-
A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct large-scale SEO poisoning and online-gambling fraud. The operation has been active since mid-20…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student at the University of Helsinki, Linus Torvalds, announced his work on the comp.os newsgroup.mini…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cluster of trojanized npm packages is delivering the RedC2 4.0 Linux implant, providing operators with a pathway from a seemingly harmless dependency import to internal network pivoting via SOCKS5 proxies and TCP forwarding. The campaign disguises ma…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launch up to 100 encryption threads, a design that compresses the time defenders have to detect and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridge`. This vulnerability occurs within the Spanning Tree Protocol (STP) timer lifecycle. It…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch (OVS) implementation. This vulnerability could allow unprivileged local users to gain roo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain fileless execution, and persist across multiple user accounts on compromised hosts. The operation, tr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


