Advertisement
Linux Kernel Januscape Flaw: VM Escape on KVM Hypervisors
Analysis of the 16-year-old Januscape flaw affecting Linux KVM hypervisors, enabling VM escape and potential host code execution on Intel and AMD systems.
CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw
A critical 16-year-old use-after-free vulnerability, Januscape (CVE-2026-53359), in Linux KVM allows guest VMs to escape to the host on Intel and AMD x86 systems.
CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android
Critical Linux kernel 'Bad Epoll' flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.
DirtyClone: Linux Kernel Privilege Escalation via Page Cache Manipulation
DirtyClone, a variant of DirtyFrag, allows unprivileged local users to exploit a Linux kernel flaw to manipulate the page cache and achieve root privileges.
CVE-2026-46331: Linux pedit COW Exploit Grants Root Access
A critical Linux kernel flaw, 'pedit COW' (CVE-2026-46331), allows local unprivileged users to gain root access via an out-of-bounds write. Public exploits exist.
Linux Foundation's Project Akrites: Bolstering Open Source Security
Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.
CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access
DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation allowing local users to gain root access via cloned network packets. Patch now.
CVE-2024-6387: OpenSSH regreSSHion RCE — Mitigation Guide
Critical analysis of CVE-2024-6387 (regreSSHion) in OpenSSH. Learn technical details of the signal handler race condition and how to defend Linux systems.
Linux Process Name Masquerading: Analyzing T1036 Obfuscation
Explore the technical methods behind Linux process name masquerading (MITRE ATT&CK T1036) used by actors like Velvet Ant to evade detection.
Earth Lusca Deploys New SprySOCKS Windows Variant Against Governments
Earth Lusca has ported the SprySOCKS Linux malware to Windows, targeting government entities globally. Analyze the TTPs and learn how to detect this threat.
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.
AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers
Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.
CVE-2026-23111: Linux Kernel nf_tables LPE and Container Escape
A one-character use-after-free vulnerability in the Linux kernel nf_tables subsystem allows local root access and container escapes. Patch immediately.
Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626
CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.
Microsoft Coreutils for Windows: Security and Memory Safety Analysis
Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.
CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595
CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.
PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap
An analysis of active PAN-OS exploitation, a new Linux authentication flaw, and the rise of AI-powered OAuth phishing kits targeting enterprise environments.
CVE-2024-52336: How CIFSwitch Grants Root Access on Linux Systems
The CVE-2024-52336 vulnerability, known as CIFSwitch, allows local privilege escalation to root by abusing CIFS key requests in the Linux kernel.
Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap
Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.
Linux Process-Specific HTTP Proxying: Tools and Analysis Gaps
Explores the utility of process-specific HTTP proxying for Linux debugging and reverse engineering, highlighting the absence of a generic solution akin to Proxifier.
Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis
Recent intelligence highlights a surge in Linux rootkits and router zero-day vulnerabilities targeting trusted system components and AI-driven intrusions.
Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy
Researchers discover Showboat, a modular Linux post-exploitation framework used in Middle East telecom attacks to establish persistent SOCKS5 proxy backdoors.
Flipper One: The Evolution of Linux-Based Hardware Pentesting Tools
Flipper Devices announces the Flipper One, an open Linux platform. Analyze the security implications and defensive requirements for this modular hacking tool.