybersecurity and Infrastructure Security Agency (CISA) has just sounded the alarm, adding six new vulnerabilities to its Known Exploited Vulnerabilities catalog in a single day - a stark reminder that threat actors are relentlessly targeting both old and newly discovered software weaknesses. This urgent move underscores the need for immediate action to patch these flaws and prevent exploitation.

Analyst 207
Laptop on a minimalist desk surrounded by technical instruments and papers in a bright room.

Researcher Exploits Apple's Find My to Track Locations with Linux

Meet Zerotistic, a 22-year-old security researcher who just pulled off a clever hack: enrolling a Linux device into Apple's Find My network and receiving live location data, typically reserved for Apple devices. This ingenious feat reveals some surprising technical constraints in Apple's system.

Analyst 207
Cluttered network closet with tangled cables and a single computer on a shelf.

Mirai-Based Botnet Evooo1Bot Exploits Vulnerabilities, Turns Devices Into Proxies

Meet Evooo1Bot, a newly identified Mirai-derived Linux botnet that's turning devices into proxies by exploiting vulnerabilities, and has been actively targeting internet-facing devices since July 2026. Its operators have been using a single loader URL to launch attacks, allowing researchers to track and identify the malware.

Analyst 207
Technicians walk by rows of server racks and networking equipment in a modern network operations center.

Kimwolf Botnet Evolves with Enhanced DDoS Capabilities

Meet Kimwolf v7, a highly evolved botnet that's taken DDoS capabilities to the next level with its cutting-edge command-and-control resolution via Ethereum's blockchain naming system, ENS. First discovered in February 2026, this malware has been quietly building its arsenal since August 2024, targeting a range of devices from Linux IoT gadgets to Android TV boxes.

Analyst 207
Secure computer terminal with blurred laptop screen and faint coding interface.

Mozilla Revokes Firefox GPG Key After Accidental Exposure

Mozilla swiftly responded to a security slip-up by revoking a Firefox GPG key after it was accidentally exposed in a private GitHub repository, and has since transitioned to a new key to ensure the integrity of its software. The move aims to prevent potential misuse and protect users, with measures also put in place to avoid similar incidents in the future.

Analyst 207
Close-up of a computer processor on a lab bench surrounded by testing equipment.

Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel, AMD CPUs

Researchers have uncovered a shocking vulnerability that allows an unprivileged local program to bypass Spectre v2 defenses on Intel and AMD CPUs, leaking kernel memory with alarming speed and accuracy. On an AMD Zen 2 system, this exploit can siphon off sensitive data at a rate of 5.47 bytes per second with near 92% accuracy, making it possible to crack even highly secured files like /etc/shadow.

Analyst 207
Cluttered home office workspace with a Linux workstation and laptop in focus.

Arch Linux Disables AUR Package Adoption Amid Malware Surge

To protect its users, Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) due to a surge in malware takeovers. The move is a temporary measure to handle the situation, with the team promising to reinstate the feature once it's safe to do so.

Analyst 207
Close-up of laptop motherboard with firmware chip in focus on laboratory bench.

Microsoft Secure Boot Vulnerability Exposed After 13 Years

A shocking security vulnerability in Microsoft's Secure Boot, a safeguard designed to protect Windows and Linux devices from firmware infections, has been easily exploitable for 13 of its 14 years of existence. Researchers uncovered 11 defective firmware images, some dating back to 2013, that were still publicly available and signed by Microsoft, making it alarmingly simple to bypass the security measure.

Analyst 207
A network router sits on a clean surface with a blurred background, conveying vulnerability.

OpenWrt Fixes Critical DHCPv6 Flaw That Exposes Root Code Execution Risk

OpenWrt has patched a critical DHCPv6 flaw, known as CVE-2026-53921, that could allow an unauthenticated attacker to execute root code by sending a crafted request to the DHCPv6 server. This severe vulnerability, rated 9.8 out of 10, highlights the importance of updating your OpenWrt setup to prevent potential security breaches.

Analyst 207
System administrator examines code on laptop screen in data center.

Linux Flaw RefluXFS Exposes Systems to Root Privilege Attacks

A nine-year-old Linux kernel vulnerability, dubbed RefluXFS, has been discovered in the XFS filesystem, allowing local attackers to gain root privileges and wreak havoc on systems - patching is urgently recommended to prevent exploitation. Immediate action can neutralize this threat and safeguard your systems from potential attacks.

Analyst 207
Ubuntu desktop computer setup with monitor and keyboard in daylight.

Ubuntu Flaw Exposes Local Users to Root Access on Default Desktop Installs

A newly discovered security flaw, CVE-2026-8933, can give local users full root control of Ubuntu Desktop installs, posing a significant threat to default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. This high-severity vulnerability highlights the importance of staying vigilant about system security.

Analyst 207
A typical office workspace with a Linux workstation, monitor, and keyboard on a desk, surrounded by documents, conveying a…

Ubuntu Vulnerability Exposes Local Users to Root Access Risk

A newly discovered vulnerability, CVE-2026-8933, puts users of Ubuntu Desktop 24.04, 25.10, and 26.04 at risk of full root access, allowing any local user to gain unrestricted control on default installs. This high-severity flaw can be easily exploited by a local, unprivileged user, making immediate attention crucial.

Analyst 207
Motherboard components and UEFI firmware chip in a well-lit lab setting.

Microsoft-Signed Linux UEFI Shims Expose Secure Boot Bypass Risk

A newly discovered vulnerability in 11 Microsoft-signed Linux UEFI shims could allow hackers to bypass Secure Boot and deploy malicious code during system startup, putting your device at risk of infection with UEFI bootkits or other malware. This security flaw enables attackers to execute untrusted code during boot, making it a critical threat to your system's security.

Analyst 207
Cybersecurity researcher working at cluttered desk with laptop and Linux devices nearby.

Malware Delivered via Trojanized GitHub Exploits Targets Security Researchers

Security researchers have been targeted by a sneaky malware campaign that uses trojanized GitHub exploits to deliver a Python-based remote access trojan, hiding in plain sight within popular proof-of-concept code repositories. The malware, downloaded over 2,400 times mostly on Linux-based systems, was spread through malicious packages cleverly concealed in dependency lists on GitHub.

Analyst 207
Cluttered home office desk with Linux workstation, notes, and technical books.

Arch Linux Cracks Down on Malicious Commits in User Repository

Malicious hackers have launched a massive assault on the Arch User Repository, compromising over 1,500 user-submitted packages and forcing the Arch Linux team to temporarily halt new account signups to contain the damage. The attack has been mitigated, but not before highlighting the vulnerability of community-run package repositories.

Analyst 207
Dimly lit computer terminal in a quiet workspace with blurred background elements.

Arch Linux AUR Packages Targeted in Credential Stealer Campaign

Malicious actors have hijacked over 400 Arch Linux AUR packages, quietly altering their build scripts to deploy a sneaky Rust credential stealer in a campaign dubbed Atomic Arch. By targeting abandoned packages and preserving their original names and histories, the attackers cleverly evaded detection.

Analyst 207
Linux workstation in a modern office setting with natural lighting.

Linux Flaw Enables Rapid Local Root Access Escalation

A single-character logic error in Linux's nf_tables code, known as CVE-2026-23111, can quickly turn an unprivileged local account into a powerful root account, allowing for container escape - and publicly available exploit code makes it a pressing concern. This vulnerability has already been patched, but its public exposure puts Linux users at risk.

Analyst 207
Server equipment sits on a rack in a data center with cables and networking gear surrounding it.

VerdantBamboo Targets Linux Systems with Customized Malware Arsenal

Meet VerdantBamboo, a stealthy threat actor that infiltrated Linux and BSD systems, hiding in plain sight for 18 months by cleverly evading detection and morphing its malware arsenal to blend in. Its sophisticated attacks went undetected until Volexity's incident response team uncovered the intrusion, revealing a complex trail that led from Egnyte appliances into Microsoft 365 environments.

Analyst 207
Developer workspace with Windows laptop, notes, and coding materials, displaying a command-line interface with mixed…

Microsoft Brings Linux Commands to Windows with Coreutils Release

Microsoft just made life easier for developers who juggle Windows and Linux, releasing Coreutils for Windows, a package that brings commonly used Linux commands to Windows as native apps. This game-changing move eliminates frustrating workarounds and context switching, letting devs focus on what matters most - coding.

Analyst 207
Laptop and development tools sit on a cluttered workspace surrounded by generic technology equipment.

GitHub-Hosted Malware Targets PHP Packages in Coordinated Supply Chain Attack

Malicious code was injected into eight PHP packages on Packagist, triggering a Linux binary download from GitHub Releases via JavaScript lifecycle hooks in package.json postinstall scripts. The attack was swiftly contained, with the malicious versions removed from Packagist.

Analyst 207
Modern computer lab setting with a laptop and peripherals.

Linux Kernel Faces New Exploit for DirtyDecrypt Vulnerability

A new exploit has been discovered for the DirtyDecrypt vulnerability in the Linux Kernel, allowing for a potentially devastating rxgk pagecache write due to a missing copy-on-write guard. This flaw, tracked as CVE-2026-31635, has a CVSS score of 7.5 and was recently patched after being reported by security researchers.

Analyst 207
A Linux system terminal in a neutral setting with ambient lighting.

Linux Flaw Exposes Root Files to Unprivileged Users

A critical flaw in the Linux kernel has been discovered, allowing unprivileged users to access files that should be restricted to root accounts, putting system security at risk. This bug puts a spotlight on the importance of kernel access controls for system operators and users who rely on them.

Analyst 207
Dimly lit server room with equipment and one glowing server screen.

DirtyDecrypt Flaw Exposes Linux Systems to Root Access Risk

A newly patched Linux kernel flaw, dubbed DirtyDecrypt, has been exposed through a public proof-of-concept exploit that can grant root access to vulnerable systems. This critical vulnerability was recently patched, but a public exploit is now available, putting Linux systems at risk.

Analyst 207