Skip to main content
← CVE Tracker

Vendor

Linux

67 articles

TH
INFO
Threat Intel

Microsoft Coreutils for Windows: Security and Memory Safety Analysis

Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.

Runtime Rebel Intel
3 min read · Jun 3, 2026
VU
HIGH
Vulnerabilities

CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595

CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.

Runtime Rebel Intel
3 min read · Jun 2, 2026
PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap
HIGH
Threat Intel

PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap

An analysis of active PAN-OS exploitation, a new Linux authentication flaw, and the rise of AI-powered OAuth phishing kits targeting enterprise environments.

Runtime Rebel Intel
3 min read · Jun 1, 2026
VU
HIGH
Vulnerabilities

CVE-2024-52336: How CIFSwitch Grants Root Access on Linux Systems

The CVE-2024-52336 vulnerability, known as CIFSwitch, allows local privilege escalation to root by abusing CIFS key requests in the Linux kernel.

Runtime Rebel Intel
4 min read · May 30, 2026
Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap
HIGH
Threat Intel

Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap

Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.

Runtime Rebel Intel
3 min read · May 25, 2026
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
HIGH
Supply Chain

Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware

Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.

Runtime Rebel Intel
3 min read · May 23, 2026
TH
INFO
Threat Intel

Linux Process-Specific HTTP Proxying: Tools and Analysis Gaps

Explores the utility of process-specific HTTP proxying for Linux debugging and reverse engineering, highlighting the absence of a generic solution akin to Proxifier.

Runtime Rebel Intel
5 min read · May 21, 2026
Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis
HIGH
Threat Intel

Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis

Recent intelligence highlights a surge in Linux rootkits and router zero-day vulnerabilities targeting trusted system components and AI-driven intrusions.

Runtime Rebel Intel
4 min read · May 21, 2026
Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy
HIGH
Threat Intel

Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy

Researchers discover Showboat, a modular Linux post-exploitation framework used in Middle East telecom attacks to establish persistent SOCKS5 proxy backdoors.

Runtime Rebel Intel
3 min read · May 21, 2026
TH
INFO
Threat Intel

Flipper One: The Evolution of Linux-Based Hardware Pentesting Tools

Flipper Devices announces the Flipper One, an open Linux platform. Analyze the security implications and defensive requirements for this modular hacking tool.

Runtime Rebel Intel
4 min read · May 21, 2026
CVE-2026-46333: Nine-Year-Old Linux Kernel Privilege Escalation Flaw
MEDIUM
Vulnerabilities

CVE-2026-46333: Nine-Year-Old Linux Kernel Privilege Escalation Flaw

A long-standing Linux kernel flaw, CVE-2026-46333, allows local users to achieve root access and disclose sensitive data on major Linux distributions.

Runtime Rebel Intel
4 min read · May 21, 2026
VU
HIGH
Vulnerabilities

CVE-2024-51567: How Attackers Exploit Arch Linux genfstab — Patch Now

A public exploit for PinTheft (CVE-2024-51567) allows local attackers to gain root privileges on Arch Linux via the genfstab script. Update to version 31.

Runtime Rebel Intel
4 min read · May 20, 2026
CVE-2026-31635: DirtyDecrypt Linux Kernel LPE PoC Released
HIGH
Vulnerabilities

CVE-2026-31635: DirtyDecrypt Linux Kernel LPE PoC Released

Exploit code for DirtyDecrypt (CVE-2026-31635) has been released, allowing local privilege escalation via vulnerabilities in the Linux kernel crypto API.

Runtime Rebel Intel
4 min read · May 19, 2026
VU
HIGH
Vulnerabilities

DirtyDecrypt: How Attackers Exploit Linux Kernel rxgk for Root Access

Learn about DirtyDecrypt, a local privilege escalation vulnerability in the Linux rxgk module. Discover how to detect and mitigate this root access threat.

Runtime Rebel Intel
3 min read · May 18, 2026
VU
HIGH
Vulnerabilities

Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits

Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.

Runtime Rebel Intel
4 min read · May 15, 2026
VU
HIGH
Vulnerabilities

CVE-2026-46300: Fragnesia Flaw Enables Linux Root Privilege Escalation

Security researchers identify Fragnesia (CVE-2026-46300), a Linux kernel vulnerability allowing local attackers to gain root access via packet fragmentation.

Runtime Rebel Intel
3 min read · May 14, 2026
VU
HIGH
Vulnerabilities

CVE-2026-46300: Linux Fragnesia Kernel Privilege Escalation Analysis

Critical analysis of the Fragnesia Linux kernel vulnerability (CVE-2026-46300), enabling local root access via IP fragmentation flaws. Includes mitigation steps.

Runtime Rebel Intel
4 min read · May 14, 2026
CVE-2026-46300: Fragnesia Linux Kernel LPE Grants Root Access
HIGH
Vulnerabilities

CVE-2026-46300: Fragnesia Linux Kernel LPE Grants Root Access

A technical analysis of CVE-2026-46300, a Linux kernel LPE vulnerability dubbed Fragnesia that enables root access via XFRM page cache corruption.

Runtime Rebel Intel
4 min read · May 14, 2026
VU
HIGH
Vulnerabilities

CVE-2026-31431: Analyzing the Copy.Fail Linux Kernel LPE

Technical analysis of CVE-2026-31431 (Copy.Fail), a critical Linux kernel vulnerability enabling local privilege escalation via page cache corruption.

Runtime Rebel Intel
4 min read · May 12, 2026
CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels
HIGH
Vulnerabilities

CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels

Analysis of CVE-2024-1086 (Dirty Frag), a netfilter vulnerability enabling local privilege escalation to root across major enterprise Linux distributions.

Runtime Rebel Intel
3 min read · May 11, 2026
Linux Rootkits and macOS Crypto Stealers Surge in Supply Chain Attacks
HIGH
Threat Intel

Linux Rootkits and macOS Crypto Stealers Surge in Supply Chain Attacks

Analysis of recent threats involving Linux rootkit persistence, macOS crypto-stealing malware, and the exploitation of poisoned supply chain downloads.

Runtime Rebel Intel
3 min read · May 11, 2026
VU
HIGH
Vulnerabilities

CVE-2026-43284: 'Dirty Frag' Linux Vulnerability Exploited — Patch Now

Analysis of the 'Dirty Frag' (Copy Fail 2) Linux kernel vulnerabilities CVE-2026-43284 and CVE-2026-43500, which enable potential remote code execution.

Runtime Rebel Intel
4 min read · May 11, 2026
TH
HIGH
Threat Intel

PamDOORa Backdoor and Windows Phone Link OTP Theft Analysis

Recent intelligence highlights the PamDOORa Linux backdoor and malware leveraging Windows Phone Link to bypass OTP-based authentication mechanisms.

Runtime Rebel Intel
3 min read · May 8, 2026
Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks
HIGH
Malware

Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks

A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.

Runtime Rebel Intel
4 min read · May 8, 2026