Visualização normal

Hoje — 7 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • Linux Kernel 7.1 Reaches End of Life Do Son
    The Linux Kernel 7.1 EOL has officially arrived. Discover the final updates and learn why you must upgrade to the latest stable LTS releases immediately. Related Posts: CERN to Move 2,200 Accelerator Control Machines to Debian 13 Debian 11 Reaches End of Long Term Support Linux Nears USB4 Support for Apple Silicon The post Linux Kernel 7.1 Reaches End of Life appeared first on Daily CyberSecurity.
     

Linux Kernel 7.1 Reaches End of Life

Por:Do Son
7 de Setembro de 2026, 00:33

The Linux Kernel 7.1 EOL has officially arrived. Discover the final updates and learn why you must upgrade to the latest stable LTS releases immediately.

Related Posts:

The post Linux Kernel 7.1 Reaches End of Life appeared first on Daily CyberSecurity.

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash […]

The post Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation Do Son
    Security researchers released a Linux CVE-2026-52924 PoC exploit. Check flaw details and patch instructions to secure your systems against root takeovers. Related Posts: MikroTik RouterOS Vulnerability Exploited in the Wild: Patch and Defense Blueprint StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE The post CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CERN to Move 2,200 Accelerator Control Machines to Debian 13 Do Son
    CERN's Debian migration moves 2,200+ accelerator control machines off Red Hat, driven by RHEL's raised x86-64 CPU baseline. Related Posts: Debian 11 Reaches End of Long Term Support Linux Nears USB4 Support for Apple Silicon Debian AI Policy: Responsible Generative AI Use Wins Vote The post CERN to Move 2,200 Accelerator Control Machines to Debian 13 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Debian 11 Reaches End of Long Term Support Do Son
    Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version. Related Posts: Linux Nears USB4 Support for Apple Silicon Debian AI Policy: Responsible Generative AI Use Wins Vote California Exempts Linux from Age Verification The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.
     

Debian 11 Reaches End of Long Term Support

Por:Do Son
1 de Setembro de 2026, 22:18

Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version.

Related Posts:

The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Linux Nears USB4 Support for Apple Silicon Do Son
    Discover how the Asahi Linux project is successfully pushing vital USB4 protocol drivers for Apple Silicon directly into the mainline Linux kernel. Related Posts: Debian AI Policy: Responsible Generative AI Use Wins Vote California Exempts Linux from Age Verification Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes The post Linux Nears USB4 Support for Apple Silicon appeared first on Daily CyberSecurity.
     

Linux Nears USB4 Support for Apple Silicon

Por:Do Son
31 de Agosto de 2026, 23:31

Discover how the Asahi Linux project is successfully pushing vital USB4 protocol drivers for Apple Silicon directly into the mainline Linux kernel.

Related Posts:

The post Linux Nears USB4 Support for Apple Silicon appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Debian AI Policy: Responsible Generative AI Use Wins Vote Do Son
    Debian's AI policy vote picked "Responsible Use of Generative AI": AI is neither banned nor endorsed, with full accountability left to contributors. Related Posts: Linux Nears USB4 Support for Apple Silicon California Exempts Linux from Age Verification Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes The post Debian AI Policy: Responsible Generative AI Use Wins Vote appeared first on Daily CyberSecurity.
     

Debian AI Policy: Responsible Generative AI Use Wins Vote

Por:Do Son
31 de Agosto de 2026, 10:02

Debian's AI policy vote picked "Responsible Use of Generative AI": AI is neither banned nor endorsed, with full accountability left to contributors.

Related Posts:

The post Debian AI Policy: Responsible Generative AI Use Wins Vote appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw Do Son
    A public proof-of-concept for the CVE-2026-52933 privilege escalation flaw is available. This Linux kernel io_uring exploit carries a CVSS 7.8 score. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover The post PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • California Exempts Linux from Age Verification Do Son
    California passes AB-1856, exempting open-source operating systems like Linux from the burdensome age verification mandates of the Digital Age Assurance Act. Related Posts: Debian AI Policy: Responsible Generative AI Use Wins Vote Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes Framework Laptop 12: Upgraded with Intel Core Series 3 The post California Exempts Linux from Age Verification appeared first on Daily CyberSecurity.
     

California Exempts Linux from Age Verification

Por:Do Son
31 de Agosto de 2026, 04:55

California passes AB-1856, exempting open-source operating systems like Linux from the burdensome age verification mandates of the Digital Age Assurance Act.

Related Posts:

The post California Exempts Linux from Age Verification appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes Do Son
    Canonical releases Ubuntu 26.04.1 LTS, consolidating security patches and resolving critical desktop, hardware, and installation bugs for new deployments. Related Posts: Framework Laptop 12: Upgraded with Intel Core Series 3 WSL Ubuntu Installations Threaten Native Desktop Dominance Linux Kernel 7.2 Arrives with Extensive Updates The post Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes appeared first on Daily CyberSecurity.
     

Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes

Por:Do Son
28 de Agosto de 2026, 04:20

Canonical releases Ubuntu 26.04.1 LTS, consolidating security patches and resolving critical desktop, hardware, and installation bugs for new deployments.

Related Posts:

The post Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes appeared first on Daily CyberSecurity.

  • ✇Cyber Security News
  • CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks Abinaya
    The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks. The issue affects the Linux kernel’s IPv6 networking subsystem. It could allow a local attacker to gain elevated privileges on a vulnerable system. CVE-2026-53362 is currently described as an unspecified Linux kernel vulnerability. However, CI
     

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

28 de Agosto de 2026, 03:41

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks.

The issue affects the Linux kernel’s IPv6 networking subsystem. It could allow a local attacker to gain elevated privileges on a vulnerable system.

CVE-2026-53362 is currently described as an unspecified Linux kernel vulnerability. However, CISA said the flaw can enable privilege escalation through the IPv6 networking component.

Privilege escalation flaws are especially dangerous because an attacker with limited access to a Linux host may be able to obtain higher permissions, potentially including root-level control.

The vulnerability may affect Linux distributions and products that use the Linux kernel, including SUSE, Red Hat, and other vendor platforms.

Organizations should not assume that only these named distributions are affected, since the exposure depends on the kernel version, vendor build, configuration, and the availability of security fixes or mitigations.

Linux Kernel Privilege Escalation Vulnerability Exploited

CISA added CVE-2026-53362 to the catalog on August 27, 2026, and set a remediation deadline of August 30, 2026, for federal civilian executive branch agencies.

The agency has also marked the vulnerability as requiring forensic triage under Binding Operational Directive 26-04, indicating that affected organizations should assess whether exploitation has already occurred before or during patch application.

Although CISA has not linked the flaw to a specific ransomware operation, privilege-escalation vulnerabilities are often valuable to attackers once they have initial access.

A threat actor may exploit such weaknesses after gaining a foothold through stolen credentials, a vulnerable public-facing application, phishing, or a compromised cloud workload.

Elevated privileges can enable attackers to turn off security tools, access sensitive data, move laterally, and deploy ransomware across an environment.

CISA instructed organizations to apply mitigations in accordance with vendor guidance and to follow the risk-based security update requirements in BOD 26-04.

Where a vendor patch is unavailable, stakeholders should evaluate whether compensating controls can reduce exposure. CISA also stated that organizations should discontinue use of affected products if mitigations are not available.

Linux administrators should immediately identify internet-facing and business-critical systems running potentially affected kernel versions.

Security teams should review authentication activity, privilege changes, unexpected kernel-related errors, suspicious processes running as root, and endpoint detection alerts for signs of post-compromise activity.

Because details of exploitation remain limited, organizations should closely monitor updates from Linux distribution vendors and CISA.

The immediate priority is to determine which Linux assets rely on potentially affected kernels, apply vendor fixes, and conduct forensic triage on high-risk systems.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks appeared first on Cyber Security News.

  • ✇Cybersecurity News
  • CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution Do Son
    TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution appeared first on Daily C
     
  • ✇Cybersecurity News
  • Public PoC for CVE-2026-52923 Allows Attackers to Escalate to Root Privilege Do Son
    A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details. Related Posts: CVE-2026-77136: TYPO3 Powermail RCE Flaw Exploited in the Wild Weidmueller Router Flaw CVE-2026-63586 With CVSS 9.8 Allows Attackers To Execute Arbitrary Commands With Root Privileges Fake AI PoCs Flood Exploit Repositories in 2026 The post Public PoC for CVE-2026-52923 Allows Attackers to Escalate to Root Privilege appeared fi
     
  • ✇Cybersecurity News
  • Framework Laptop 12: Upgraded with Intel Core Series 3 Do Son
    Discover the new Framework Laptop 12 featuring Intel Core Series 3 processors, a 70 percent battery boost, and default Fedora Linux OS configuration. Related Posts: WSL Ubuntu Installations Threaten Native Desktop Dominance Linux Kernel 7.2 Arrives with Extensive Updates Tails 7.10.1 Fixes Critical Linux Kernel Vulnerability The post Framework Laptop 12: Upgraded with Intel Core Series 3 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • WSL Ubuntu Installations Threaten Native Desktop Dominance Do Son
    Canonical reveals that Ubuntu installations on the Windows Subsystem for Linux (WSL) are surging, soon surpassing native desktop deployments due to AI tools. Related Posts: Linux Kernel 7.2 Arrives with Extensive Updates Tails 7.10.1 Fixes Critical Linux Kernel Vulnerability Proxmox VE Formally Launches Arm64 Architecture Support The post WSL Ubuntu Installations Threaten Native Desktop Dominance appeared first on Daily CyberSecurity.
     

WSL Ubuntu Installations Threaten Native Desktop Dominance

Por:Do Son
18 de Agosto de 2026, 01:30

Canonical reveals that Ubuntu installations on the Windows Subsystem for Linux (WSL) are surging, soon surpassing native desktop deployments due to AI tools.

Related Posts:

The post WSL Ubuntu Installations Threaten Native Desktop Dominance appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Linux Kernel 7.2 Arrives with Extensive Updates Do Son
    Following extensive testing, Linux Kernel 7.2 is now available. Discover the latest updates regarding hardware drivers, file systems, and kernel security. Related Posts: WSL Ubuntu Installations Threaten Native Desktop Dominance Tails 7.10.1 Fixes Critical Linux Kernel Vulnerability Proxmox VE Formally Launches Arm64 Architecture Support The post Linux Kernel 7.2 Arrives with Extensive Updates appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • New Mirai-Based Evooo1Bot Botnet Targets Linux Devices Pierluigi Paganini
    Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module on top. “FortiGuard Labs has been tracking a pr
     

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

18 de Agosto de 2026, 04:18

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services.

Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module on top.

“FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.” reads the report published by Fortinet. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities.”

The botnet targets 18 known CVEs, some of them dating back to 2007, including:

  • CVE-2007-3010: Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
  • CVE-2016-6277: NETGEAR Multiple Routers Remote Code Execution Vulnerability
  • CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
  • CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
  • CVE-2020-10987: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
  • CVE-2021-46422: Telesquare SDT-CW3B1 Command Injection vulnerability
  • CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability
  • CVE-2024-29269, Telesquare TLR-2005KSH Command Injection Vulnerability
  • CVE-2025-10123, D-Link DIR-823X Command Injection Vulnerability
  • CVE-2025-55583: D-Link DIR-868L B1 router Command Injection Vulnerability

The bot communicates exclusively over port 443, which is intentional: the traffic blends into expected HTTPS flows at the network perimeter. After gaining initial access through one of its exploit modules or via brute-forced SSH credentials, the bot runs a loader script that clears Bash history to erase evidence of the intrusion before pulling the architecture-appropriate binary from an external server.

The breadth suggests the operators are scanning opportunistically for anything unpatched rather than targeting specific organizations.

“This capability significantly increases the value of an infected host to attackers. The victim’s IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine.” continues the report. “In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services.”

Evooo1Bot stands out because of its proxy module. A network of compromised routers, cameras, and firewalls acting as SOCKS5 relays is a valuable commodity; operators can use it themselves to obscure attack traffic, or sell access to other criminals looking for residential or enterprise IP addresses that don’t trigger geographic blocks.

“Unlike typical botnet commands that focus on downloading payloads or launching attacks, the !socks module turns an infected host into a SOCKS5 proxy that the operator can use as a network relay. It supports two operating modes. In direct mode, it opens a SOCKS5 listener on the infected host on the default TCP port 1080 and waits for incoming client connections. The implementation first attempts to create a dual-stack IPv6 listener and falls back to IPv4 if that fails. Each accepted client is then passed to the session handler for proxying.” continues the report. “The botnet also implements a reverse relay mode. Instead of exposing a listening port, the bot establishes an outbound encrypted connection to an operator-specified relay server. This persistent control channel listens for commands such as RELAY_NEW:<session_id>, which indicate that a new proxy session should be created.”

After establishing C2 contact, the bot accepts commands covering the full post-compromise toolkit: file upload and download, interactive shell access, persistence installation, binary updates, HTTP Basic Auth and Cookie header interception, DDoS over DNS, TCP, and UDP, and the HTTP exploit dispatcher.

The credential sniffer intercepts authentication headers in transit, so any HTTP Basic Auth credentials passing through an infected device can be captured without any additional effort from the operator. If you’re still running devices with unpatched firmware from the CVE list above, or if any of your edge hardware is using default SSH credentials, Evooo1Bot is already scanning for you.

“Beyond traditional botnet functionality, it features encrypted C2 communications, multiple layers of string obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation, as well as a 28-command remote administration interface.” concludes the report. “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Evooo1Bot botnet)

  • ✇Cybersecurity News
  • ChatGPT for Linux Desktop Preview Launches for Ubuntu, Debian, and Fedora Do Son
    OpenAI launches ChatGPT for Linux desktop in preview, supporting Ubuntu, Debian, and Fedora with ChatGPT, Codex, and Work features. Related Posts: Apple Proposes New App Store Link-Out Fees of 5% to 15% in Epic Legal Battle Microsoft Copilot Super App: A Unified Platform Vision Mozilla Rotates Firefox and Thunderbird Linux GPG Signing Key After Private Repo Exposure The post ChatGPT for Linux Desktop Preview Launches for Ubuntu, Debian, and Fedora appeared first on Daily CyberSecurity.
     
  • ✇Cyber Security News
  • CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges Abinaya
    A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux host with root privileges. The issue affects KVM/x86, a virtualization technology that separates guest systems from the physical server. The flaw is especially serious for cloud providers and enterprises that run untrusted workloads. Zapscape was discovered by security researcher Hyunwoo Kim, known as V4bel. It exists in
     

CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges

7 de Agosto de 2026, 10:32

A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux host with root privileges.

The issue affects KVM/x86, a virtualization technology that separates guest systems from the physical server. The flaw is especially serious for cloud providers and enterprises that run untrusted workloads.

Zapscape was discovered by security researcher Hyunwoo Kim, known as V4bel. It exists in KVM’s shadow memory management unit, or shadow MMU. It manages memory translations when nested virtualization is used.

Nested virtualization allows one virtual machine to run another virtual machine inside it. While useful for testing and cloud services, it creates a larger attack surface.

The vulnerability is a use-after-free bug in the recursive zap path used by KVM when reclaiming shadow pages. In simple terms, KVM can free a memory structure but later continue to use it.

Zapscape KVM Escape Grants Root Access

A malicious guest can trigger that unsafe condition from inside the guest. This can corrupt memory in the host kernel, breaking the security boundary that normally keeps a guest separate from its host.

A successful attack could have severe consequences. An attacker with kernel-level control in an L1 guest may execute commands on the KVM host as root.

That could allow data theft, service disruption, access to other virtual machines on the same server, or host control. In shared cloud environments, one compromised tenant instance could therefore put other customers at risk.

A proof-of-concept published on GitHub demonstrates the escape chain in a controlled QEMU TCG environment, resulting in a root-owned file on the host.

The researcher said it is not a ready-made cloud attack, but warned that adapting it to a real environment would not be difficult. Organizations should treat the availability of public exploits as an urgent patching signal.

The affected code was introduced in 2020 and was fixed upstream in Linux commit 2abd5287f083 on July 21, 2026. The patch changes the validation order in the shadow MMU fault path.

KVM now checks whether a root page became invalid after it makes MMU pages available. If the page was reclaimed, KVM retries the fault rather than continuing to use the invalid structure.

Risk is highest where nested virtualization is exposed to untrusted users. Guest root access is generally required for the documented escape route, which is common in infrastructure-as-a-service deployments.

Intel environments face an additional condition: both four-level and five-level EPT page-walk support must be exposed to the L1 guest. AMD systems do not have that stated condition.

Administrators should promptly install a vendor kernel containing the upstream fix and reboot affected KVM hosts. Until patching is complete, teams should disable nested virtualization for untrusted guests where operationally possible.

They should also restrict access to /dev/kvm, review host configurations, identify exposed multi-tenant systems, and monitor vendor advisories.

Zapscape shows that hypervisor patch management is essential: a single guest escape can undermine isolation across an entire server.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges appeared first on Cyber Security News.

❌
❌