Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its…
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its…
The public exploit for CVE-2026-53264 was demonstrated on CentOS Stream 9, requiring specific kernel configurations and unprivileged user namespaces. Users should apply…
DevMan ransomware is a locker that targets Windows, ESXi, and Linux systems. It uses ChaCha20-Poly1305 encryption, fully encrypting files up to 3…
The operators of the DevMan ransomware-as-a-service (RaaS) scheme maintain a dedicated web platform that offers affiliates the ability to build payloads, oversee…
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as root on…
Cybersecurity researchers at Accomplish AI have disclosed a sandbox escape vulnerability in Anthropic's Claude Cowork, tracked as SharedRoot, that allows an AI…
A critical Linux kernel vulnerability, tracked as CVE-2026-64600 and named RefluXFS, has been disclosed by Qualys. The flaw, present in Linux kernels…
A Linux distribution by the Fedora Project, affected by CVE-2026-64600. Default installations with reflink-enabled XFS are vulnerable.
A Linux distribution by Amazon Web Services, affected by CVE-2026-64600. Default installations with reflink-enabled XFS are vulnerable.
Cybersecurity researchers have disclosed a high-severity local privilege escalation (LPE) vulnerability in snap-confine, tracked as CVE-2026-8933 (CVSS score: 7.8), that allows an…