<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Linux Security</title><description>Cybersecurity articles tagged #Linux Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2024-6387: OpenSSH regreSSHion RCE — Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2024-6387-openssh-regresshion-rce-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-6387-openssh-regresshion-rce-mitigation-guide</guid><description>Critical analysis of CVE-2024-6387 (regreSSHion) in OpenSSH. Learn technical details of the signal handler race condition and how to defend Linux systems.</description><pubDate>Wed, 24 Jun 2026 09:23:43 GMT</pubDate><category>CVE-2024-6387</category><category>OpenSSH</category><category>regreSSHion</category><category>Linux Security</category><category>RCE</category></item><item><title>Linux Process Name Masquerading: Analyzing T1036 Obfuscation</title><link>https://runtimerebel.com/blog/linux-process-name-masquerading-analyzing-t1036-obfuscation</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-process-name-masquerading-analyzing-t1036-obfuscation</guid><description>Explore the technical methods behind Linux process name masquerading (MITRE ATT&amp;CK T1036) used by actors like Velvet Ant to evade detection.</description><pubDate>Wed, 24 Jun 2026 09:23:19 GMT</pubDate><category>T1036</category><category>Linux Security</category><category>Velvet Ant</category><category>Process Masquerading</category><category>Obfuscation</category></item><item><title>Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap</title><link>https://runtimerebel.com/blog/linux-vulnerabilities-and-defender-zero-days-weekly-threat-recap</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-vulnerabilities-and-defender-zero-days-weekly-threat-recap</guid><description>Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.</description><pubDate>Mon, 25 May 2026 16:48:57 GMT</pubDate><category>Linux Security</category><category>Microsoft Defender</category><category>Supply Chain Security</category><category>Botnets</category></item><item><title>Flipper One: The Evolution of Linux-Based Hardware Pentesting Tools</title><link>https://runtimerebel.com/blog/flipper-one-the-evolution-of-linux-based-hardware-pentesting-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/flipper-one-the-evolution-of-linux-based-hardware-pentesting-tools</guid><description>Flipper Devices announces the Flipper One, an open Linux platform. Analyze the security implications and defensive requirements for this modular hacking tool.</description><pubDate>Thu, 21 May 2026 13:20:04 GMT</pubDate><category>Flipper One</category><category>Hardware Hacking</category><category>Penetration Testing</category><category>Physical Security</category><category>Linux Security</category></item><item><title>CVE-2026-31431: CISA Warns of Linux Local Privilege Escalation Exploit</title><link>https://runtimerebel.com/blog/cve-2026-31431-cisa-warns-of-linux-local-privilege-escalation-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-31431-cisa-warns-of-linux-local-privilege-escalation-exploit</guid><description>CISA adds CVE-2026-31431 to its KEV catalog following active exploitation of a Linux local privilege escalation flaw. Learn how to mitigate root access risks.</description><pubDate>Sun, 03 May 2026 08:40:00 GMT</pubDate><category>CVE-2026-31431</category><category>Linux Security</category><category>CISA KEV</category><category>Privilege Escalation</category></item><item><title>Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers</title><link>https://runtimerebel.com/blog/cookie-controlled-php-web-shells-evade-detection-on-linux-servers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cookie-controlled-php-web-shells-evade-detection-on-linux-servers</guid><description>Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.</description><pubDate>Sat, 04 Apr 2026 00:36:49 GMT</pubDate><category>Php Web Shell</category><category>Linux Security</category><category>Microsoft Defender</category><category>Persistence Mechanisms</category><category>Cron Job Exploitation</category></item><item><title>GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact</title><link>https://runtimerebel.com/blog/gsocket-backdoor-analysis-malicious-bash-script-delivery-and-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/gsocket-backdoor-analysis-malicious-bash-script-delivery-and-impact</guid><description>Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.</description><pubDate>Fri, 20 Mar 2026 12:19:53 GMT</pubDate><category>Gsocket</category><category>Bash Malware</category><category>Persistence</category><category>Linux Security</category><category>Nat Traversal</category></item><item><title>Ubuntu CVE-2026-3888: Privilege Escalation via systemd Timing Flaw</title><link>https://runtimerebel.com/blog/ubuntu-cve-2026-3888-privilege-escalation-via-systemd-timing-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/ubuntu-cve-2026-3888-privilege-escalation-via-systemd-timing-flaw</guid><description>A high-severity flaw in Ubuntu 24.04+ allows local attackers to gain root access via a systemd cleanup timing exploit tracked as CVE-2026-3888.</description><pubDate>Wed, 18 Mar 2026 12:24:05 GMT</pubDate><category>Ubuntu</category><category>Systemd</category><category>CVE-2026-3888</category><category>Privilege Escalation</category><category>Linux Security</category></item></channel></rss>