Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Linux

20 articles

The Hacker News general Linux Docker Aug 7

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container a...

The Hacker News → Details

SANS ISC advisories Linux Aug 7

Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)

UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack o...

SANS ISC → Details

SC Media general Linux Aug 6

OVSwrap vulnerability allows local privilege escalation on Linux

As reported by Security Affairs, a 13-year-old Linux kernel flaw named OVSwrap was disclosed, enabling local users to gain root privileges on many default-co...

T1548 T1068

SC Media → Details

BleepingComputer general Linux Aug 6

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from ...

BleepingComputer → Details

The Hacker News general Linux Aug 6

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation an...

1 IOC

The Hacker News → Details

The Hacker News general Linux Intel AMD Aug 6

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, r...

The Hacker News → Details

GBHackers general Linux Aug 6

PoC Released for Linux Kernel STP Use-After-Free Vulnerability

A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridg...

GBHackers → Details

Security Affairs general Linux Aug 5

OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Mani...

T1548 T1068 T1598 1 IOC

Security Affairs → Details

GBHackers general Linux Aug 5

OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access

A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch ...

1 IOC

GBHackers → Details

The Hacker News general Linux Aug 5

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distribut...

1 IOC

The Hacker News → Details

SC Media general Linux Aug 3

Arch Linux temporarily disables AUR package adoption amid malicious takeover surge

The surge in malicious activity began around July 29, with initial reports identifying the "openconnect-sso" package as compromised.

SC Media → Details

GBHackers general Linux Aug 1

Arch Linux Suspends AUR Package Adoptions to Block Ongoing Malicious Commit Campaign

Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after detecting a wave of malicious activity targeting orphaned and u...

GBHackers → Details

BleepingComputer general Linux Jul 31

Arch Linux disables AUR package adoption to stop malware flood

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [.

BleepingComputer → Details

GBHackers general Linux Jul 31

Ransomware Killers Overwrite Security Process Memory Without Terminating Applications

Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply terminating...

GBHackers → Details

GBHackers general Linux Jul 31

Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion

Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively gradi...

T1592 1 IOC

GBHackers → Details

Security Affairs general Linux Jul 31

SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign

SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL doc...

Security Affairs → Details

GBHackers general Linux Jul 31

OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign

OctLurk and SilkLurk are highly customized, memory‑resident backdoors used in an ongoing cyberespionage campaign against government and critical‑sector netwo...

GBHackers → Details

SC Media general Linux Jul 30

The modern path to unified Linux identity security: Securing hybrid infrastructure in a cloud-first world

In the cloud-based enterprise, Linux servers can't stay isolated on legacy authentication systems.

SC Media → Details

Infosecurity Magazine general Linux Jul 30

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts

Infosecurity Magazine → Details

GBHackers general Linux Jul 30

Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access

A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain filele...

GBHackers → Details

«Previous page 1 ... 4 5 6 7 8 9 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA