Skip to main content
← CVE Tracker

Vendor

Linux

67 articles

MA
HIGH
Malware

SSH Botnet Reconnaissance Before Linux Cryptominer Deployment

An SSH botnet performs extensive hardware and system reconnaissance on Linux targets before deploying an optimized cryptocurrency miner. Weak credentials exploited.

Runtime Rebel Intel
4 min read · Jul 30, 2026
VU
MEDIUM
Vulnerabilities

Microsoft Secure Boot Bypass via Vulnerable Shims — Remediation Guide

An analysis of a decade-long vulnerability in Microsoft Secure Boot. Learn how vulnerable Linux shims allow attackers to bypass UEFI firmware protections.

Runtime Rebel Intel
4 min read · Jul 29, 2026
Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence
MEDIUM
Malware

Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence

The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.

Runtime Rebel Intel
4 min read · Jul 28, 2026
CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access
HIGH
Vulnerabilities

CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access

A use-after-free race condition in the Linux kernel traffic-control subsystem, CVE-2026-53264, allows local privilege escalation to root on CentOS Stream 9.

Runtime Rebel Intel
4 min read · Jul 28, 2026
TH
HIGH
Threat Intel

Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws

Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.

Runtime Rebel Intel
5 min read · Jul 24, 2026
Claude Cowork Sandbox Escape: VM to macOS File Access
HIGH
Vulnerabilities

Claude Cowork Sandbox Escape: VM to macOS File Access

A critical sandbox escape vulnerability in Anthropic's Claude Cowork allows AI agents to break out of their Linux VM, gaining full file access on macOS hosts, affecting…

Runtime Rebel Intel
5 min read · Jul 23, 2026
VU
HIGH
Vulnerabilities

CVE-2026-64600: Local Root via Linux XFS Race Condition — Patch Now

A nine-year-old race condition in the Linux kernel XFS filesystem, known as RefluXFS, allows local attackers to achieve root privileges via file overwrites.

Runtime Rebel Intel
4 min read · Jul 23, 2026
CVE-2026-64600: RefluXFS Race Condition Grants Root on RHEL Systems
HIGH
Vulnerabilities

CVE-2026-64600: RefluXFS Race Condition Grants Root on RHEL Systems

Technical analysis of CVE-2026-64600, a nine-year-old race condition in the Linux XFS driver allowing local privilege escalation on RHEL and Amazon Linux.

Runtime Rebel Intel
4 min read · Jul 23, 2026
SU
MEDIUM
Supply Chain

OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse

OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.

Runtime Rebel Intel
4 min read · Jul 10, 2026
CVE-2026-43499: GhostLock Linux Kernel Privilege Escalation Analysis
HIGH
Vulnerabilities

CVE-2026-43499: GhostLock Linux Kernel Privilege Escalation Analysis

A 15-year-old Linux kernel flaw, CVE-2026-43499 (GhostLock), enables local root access and container escape across major distributions since 2011.

Runtime Rebel Intel
4 min read · Jul 8, 2026
VU
HIGH
Vulnerabilities

Linux Kernel Januscape Flaw: VM Escape on KVM Hypervisors

Analysis of the 16-year-old Januscape flaw affecting Linux KVM hypervisors, enabling VM escape and potential host code execution on Intel and AMD systems.

Runtime Rebel Intel
4 min read · Jul 7, 2026
CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw
HIGH
Vulnerabilities

CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw

A critical 16-year-old use-after-free vulnerability, Januscape (CVE-2026-53359), in Linux KVM allows guest VMs to escape to the host on Intel and AMD x86 systems.

Runtime Rebel Intel
5 min read · Jul 6, 2026
CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android
HIGH
Vulnerabilities

CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android

Critical Linux kernel 'Bad Epoll' flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.

Runtime Rebel Intel
4 min read · Jul 3, 2026
VU
HIGH
Vulnerabilities

DirtyClone: Linux Kernel Privilege Escalation via Page Cache Manipulation

DirtyClone, a variant of DirtyFrag, allows unprivileged local users to exploit a Linux kernel flaw to manipulate the page cache and achieve root privileges.

Runtime Rebel Intel
5 min read · Jun 29, 2026
CVE-2026-46331: Linux pedit COW Exploit Grants Root Access
HIGH
Vulnerabilities

CVE-2026-46331: Linux pedit COW Exploit Grants Root Access

A critical Linux kernel flaw, 'pedit COW' (CVE-2026-46331), allows local unprivileged users to gain root access via an out-of-bounds write. Public exploits exist.

Runtime Rebel Intel
4 min read · Jun 26, 2026
SU
INFO
Supply Chain

Linux Foundation's Project Akrites: Bolstering Open Source Security

Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.

Runtime Rebel Intel
4 min read · Jun 26, 2026
CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access
HIGH
Vulnerabilities

CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access

DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation allowing local users to gain root access via cloned network packets. Patch now.

Runtime Rebel Intel
4 min read · Jun 26, 2026
VU
HIGH
Vulnerabilities

CVE-2024-6387: OpenSSH regreSSHion RCE — Mitigation Guide

Critical analysis of CVE-2024-6387 (regreSSHion) in OpenSSH. Learn technical details of the signal handler race condition and how to defend Linux systems.

Runtime Rebel Intel
4 min read · Jun 24, 2026
TH
MEDIUM
Threat Intel

Linux Process Name Masquerading: Analyzing T1036 Obfuscation

Explore the technical methods behind Linux process name masquerading (MITRE ATT&CK T1036) used by actors like Velvet Ant to evade detection.

Runtime Rebel Intel
4 min read · Jun 24, 2026
TH
HIGH
Threat Intel

Earth Lusca Deploys New SprySOCKS Windows Variant Against Governments

Earth Lusca has ported the SprySOCKS Linux malware to Windows, targeting government entities globally. Analyze the TTPs and learn how to detect this threat.

Runtime Rebel Intel
3 min read · Jun 16, 2026
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
HIGH
Supply Chain

400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer

Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.

Runtime Rebel Intel
4 min read · Jun 12, 2026
SU
MEDIUM
Supply Chain

AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers

Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.

Runtime Rebel Intel
4 min read · Jun 12, 2026
CVE-2026-23111: Linux Kernel nf_tables LPE and Container Escape
HIGH
Vulnerabilities

CVE-2026-23111: Linux Kernel nf_tables LPE and Container Escape

A one-character use-after-free vulnerability in the Linux kernel nf_tables subsystem allows local root access and container escapes. Patch immediately.

Runtime Rebel Intel
4 min read · Jun 8, 2026
VU
HIGH
Vulnerabilities

Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626

CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.

Runtime Rebel Intel
4 min read · Jun 3, 2026