#linux
18 stories taggedlinux.

cPanel Patches Bug That Let One Mail Account Hijack a Whole Server
A flaw in cPanel's EmailTrack tool let any authenticated mailbox user write files and run commands as root, the top-level administrator with total control of the machine.

AMD, Arm, and Nvidia Fix Security Flaws in Graphics and AI Chips
Three of the world's biggest chipmakers released patches this week for flaws that could let attackers crash systems or quietly read private data. Here is what each company fixed and who needs to act.

Acronis backup add-on carries a Linux privilege flaw, and someone is already using it
A high-severity bug in Acronis backup plugins for cPanel, WHM and Plesk is being exploited in what the vendor calls limited, targeted attacks. Patches are out.

'Ted' Backdoor Found Baked Into HAProxy Builds at Two South Korean Firms
A never-before-seen Linux implant was compiled straight into the load balancers, letting attackers read web traffic and swap pages for chosen visitors.

Iranian Hackers Nimbus Manticore Target Mac and Linux With Fake Job Tests
Kaspersky says the state-linked crew is now posing as recruiters and hiding remote-access malware inside coding challenges sent to job hunters.

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor
Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.
A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

Eighteen-Year-Old Bug in Linux Networking Code Hands Attackers the Keys to the Machine
A flaw in Linux's SCTP networking that has been sitting in the code since 2008 lets a local user become root and break out of a container. Fixed kernels shipped on 3 August.

Tengu Botnet Turns Linux Devices Against Their Own Defenders
A new Mirai spin-off reboots infected machines when responders try to shut it down, giving its persistence tricks another shot at survival.

A Hidden Linux Flaw Lets Any Local User Seize Full Control of a Machine
A race condition buried in the Linux XFS filesystem since 2017 can hand a regular user complete administrative control. Patches are out. Reboots are required.

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers
A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System
Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

OpenMandriva Linux Says Angry Contributor Wiped Years of Work
A developer with admin keys deleted repositories and pushed a package that could have broken user systems, after a dispute over the project's direction.

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.