Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Linux

20 articles

BleepingComputer general Linux NEW 1h ago

Arch Linux disables AUR package adoption to stop malware flood

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [.

BleepingComputer → Details

GBHackers general Linux 11h ago

Ransomware Killers Overwrite Security Process Memory Without Terminating Applications

Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply terminating...

GBHackers → Details

GBHackers general Linux 15h ago

Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion

Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively gradi...

T1592 1 IOC

GBHackers → Details

Security Affairs general Linux 15h ago

SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign

SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL doc...

Security Affairs → Details

GBHackers general Linux 17h ago

OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign

OctLurk and SilkLurk are highly customized, memory‑resident backdoors used in an ongoing cyberespionage campaign against government and critical‑sector netwo...

GBHackers → Details

SC Media general Linux 1d ago

The modern path to unified Linux identity security: Securing hybrid infrastructure in a cloud-first world

In the cloud-based enterprise, Linux servers can't stay isolated on legacy authentication systems.

SC Media → Details

Infosecurity Magazine general Linux 1d ago

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts

Infosecurity Magazine → Details

GBHackers general Linux 1d ago

Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access

A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain filele...

GBHackers → Details

SC Media general Linux 2d ago

New Tengu botnet uses hardware watchdog for advanced persistence

A new Mirai-derived botnet, dubbed Tengu, was identified with advanced persistence and self-defense mechanisms, including the ability to use a compromised Li...

SC Media → Details

Help Net Security general Linux 2d ago

Tengu botnet reboots Linux devices to survive removal

A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opport...

T1110

Help Net Security → Details

The Hacker News general Linux 3d ago

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If t...

T1110

The Hacker News → Details

Infosecurity Magazine general Linux 3d ago

AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched

AI-assisted research uncovered Linux kernel use-after-free allowing root escalation

Infosecurity Magazine → Details

CISA Advisories advisories Linux 3d ago

Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.

CISA Advisories → Details

GBHackers general Linux 3d ago

AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation

A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to roo...

T1548 T1068 1 IOC

GBHackers → Details

The Hacker News general Linux Intel 3d ago

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE...

T1068 1 IOC

The Hacker News → Details

Help Net Security general Linux NVIDIA 4d ago

Tech giants form alliance to put open AI in cyber defenders’ hands

NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of i...

Help Net Security → Details

BleepingComputer general Linux Jul 23

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected f...

1 IOC

BleepingComputer → Details

SC Media general Linux Jul 22

Linux kernel security faces challenge with surge in CVEs

The sheer number of Linux kernel CVEs, published recently, has raised questions about effective vulnerability management.

SC Media → Details

SC Media general Linux Jul 22

Ubuntu snap-confine vulnerability grants root access

The vulnerability stems from a security hardening change made in July 2025, where snap-confine shifted to a set-capabilities model.

SC Media → Details

The Hacker News general Linux Jul 22

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigge...

T1548 T1068 1 IOC

The Hacker News → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA