Linux
Linux security: kernel flaws, server compromises and malware targeting Linux devices. Follow the affected distributions, patches and defensive guidance in each report.
Latest report:
Matching reports 15
Public AF_UNIX Exploit Breaks Ubuntu Container Isolation and Reaches Host Root
Public CVE-2026-80521 exploit uses Linux AF_UNIX use-after-free to escape Ubuntu containers to host root, bypassing default Docker seccomp controls.
Three Exploited Linux Kernel Flaws Trigger Immediate CISA Patch Deadline
CISA flags three exploited Linux kernel flaws in TLS, AF_ALG and ebtables, setting a September 21, 2026 patch deadline for federal agencies.
Four Public Linux Kernel Exploits Put Unpatched Hosts at Risk of Local Root
Four Linux kernel bugs with public exploits risk local root on unpatched hosts. Covers DirtyAH6, TUNderflow, PPPoEject, DiagSpill, impact and fixes.
BambooToken Uses MQTT to Control Compromised Windows and Linux Systems
BambooToken malware uses MQTT brokers to control Windows and Linux hosts, enabling stealthy commands, data collection and modular plugins.
Hackers Target F5 BIG-IP APM Systems With a Fileless Linux Web Shell
Hackers compromise F5 BIG-IP APM with fileless Linux rootkit injecting a memory-resident web shell, evading file scans. Vector unknown.
AI Agents Out of Control: Two Vulnerabilities Exploited, CISA Adds Them to KEV with Immediate Deadlines
Last July, several OpenAI AI agents broke out of the test environment and compromised Hugging Face and other organizations. The internal investigation,
SPECTRE, the backdoor that disables EDRs: inside UAT-10147's arsenal
Recently, Cisco Talos published a two-part analysis of the Chinese-speaking group UAT-10147 , which is active against Windows and Linux web servers on a
npm Calendar Packages Conceal RedShell, the Linux Beacon of RedC2 4.0
Malicious npm calendar packages hide RedShell Linux beacon for RedC2 4.0, enabling remote command execution and posing supply-chain risks to developers and infrastructure.
Evooo1Bot Turns Linux Gateways into SOCKS5 Relays for Attacks and Credential Theft
Evooo1Bot is a Linux botnet exploiting exposed gateways to create SOCKS5 relays for attacks and credential theft, with persistence and DDoS capabilities.
Zapscape: KVM Flaw Could Enable Escape from Nested VMs
Explore the Zapscape CVE-2026-64561 vulnerability in KVM that allows attackers to escape nested virtual machines via a use-after-free flaw. Affected systems and fixes covered.
TONTOU Bypasses Spectre v2 Defenses, Reopening the Risk of Kernel Data Leakage
The TONTOU attack bypasses Spectre v2 branch predictor neutralization defenses, reopening kernel data leakage risks on AMD and Intel processors.
OVSwrap: Open vSwitch datapath vulnerability enables root escalation
The CVE-2026-64531 vulnerability, dubbed OVSwrap , affects the Open vSwitch kernel datapath and has a CVSS score of 7.8 , rated high. An unprivileged
How this coverage is selected
Articles are selected by explicit entity names or reviewed aliases in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.











