<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Linux</title><description>Cybersecurity articles tagged #Linux on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Evooo1Bot Linux Botnet: Beyond DDoS with Exploits &amp; Credential Theft</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</guid><description>Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.</description><pubDate>Mon, 17 Aug 2026 16:18:57 GMT</pubDate><category>Linux</category><category>Botnet</category><category>DDoS</category><category>Credential Theft</category><category>Evooo1Bot</category></item><item><title>TONTOU CPU Attack Bypasses Spectre v2 Mitigations on Linux</title><link>https://runtimerebel.com/blog/tontou-cpu-attack-bypasses-spectre-v2-mitigations-on-linux</link><guid isPermaLink="true">https://runtimerebel.com/blog/tontou-cpu-attack-bypasses-spectre-v2-mitigations-on-linux</guid><description>New TONTOU CPU attack bypasses Spectre v2 fixes on Intel and AMD, enabling unprivileged attackers to leak Linux kernel password hashes.</description><pubDate>Mon, 10 Aug 2026 09:08:38 GMT</pubDate><category>Linux</category><category>TONTOU</category><category>Spectre V2</category><category>CPU Attack</category><category>Side Channel</category></item><item><title>NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS</title><link>https://runtimerebel.com/blog/natjack-attacks-exploiting-nat-trust-in-windows-linux-macos</link><guid isPermaLink="true">https://runtimerebel.com/blog/natjack-attacks-exploiting-nat-trust-in-windows-linux-macos</guid><description>Synack&apos;s research reveals NatJack attacks, a new class of NAT exploitation affecting Windows, Linux, and macOS, leveraging trust assumptions.</description><pubDate>Sun, 09 Aug 2026 00:58:42 GMT</pubDate><category>Windows</category><category>Linux</category><category>macOS</category><category>NatJack</category><category>NAT</category></item><item><title>CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape</title><link>https://runtimerebel.com/blog/cve-2026-64561-zapscape-kvm-flaw-allows-guest-vm-escape</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64561-zapscape-kvm-flaw-allows-guest-vm-escape</guid><description>Analyze CVE-2026-64561, a KVM shadow MMU vulnerability dubbed Zapscape allowing L1 guest VM escape to Linux hosts. Learn mitigation steps.</description><pubDate>Fri, 07 Aug 2026 02:08:24 GMT</pubDate><category>CVE-2026-64561</category><category>Linux</category><category>Kernel</category><category>Virtualization</category><category>Vulnerability</category></item><item><title>SSH Botnet Reconnaissance Before Linux Cryptominer Deployment</title><link>https://runtimerebel.com/blog/ssh-botnet-reconnaissance-before-linux-cryptominer-deployment</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssh-botnet-reconnaissance-before-linux-cryptominer-deployment</guid><description>An SSH botnet performs extensive hardware and system reconnaissance on Linux targets before deploying an optimized cryptocurrency miner. Weak credentials exploited.</description><pubDate>Thu, 30 Jul 2026 02:32:56 GMT</pubDate><category>SSH Botnet</category><category>Cryptomining</category><category>Linux</category><category>XMRig</category><category>Pnscan</category><category>Brute Force</category></item><item><title>UEFI Shim Bootloader Vulnerabilities: Secure Boot Blind Spot</title><link>https://runtimerebel.com/blog/uefi-shim-bootloader-vulnerabilities-secure-boot-blind-spot</link><guid isPermaLink="true">https://runtimerebel.com/blog/uefi-shim-bootloader-vulnerabilities-secure-boot-blind-spot</guid><description>Nearly a dozen vulnerable UEFI shim bootloaders remained trusted for years, allowing attackers to bypass Secure Boot for persistent malware and rootkit deployment.</description><pubDate>Thu, 16 Jul 2026 02:43:41 GMT</pubDate><category>UEFI</category><category>Secure Boot</category><category>Bootloader</category><category>Supply Chain Attack</category><category>Rootkit</category><category>Linux</category></item><item><title>Linux Process-Specific HTTP Proxying: Tools and Analysis Gaps</title><link>https://runtimerebel.com/blog/linux-process-specific-http-proxying-tools-and-analysis-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-process-specific-http-proxying-tools-and-analysis-gaps</guid><description>Explores the utility of process-specific HTTP proxying for Linux debugging and reverse engineering, highlighting the absence of a generic solution akin to Proxifier.</description><pubDate>Thu, 21 May 2026 20:44:33 GMT</pubDate><category>Linux</category><category>HTTP Proxy</category><category>Reverse Engineering</category><category>Debugging</category><category>Security Tools</category></item><item><title>Linux Kernel Dirty Frag: CVE-2024-26610 LPE Vulnerability Analysis</title><link>https://runtimerebel.com/blog/linux-kernel-dirty-frag-cve-2024-26610-lpe-vulnerability-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-kernel-dirty-frag-cve-2024-26610-lpe-vulnerability-analysis</guid><description>Technical analysis of the Dirty Frag Linux kernel vulnerability (CVE-2024-26610), exploring its impact on IPv4 fragmentation and mitigation strategies.</description><pubDate>Fri, 08 May 2026 08:40:45 GMT</pubDate><category>Linux</category><category>Dirty Frag</category><category>CVE-2024-26610</category><category>Privilege Escalation</category><category>LPE</category><category>Kernel Security</category></item><item><title>Dirty Frag: Linux Kernel Zero-Day Enables Local Privilege Escalation</title><link>https://runtimerebel.com/blog/dirty-frag-linux-kernel-zero-day-enables-local-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/dirty-frag-linux-kernel-zero-day-enables-local-privilege-escalation</guid><description>The Dirty Frag zero-day vulnerability allows local attackers to gain root access on major Linux distributions via an exploit in kernel fragmentation handling.</description><pubDate>Fri, 08 May 2026 08:38:16 GMT</pubDate><category>Linux</category><category>Kernel</category><category>Dirty Frag</category><category>Privilege Escalation</category><category>Zero-Day</category></item><item><title>AI-Assisted Scan Uncovers 9-Year-Old Linux Vulnerability</title><link>https://runtimerebel.com/blog/ai-assisted-scan-uncovers-9-year-old-linux-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-scan-uncovers-9-year-old-linux-vulnerability</guid><description>An AI-assisted software scan revealed a 9-year-old Linux vulnerability with a 10-line proof-of-concept exploit. Learn about its implications and essential mitigation.</description><pubDate>Fri, 01 May 2026 00:55:21 GMT</pubDate><category>Linux</category><category>Vulnerability</category><category>AI Assisted Discovery</category><category>Proof of Concept</category><category>Patching</category></item><item><title>Axios npm Package Hijacked: Cross-Platform Malware Distribution</title><link>https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</guid><description>Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.</description><pubDate>Tue, 31 Mar 2026 16:29:10 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Remote Access Trojan</category><category>Malware</category><category>JavaScript</category><category>Linux</category><category>Windows</category><category>macOS</category></item><item><title>N8n Flaw Exploitation, Slopoly Malware, AppArmor LPE: Key Threats</title><link>https://runtimerebel.com/blog/n8n-flaw-exploitation-slopoly-malware-apparmor-lpe-key-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-flaw-exploitation-slopoly-malware-apparmor-lpe-key-threats</guid><description>Analysis of recent cybersecurity threats: actively exploited N8n flaw, Slopoly malware, Linux AppArmor root privilege vulnerability, and Telus Digital breach.</description><pubDate>Fri, 13 Mar 2026 16:20:49 GMT</pubDate><category>N8n</category><category>Slopoly</category><category>Malware</category><category>AppArmor</category><category>Linux</category><category>Privilege Escalation</category><category>Data Breach</category><category>Telus Digital</category><category>Exploitation</category></item><item><title>Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors</title><link>https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</guid><description>An undefined Chinese-speaking actor conducts long-term cyber espionage against critical Asian sectors using custom malware and living-off-the-land binaries.</description><pubDate>Mon, 09 Mar 2026 16:35:16 GMT</pubDate><category>Chinese APT</category><category>Espionage</category><category>Windows</category><category>Linux</category><category>LOTL</category><category>Custom Malware</category><category>Critical Infrastructure</category><category>Threat Actor</category></item><item><title>Critical Zero-Day in Linux Kernel Exposes Millions of Servers</title><link>https://runtimerebel.com/blog/zero-day-linux-kernel</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-day-linux-kernel</guid><description>A newly discovered zero-day vulnerability in the Linux kernel&apos;s netfilter subsystem allows local privilege escalation on systems running kernel versions 5.14 through…</description><pubDate>Mon, 15 Jan 2024 00:00:00 GMT</pubDate><category>Linux</category><category>Kernel</category><category>Zero-Day</category><category>Privilege Escalation</category><category>CVE</category></item></channel></rss>