#linux
16 stories taggedlinux.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.
A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

Eighteen-Year-Old Bug in Linux Networking Code Hands Attackers the Keys to the Machine
A flaw in Linux's SCTP networking that has been sitting in the code since 2008 lets a local user become root and break out of a container. Fixed kernels shipped on 3 August.

Tengu Botnet Turns Linux Devices Against Their Own Defenders
A new Mirai spin-off reboots infected machines when responders try to shut it down, giving its persistence tricks another shot at survival.

A Hidden Linux Flaw Lets Any Local User Seize Full Control of a Machine
A race condition buried in the Linux XFS filesystem since 2017 can hand a regular user complete administrative control. Patches are out. Reboots are required.

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers
A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System
Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

OpenMandriva Linux Says Angry Contributor Wiped Years of Work
A developer with admin keys deleted repositories and pushed a package that could have broken user systems, after a dispute over the project's direction.

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

A 16-Year-Old Linux Flaw Lets Attackers Break Out of Virtual Machines
A newly disclosed bug in the Linux kernel has sat unnoticed since 2009, and it lets criminals escape the virtual walls that are supposed to keep cloud servers separate and safe.

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw
A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. That raises the urgency for every organisation running Linux servers to patch now.

Monday Brief: A DirtyClone Linux Bug, Turla's New Backdoor, and the Infostealer Churn
Old access paths, missed patches, and a fresh kernel flaw kept defenders busy. A roundup of what moved this week in the cybercrime ecosystem.

DirtyClone: New Linux Kernel Flaw Hands Unprivileged Users the Root Keys
A page-cache manipulation bug related to DirtyFrag lets local, unprivileged attackers escalate to root — no credentials required beyond a shell.

Velvet Ant Lived Inside PAM and OpenSSH for Nearly Ten Years
A China-nexus crew skipped the endpoints defenders actually watch and backdoored the Linux login stack itself, where IR runbooks rarely reach.

PoC Drops for 19-Year-Old Linux Kernel Privilege-Escalation Bug in CIFSwitch
A flaw that's been sitting in the kernel since the mid-2000s now has working exploit code. Low-privileged users can reach root.