Security news

Latest security news

24 of 1,256 storiesLinuxClear all

Fri, 4 Sept 2026

  1. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance. The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected. Operating alongside this are an SSH keylogger, a curl-based RAT, and a stager. The RAT maintains a watchdog thread dedicated to tracking HAProxy’s health, and reporting it back to the operator’s infrastructure. The earliest uploads on VirusTotal date back to mid-2025 and the

    Rapid7 BlogLinux

Thu, 3 Sept 2026

  1. SUSE Linux security advisory (AV26-882)

    Serial Number: AV26-882 Date: September 3, 2026 As of September 3, 2026, SUSE is affected by vulnerabilities in the following product: Rancher Prior to 2.15.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release v2.15.1 · rancher/rancher · GitHub SUSE Update Advisories

    Canadian Centre for Cyber SecurityGitHub, Linux
  2. Your phone or computer may soon ask how old you are

    California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.

    Malwarebytes LabsLinux

Wed, 2 Sept 2026

  1. Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

    Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors,

    Check Point ResearchLinux

Thu, 27 Aug 2026

  1. CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products

    CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild

    Infosecurity MagazineMicrosoft, Citrix, Linux

Wed, 26 Aug 2026

  1. Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

    This new open standard offers hardware-attested runtime and compliance evidence for AI agents

    Infosecurity MagazineLinux

Thu, 20 Aug 2026

  1. UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

    The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.

    Cisco TalosLinux

Wed, 19 Aug 2026

  1. Exclusive: Linux Foundation's Akrites to Go Live in September

    The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects

    Infosecurity MagazineLinux

Fri, 14 Aug 2026

  1. Metasploit Wrap Up: Lot of summer shells and fit http profiles

    This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.* New module content (13) Ray Dashboard Logs API Path Traversal Author: Richard Howe Type: Auxiliary Pull request: #21681 contributed by rmhowe425 Path: `gather/ray_dashboard_logs_api_path_traversal` Description: This adds an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of

    Rapid7 BlogWindows, SonicWall, Linux
  2. New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

    Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies

    Infosecurity MagazineLinux

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets