Tag

#linux

18 stories taggedlinux.

Server room with multiple tall rack units illuminated in blue and green, one unit's indicator lights flashing amber in an irregular pattern suggesting abnormal
Vulnerabilities

cPanel Patches Bug That Let One Mail Account Hijack a Whole Server

A flaw in cPanel's EmailTrack tool let any authenticated mailbox user write files and run commands as root, the top-level administrator with total control of the machine.

3 min read
Three different computer chip circuit boards arranged in a technical workspace—one showing graphics processing patterns, one with AI neuron-like structures, and
Vulnerabilities

AMD, Arm, and Nvidia Fix Security Flaws in Graphics and AI Chips

Three of the world's biggest chipmakers released patches this week for flaws that could let attackers crash systems or quietly read private data. Here is what each company fixed and who needs to act.

4 min read
A server room with multiple dark tower units and blinking status lights, with one unit's access panel slightly ajar revealing the internal circuitry, suggesting
Vulnerabilities

Acronis backup add-on carries a Linux privilege flaw, and someone is already using it

A high-severity bug in Acronis backup plugins for cPanel, WHM and Plesk is being exploited in what the vendor calls limited, targeted attacks. Patches are out.

3 min read
A HAProxy load balancer interface showing network traffic monitoring, with malicious code injected into the build logs visible in the background terminal
Threat Intelligence

'Ted' Backdoor Found Baked Into HAProxy Builds at Two South Korean Firms

A never-before-seen Linux implant was compiled straight into the load balancers, letting attackers read web traffic and swap pages for chosen visitors.

4 min read
A laptop screen displaying a job recruitment email and coding challenge test file, Mac and Linux system environments visible, malicious payload hidden within th
Threat Intelligence

Iranian Hackers Nimbus Manticore Target Mac and Linux With Fake Job Tests

Kaspersky says the state-linked crew is now posing as recruiters and hiding remote-access malware inside coding challenges sent to job hunters.

3 min read
A developer's workstation with a code editor showing package dependencies and terminal windows with security warnings, with red alert indicators on the screen
Threat Intelligence

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor

Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

3 min read
A timeline graphic displayed on a large monitor tracing decades of software history, highlighting ancient code libraries and print-spooler systems, Stuxnet malw
Vulnerabilities

Some of the Bugs That Hid Inside Everyday Software for Decades

From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

4 min read
A GitHub repository page displayed on a monitor, a private key snippet visible in code history with a glowing red circle and X overlay, security warning banners
Identity & Access

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.

A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

3 min read
A Linux system terminal window showing kernel code from 2008 with a privilege escalation exploit running, displaying root access being granted with an alert ove
Vulnerabilities

Eighteen-Year-Old Bug in Linux Networking Code Hands Attackers the Keys to the Machine

A flaw in Linux's SCTP networking that has been sitting in the code since 2008 lets a local user become root and break out of a container. Fixed kernels shipped on 3 August.

3 min read
A network operations center with multiple server racks, one machine rebooting with lights cycling through red and amber, an engineer's hand frozen mid-gesture n
Threat Intelligence

Tengu Botnet Turns Linux Devices Against Their Own Defenders

A new Mirai spin-off reboots infected machines when responders try to shut it down, giving its persistence tricks another shot at survival.

3 min read
A system administrator's hands hovering over a keyboard at an empty desk, with a computer monitor displaying a terminal window showing file system logs and perm
Vulnerabilities

A Hidden Linux Flaw Lets Any Local User Seize Full Control of a Machine

A race condition buried in the Linux XFS filesystem since 2017 can hand a regular user complete administrative control. Patches are out. Reboots are required.

4 min read
A Red Hat Enterprise Linux desktop with file system permission indicators showing a regular user escalating to root-level access through a nine-year-old XFS vul
Vulnerabilities

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers

A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.

3 min read
Full-frame photoreal editorial image of a close-up Windows laptop screen showing a generic blue security shield icon glowing, with faint reflection on a dark de
Vulnerabilities

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System

Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

3 min read
Photoreal news-editorial image, full frame 16:9, of an abandoned open source developer workstation at night: dark room, glowing monitor showing a terminal with
Identity & Access

OpenMandriva Linux Says Angry Contributor Wiped Years of Work

A developer with admin keys deleted repositories and pushed a package that could have broken user systems, after a dispute over the project's direction.

3 min read
Full-frame close-up of a dark server room aisle, rows of black rack-mounted machines with faint green and amber status LEDs, one open server tray showing a bare
Vulnerabilities

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access

Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

3 min read
© 2026 Threat Vectr