ClientKing: Rust Implant for Linux and Routers
ClientKing is a Rust implant used by Jewelbug that targets Linux servers and routers. It uses five C&C channels, including a DNS…
ClientKing is a Rust implant used by Jewelbug that targets Linux servers and routers. It uses five C&C channels, including a DNS…
The China-linked threat actor known as Jewelbug has been observed conducting cyber espionage against governments and militaries while simultaneously running a cryptocurrency…
Mozilla has revoked the cryptographic signing key used for Firefox and Thunderbird downloads on Linux after an unencrypted copy of the key…
Thunderbird for Linux is affected by the revocation of Mozilla's signing key. Users who manually verify signatures must import the new key…
Sliver, an open-source command-and-control (C2) framework, is deployed as the final payload on Linux systems in the malicious npm campaign. The Linux…
A use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and named SCTPhantom, could allow local users to gain root privileges…
The Linux kernel's SCTP implementation contains a use-after-free flaw (CVE-2026-64564) that can be exploited for local privilege escalation and container escape. Patches…
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its…
The public exploit for CVE-2026-53264 was demonstrated on CentOS Stream 9, requiring specific kernel configurations and unprivileged user namespaces. Users should apply…
DevMan ransomware is a locker that targets Windows, ESXi, and Linux systems. It uses ChaCha20-Poly1305 encryption, fully encrypting files up to 3…