Wednesday, August 19, 2026

Linux

Gunra Ransomware Uses Up to 100 ChaCha20 Threads to Rapidly Encrypt Linux Systems

Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launch up to 100 encryption threads,...

PoC Released for Linux Kernel STP Use-After-Free Vulnerability

A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel's software bridge implementation found in `net/bridge`. This vulnerability occurs within...

OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access

A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel's Open vSwitch (OVS) implementation. This vulnerability...

BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations

BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese...

Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access

A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain fileless execution, and...

AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation

A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This...

Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access

A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain...

Linux Kernel Team Publishes 440 CVE Security Advisories Within 24 Hours

The Linux kernel security team published approximately 440,440 CVE advisories over 24 hours, reflecting a significant release of vulnerability records linked to fixes already...

Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection

A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is...

Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools

Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes...

Linux FUSE Vulnerability Allows Unprivileged Users to Pop a Root Shell

A newly disclosed Linux kernel vulnerability in the FUSE subsystem allows unprivileged local users to escalate privileges to root by corrupting the page cache...