Linux
20 articles
Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning
A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct ...
Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection
Security researcher has disclosed a technique used by the Singularity Linux rootkit to evade Elastic Defend by suppressing module-load telemetry to avoid det...
Linux Detection Engineering - Fileless Execution
We reproduced five Linux fileless execution patterns with FENIX, including memfd_create staging, interpreter one-liners, deleted binaries, and in-memory kern...
AI agent repeatedly escapes virtual machine in security test
During a test conducted by Trail of Bits researcher Artem Dinaburg, a preview version of GPT 5.6-Cyber was tasked with breaking out of a Debian 12 virtual ma...
Debian developers rejected an LLM ban and left disclosure voluntary
A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through Au...
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exp...
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-49105 ownCl...
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities.
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student ...
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into propose...
RedC2 Turns Compromised Linux Machines Into SOCKS5 Proxies for Internal Network Pivoting
A cluster of trojanized npm packages is delivering the RedC2 4.0 Linux implant, providing operators with a pathway from a seemingly harmless dependency impor...
ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to exec...
ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to exec...
Your Shredded Visa Card May Still Work at the Checkout
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel.
New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments
Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC pa...
Exclusive: Linux Foundation's Akrites to Go Live in September
The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source...
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
Linuxfabrik monitoring_plugins_6.0.
UNISOC Modem Flaw Enables Remote Code Execution via Video Calls
UNISOC modem flaw enabled kernel-level code execution through video calls