Skip to main content
← CVE Tracker

Vendor

Linux

81 articles

Advertisement

INFO
Threat Intel

MAccConc: Memory Access Concurrency Testing and Tracing Tool

Explore MAccConc, a new developer tool for testing and discovering Linux kernel race conditions using memory access tracing and stack delays.

Runtime Rebel Intel
2 min read · Sep 8, 2026
MEDIUM
Threat Intel

North Korean Hackers Deploy New Linux Espionage Toolkit

North Korean state-sponsored hackers target automotive and media firms in South Korea using a custom Linux espionage toolkit.

Runtime Rebel Intel
2 min read · Sep 7, 2026
CRITICAL
Vulnerabilities

CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation

CISA adds CVE-2026-53362 to KEV, confirming active exploitation of a Linux Kernel privilege escalation vulnerability via IPv6. Patch now.

Runtime Rebel Intel
5 min read · Sep 1, 2026
INFO
Threat Intel

Linux Foundation to Govern TRACE: AI Runtime Attestation Standard

The Linux Foundation now governs TRACE, an open standard providing hardware-backed, verifiable evidence for AI agent runtime and confidential workloads.

Runtime Rebel Intel
4 min read · Aug 25, 2026
Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor
HIGH
Supply Chain

Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor

Malicious npm packages deliver RedC2 4.0 Linux backdoor, featuring AI-assisted command and control for advanced post-exploitation.

Runtime Rebel Intel
4 min read · Aug 22, 2026
UAT-10147: Agentic AI Enhances Post-Compromise Operations
HIGH
Threat Intel

UAT-10147: Agentic AI Enhances Post-Compromise Operations

Chinese-speaking adversary UAT-10147 leverages agentic AI for scaled exploitation, reconnaissance, and persistence on Windows and Linux web servers.

Runtime Rebel Intel
4 min read · Aug 20, 2026
SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits
HIGH
Threat Intel

SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits

Chinese-speaking actor UAT-10147 deploys SPECTRE, a cross-platform implant featuring Linux rootkit and BYOVD EDR bypass capabilities.

Runtime Rebel Intel
5 min read · Aug 20, 2026
Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft
HIGH
Malware

Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft

Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.

Runtime Rebel Intel
3 min read · Aug 17, 2026
MEDIUM
Malware

Evooo1Bot Linux Botnet Turns Routers Into SOCKS5 Relays

A new Mirai-based modular Linux botnet called Evooo1Bot targets internet routers, turning them into SOCKS5 traffic relay nodes.

Runtime Rebel Intel
3 min read · Aug 15, 2026
HIGH
Vulnerabilities

TONTOU CPU Attack Bypasses Spectre v2 Mitigations on Linux

New TONTOU CPU attack bypasses Spectre v2 fixes on Intel and AMD, enabling unprivileged attackers to leak Linux kernel password hashes.

Runtime Rebel Intel
5 min read · Aug 10, 2026
MEDIUM
Vulnerabilities

NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS

Synack's research reveals NatJack attacks, a new class of NAT exploitation affecting Windows, Linux, and macOS, leveraging trust assumptions.

Runtime Rebel Intel
4 min read · Aug 9, 2026
Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer
HIGH
Supply Chain

Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer

Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.

Runtime Rebel Intel
5 min read · Aug 8, 2026
INFO
Threat Intel

Linux Shell Forensics: Investigating Atuin History in Incident Response

Forensic analysis of Linux shell history using Atuin, a tool that enhances command logging.

Runtime Rebel Intel
5 min read · Aug 7, 2026
CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape
MEDIUM
Vulnerabilities

CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape

Analyze CVE-2026-64561, a KVM shadow MMU vulnerability dubbed Zapscape allowing L1 guest VM escape to Linux hosts. Learn mitigation steps.

Runtime Rebel Intel
3 min read · Aug 7, 2026
HIGH
Malware

SSH Botnet Reconnaissance Before Linux Cryptominer Deployment

An SSH botnet performs extensive hardware and system reconnaissance on Linux targets before deploying an optimized cryptocurrency miner. Weak credentials exploited.

Runtime Rebel Intel
4 min read · Jul 30, 2026
MEDIUM
Vulnerabilities

Microsoft Secure Boot Bypass via Vulnerable Shims — Remediation Guide

An analysis of a decade-long vulnerability in Microsoft Secure Boot. Learn how vulnerable Linux shims allow attackers to bypass UEFI firmware protections.

Runtime Rebel Intel
4 min read · Jul 29, 2026
Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence
MEDIUM
Malware

Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence

The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.

Runtime Rebel Intel
4 min read · Jul 28, 2026
CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access
HIGH
Vulnerabilities

CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access

A use-after-free race condition in the Linux kernel traffic-control subsystem, CVE-2026-53264, allows local privilege escalation to root on CentOS Stream 9.

Runtime Rebel Intel
4 min read · Jul 28, 2026
HIGH
Threat Intel

Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws

Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.

Runtime Rebel Intel
5 min read · Jul 24, 2026
Claude Cowork Sandbox Escape: VM to macOS File Access
HIGH
Vulnerabilities

Claude Cowork Sandbox Escape: VM to macOS File Access

A critical sandbox escape vulnerability in Anthropic's Claude Cowork allows AI agents to break out of their Linux VM, gaining full file access on macOS hosts, affecting…

Runtime Rebel Intel
5 min read · Jul 23, 2026
HIGH
Vulnerabilities

CVE-2026-64600: Local Root via Linux XFS Race Condition — Patch Now

A nine-year-old race condition in the Linux kernel XFS filesystem, known as RefluXFS, allows local attackers to achieve root privileges via file overwrites.

Runtime Rebel Intel
4 min read · Jul 23, 2026
CVE-2026-64600: RefluXFS Race Condition Grants Root on RHEL Systems
HIGH
Vulnerabilities

CVE-2026-64600: RefluXFS Race Condition Grants Root on RHEL Systems

Technical analysis of CVE-2026-64600, a nine-year-old race condition in the Linux XFS driver allowing local privilege escalation on RHEL and Amazon Linux.

Runtime Rebel Intel
4 min read · Jul 23, 2026
MEDIUM
Supply Chain

OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse

OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.

Runtime Rebel Intel
4 min read · Jul 10, 2026
CVE-2026-43499: GhostLock Linux Kernel Privilege Escalation Analysis
HIGH
Vulnerabilities

CVE-2026-43499: GhostLock Linux Kernel Privilege Escalation Analysis

A 15-year-old Linux kernel flaw, CVE-2026-43499 (GhostLock), enables local root access and container escape across major distributions since 2011.

Runtime Rebel Intel
4 min read · Jul 8, 2026