Threats Tagged 'linux'
View all threats tagged with 'linux'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'linux'
Click on any threat for detailed analysis and mitigation recommendations
Linux Process Name Masquerading, (Wed, Jun 24th) 0 This threat involves Linux process name masquerading, a technique where malicious processes disguise themselves by altering their displayed process names to appear non-suspicious. This can evade detection by security analysts and some security controls. The technique manipulates the process name shown in /proc/<pid>/comm and /proc/<pid>/cmdline by using system calls and memory overwrites. It has been observed in campaigns such as those attributed to the Velvet Ant Chinese group. Detection tools that rely solely on standard process listings can be deceived, though advanced tools like Kunai using eBPF can detect the real command line despite the masquerade. Join the discussion | SANS ISC Handlers Diary | 06/24/2026, 06:29:03 UTC Added: 06/24/2026, 06:39:14 UTC |
Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262CVE-2026-50195 0 Bulletin ID: 2026-046-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/18/2026 17:30 PM PDT Description: containerd is an open-source container runtime used by Kubernetes via the Container Runtime Interface (CRI) plugin. It underpins AWS managed container services including Amazon Elastic Kubernetes Service (Amazon EKS), Amazon Elastic Container Service (Amazon ECS), AWS Fargate, Bottlerocket, and Amazon Linux. AWS identified five issues in the containerd CRI plugin affecting versions 1.7 through 2.3. - CVE-2026-50195 (GHSA-cvxm-645q-p574) - CRI checkpoint import, local image tag poisoning - CVE-2026-53488 (GHSA-xhf5-7wjv-pqxp) - image-config LABEL -> host-root command exec - CVE-2026-53492 (GHSA-33vj-92qq-66hc) - CDI annotation smuggling during checkpoint restore - CVE-2026-53489 (GHSA-rgh6-rfwx-v388) - arbitrary host file read via symlink in checkpoint restore - CVE-2026-47262 (GHSA-jpcc-p29g-p8mq) - image-triggered runtime DoS Impacted versions: containerd 1.7, 2.0, 2.1, 2.2, 2.3 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 06/19/2026, 00:29:27 UTC Added: 06/20/2026, 00:05:06 UTC |
Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover 0 Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover Join the discussion | Exploit-DB RSS Feed | 05/26/2026, 00:00:00 UTC Added: 06/17/2026, 11:03:39 UTC |
Linux Kernel - Local Privilege Escalation 0 Linux Kernel - Local Privilege Escalation Join the discussion | Exploit-DB RSS Feed | 05/29/2026, 00:00:00 UTC Added: 06/17/2026, 11:03:38 UTC |
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages 0 A supply chain attack targeted the Arch User Repository (AUR) by publishing over 1,500 malicious packages. Attackers modified abandoned packages to execute malicious code during installation, leveraging eBPF for persistence and hiding. The malware is capable of credential and secret harvesting, including SSH keys and tokens, and can evade detection by hiding processes and files. Arch Linux responded by suspending new AUR account registrations to contain the attack and is actively removing malicious commits. Join the discussion | SecurityWeek | 06/16/2026, 10:51:49 UTC Added: 06/16/2026, 11:00:15 UTC |
Windows version of SprySOCKS Linux malware used to attack govt orgs 0 Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries. [...] Join the discussion | Bleeping Computer | 06/16/2026, 09:00:00 UTC Added: 06/16/2026, 09:30:03 UTC |
CVE-2026-11931 - Insecure Permissions on Authentication Token Cache File in Kiro IDECVE-2026-11931 0 Bulletin ID: 2026-045-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/15/2026 11:45 AM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-11931, where incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600). Impacted versions: < 0.11.133 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 06/15/2026, 18:41:08 UTC Added: 06/15/2026, 18:48:00 UTC |
Over 400 Arch Linux packages compromised to push rootkit, infostealer 0 More than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens. [...] Join the discussion | Bleeping Computer | 06/12/2026, 17:03:55 UTC Added: 06/12/2026, 17:09:27 UTC |
CISA warns of active attacks exploiting Android, Linux bugs 0 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. [...] Join the discussion | Bleeping Computer | 06/03/2026, 15:36:16 UTC Added: 06/03/2026, 15:48:37 UTC |
Organizations Warned of Exploited Linux Kernel Vulnerability 0 An improper authentication bug allows attackers to escalate their privileges and escape containers. The post Organizations Warned of Exploited Linux Kernel Vulnerability appeared first on SecurityWeek . Join the discussion | SecurityWeek | 06/03/2026, 11:56:43 UTC Added: 06/03/2026, 12:03:34 UTC |
Showing 1 to 10 of 25 results