// 1 ZERO-DAY · 2 CVE · 3 EXPLOIT IN THE LAST 24H
malware

HAProxy Turned Trojan: North Korean APT Weaponizes the Load Balancer

Rapid7 Labs has uncovered a Linux toolkit that weaponizes HAProxy itself. A source-level backdoor, watchdog thread, and polymorphic st…

Sep 06, 2026views - 997

VULNEXPLOIT

Dirty Frag: The Linux Kernel Bug That Bypasses Every Container Scanner

Dirty Frag exploits three CVEs in the Linux kernel to corrupt the page cache and gain root. The problem isn't in Docker images—it's in…

Sep 05, 2026views - 1.1k

CYBERSEC

"ted" Backdoor in HAProxy: Load Balancer Turned Spy in South Korea

Rapid7 Labs uncovered a previously undocumented Linux toolkit that injects the "ted" backdoor into HAProxy 2.8.12 to intercept traffic…

Sep 04, 2026views - 1k

ransomware

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks

The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

Aug 28, 2026views - 1.2k

bluetoothCRITICAL

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing

ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

Aug 25, 2026views - 1.1k

VULNZERO-DAY

Copy Fail: The 732-Byte Linux Kernel Bug That Slept Since 2017

An unprivileged local user gains root deterministically. The exploit weighs 732 bytes. The bug had been in the kernel since 2017. This…

Aug 19, 2026views - 1.2k

CYBERSEC

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD

MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

Aug 18, 2026views - 1.2k

linuxEXPLOIT

GhostLock: Public Exploit Grants Root in 5 Seconds on Linux Since 2011

CVE-2026-43499 has existed in the Linux kernel for 15 years. The public proof-of-concept requires only a local user to obtain root in…

Aug 17, 2026views - 1.2k

VULNZERO-DAY

ZDI-26-573: Pre-Auth Linux Kernel KSMBD Vulnerability Scores CVSS 9.3

A critical flaw in the in-kernel KSMBD SMB server allows unauthenticated out-of-bounds reads leading to information disclosure and pot…

Aug 17, 2026views - 324

linux

ZDI-26-575: TOCTOU in Linux Kernel Net Scheduler Enables Local Privilege Escalation

A TOCTOU race condition in the Linux kernel's Net Scheduler packet classifier API allows local privilege escalation. The fix introduce…

Aug 16, 2026views - 1.1k

VULN

TONTOU: The Attack That Nullifies Spectre v2 Mitigations and Leaks Linux Passwords

MIT CSAIL researchers demonstrated a bypass of Spectre v2 mitigations on Linux at Black Hat USA 2026. TONTOU extracts password hashes…

Aug 14, 2026views - 1.1k

VULNZERO-DAY

ZDI-26-573 Linux Kernel KSMBD Vulnerability Exposes Sensitive Information

An out-of-bounds read in init_smb2_rsp_hdr enables unauthenticated remote information disclosure on systems with KSMBD enabled.

Aug 13, 2026views - 1.1k