Linux
Curated coverage and analysis in this editorial area.

HAProxy Turned Trojan: North Korean APT Weaponizes the Load Balancer
Rapid7 Labs has uncovered a Linux toolkit that weaponizes HAProxy itself. A source-level backdoor, watchdog thread, and polymorphic st…

Dirty Frag: The Linux Kernel Bug That Bypasses Every Container Scanner
Dirty Frag exploits three CVEs in the Linux kernel to corrupt the page cache and gain root. The problem isn't in Docker images—it's in…

"ted" Backdoor in HAProxy: Load Balancer Turned Spy in South Korea
Rapid7 Labs uncovered a previously undocumented Linux toolkit that injects the "ted" backdoor into HAProxy 2.8.12 to intercept traffic…

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks
The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing
ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

Copy Fail: The 732-Byte Linux Kernel Bug That Slept Since 2017
An unprivileged local user gains root deterministically. The exploit weighs 732 bytes. The bug had been in the kernel since 2017. This…

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

GhostLock: Public Exploit Grants Root in 5 Seconds on Linux Since 2011
CVE-2026-43499 has existed in the Linux kernel for 15 years. The public proof-of-concept requires only a local user to obtain root in…

ZDI-26-573: Pre-Auth Linux Kernel KSMBD Vulnerability Scores CVSS 9.3
A critical flaw in the in-kernel KSMBD SMB server allows unauthenticated out-of-bounds reads leading to information disclosure and pot…

ZDI-26-575: TOCTOU in Linux Kernel Net Scheduler Enables Local Privilege Escalation
A TOCTOU race condition in the Linux kernel's Net Scheduler packet classifier API allows local privilege escalation. The fix introduce…

TONTOU: The Attack That Nullifies Spectre v2 Mitigations and Leaks Linux Passwords
MIT CSAIL researchers demonstrated a bypass of Spectre v2 mitigations on Linux at Black Hat USA 2026. TONTOU extracts password hashes…

ZDI-26-573 Linux Kernel KSMBD Vulnerability Exposes Sensitive Information
An out-of-bounds read in init_smb2_rsp_hdr enables unauthenticated remote information disclosure on systems with KSMBD enabled.