threat-intel Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems A long-standing Linux kernel vulnerability, dubbed Januscape (CVE-2026-53359), has been discovered that allows attackers to escape virtual machines and gain root access on the underlying host. This flaw, dormant for 16 y… SecurityWeek · Jul 7, 2026 Critical CVE-2026-53359linuxkernelvm
threat-intel 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor, dubbed ‘Januscape’ (CVE-2026-53359), allows guest virtual machines to corrupt the host kernel's shadow-page state. Researcher Hyunwoo Kim discovered t… The Hacker News · Jul 6, 2026 High CVE-2026-53359CVE-2026-43284CVE-2026-43500use-after-freeshadow pagenested virtualization
threat-intel Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability A proof-of-concept exploit for a Linux kernel vulnerability, dubbed ‘Bad Epoll,’ has been released, allowing unprivileged processes to gain root access on various devices. The vulnerability stems from a race condition wi… SecurityWeek · Jul 6, 2026 High CVE-2026-46242CVE-2026-43074linuxkernelvulnerability
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai
vulnerability ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access A critical vulnerability, dubbed ‘DirtyClone,’ has been identified in the Linux kernel, allowing local users to gain root access. This flaw, similar to previous ‘DirtyFrag’ and ‘Fragnesia’ vulnerabilities, stems from how… SecurityWeek · Jun 29, 2026 Critical CVE-2026-43503CVE-2026-43284CVE-2026-43500linuxkernelroot
threat-intel New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A vulnerability, dubbed "pedit COW," has been discovered in the Linux kernel's traffic-control subsystem, allowing unprivileged users to gain root access by poisoning cached binaries. The exploit, demonstrated with a wor… The Hacker News · Jun 26, 2026 Critical CVE-2026-46331USGBlinuxkernelexploit
vulnerability New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets A new vulnerability, CVE-2026-43503, has been discovered in the Linux kernel related to the DirtyClone variant of the DirtyFrag family. This flaw allows local users to gain root access by exploiting a cloned network pack… The Hacker News · Jun 26, 2026 High CVE-2026-43503CVE-2026-31431CVE-2026-43284linuxkernelprivilege escalation
threat-intel Linux Process Name Masquerading, (Wed, Jun 24th) This SANS Internet Storm Center diary details a technique used by attackers, specifically the Velvet Ant Chinese group, to mask process names in Linux systems. Attackers modify the ‘comm’ and ‘cmdline’ entries in the /pr… SANS Internet Storm Center · Jun 24, 2026 Medium CHprocess_namemasqueradinglinux
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor
vulnerability One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public A critical vulnerability, CVE-2026-23111, has been discovered in the Linux kernel’s nf_tables packet-filtering code, allowing unprivileged users to escalate to root access and break out of containers. The flaw, initially… The Hacker News · Jun 8, 2026 Critical CVE-2026-23111linuxkerneluse-after-free
threat-intel VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances A China-based cyber espionage group, VerdantBamboo, deployed a BSD variant of the BRICKSTORM backdoor and the PLENET malware family on Linux appliances to target a victim organization. The attack involved exploiting vuln… The Hacker News · Jun 8, 2026 High CVE-2026-22769CHlinuxbackdoorespionage
threat-intel Microsoft's Coreutils project brings Linux commands to Windows Microsoft has released Coreutils for Windows, a project bringing commonly used Linux command-line utilities to Windows as native applications. Based on the uutils open-source project, this aims to simplify development wo… BleepingComputer · Jun 2, 2026 Low linuxwindowscommand-line
vulnerability New CIFSwitch Linux flaw gives root on multiple distributions A newly discovered vulnerability, dubbed 'CIFSwitch,' in the Linux kernel allows attackers to escalate privileges to root by forging CIFS authentication key descriptions. The flaw, present since 2007, affects multiple Li… BleepingComputer · May 30, 2026 High CVE-2026-46243linuxkernelprivilege escalation
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage group, known as Calypso (Red Lamassu), has been targeting telecommunications providers globally since mid-2022 with a dual-pronged malware campaign utilizing Showboat (Linux) and JMFBackdoor (Wi… BleepingComputer · May 21, 2026 High CHMIASlinuxwindowsespionage
other Flipper One project needs community help to build open Linux platform This article reports on Flipper Devices’ ambitious project, Flipper One, an open Linux platform designed for networking and hardware experimentation, utilizing an ARM-based Rockchip RK3576 SoC. The project aims to provid… BleepingComputer · May 21, 2026 Low linuxarmopen source
vulnerability 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros A nine-year-old vulnerability in the Linux kernel, CVE-2026-46333, allows unprivileged users to execute commands as root, posing a significant risk to systems running affected distributions. The flaw stems from improper… The Hacker News · May 21, 2026 High CVE-2026-46333linuxkernelprivilege escalation