Linux
Curated coverage and analysis in this editorial area.

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure
The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

Dirty Frag: Linux Kernel LPE Chain with Public PoC and Patches Available
Dirty Frag is a two-vulnerability chain in the Linux kernel that enables root escalation on nearly all distributions. Mainline patches…

VoidLink: The Cloud-Native Malware Turning Linux into an Attack SaaS
Check Point Research discovered VoidLink in December 2025, a cloud-native Linux malware framework written in Zig with 30-plus plugins,…

Copy Fail CVE-2026-31431: Root Escalation in 732 Bytes on Linux
CVE-2026-31431 lets a local user gain root on Linux in seconds with a 732-byte script. CISA confirms active exploitation.

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions
CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

MIT CSAIL: Interrupt Injection Bypasses Spectre v2 on Intel and AMD CPUs
MIT CSAIL researchers demonstrated that an unprivileged Linux program can inject precisely timed hardware interrupts to bypass Spectre…

ZDI-26-463: RCE in GStreamer via MRF File, Patch Available
Trend Micro's Zero Day Initiative published advisory ZDI-26-463 detailing a remote code execution vulnerability in GStreamer's MRF par…

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8
JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

Arch Linux Halts AUR Package Adoptions: Third Supply-Chain Attack in Two Months
On July 30, 2026, Arch Linux suspended package adoptions in the Arch User Repository to stop an active supply-chain campaign. It is th…

QLNX: The Linux RAT Targeting Software Supply Chain Keys
Trend Micro discovered QLNX, a previously undocumented Linux RAT that combines a dual-tier rootkit, PAM backdoor, and P2P network to s…

GhostLock: The Exploit That Unlocks Linux in 5 Seconds — 15 Years in the Shadows
On July 7, 2026, Nebula Security disclosed GhostLock, a working exploit for CVE-2026-43499, a use-after-free in the Linux kernel's fut…

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure
An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…