#rootkit — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rootkit, aggregated by home.social.
-
CoolClient backdoor goes deeper: Windows kernel rootkit added
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.
Pulse ID: 6a7ef2da146fb06724520eb4
Pulse Link: https://otx.alienvault.com/pulse/6a7ef2da146fb06724520eb4
Pulse Author: AlienVault
Created: 2026-08-14 10:50:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault
-
CoolClient backdoor goes deeper: Windows kernel rootkit added
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.
Pulse ID: 6a7ef2da146fb06724520eb4
Pulse Link: https://otx.alienvault.com/pulse/6a7ef2da146fb06724520eb4
Pulse Author: AlienVault
Created: 2026-08-14 10:50:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7beecb020ccbfd7b706fad
Pulse Link: https://otx.alienvault.com/pulse/6a7beecb020ccbfd7b706fad
Pulse Author: CyberHunter_NL
Created: 2026-08-12 03:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL
-
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7beecb020ccbfd7b706fad
Pulse Link: https://otx.alienvault.com/pulse/6a7beecb020ccbfd7b706fad
Pulse Author: CyberHunter_NL
Created: 2026-08-12 03:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL
-
Reversing a Windows Kernel Driver Rootkit
Pulse ID: 6a717c19f73dc4fe90461760
Pulse Link: https://otx.alienvault.com/pulse/6a717c19f73dc4fe90461760
Pulse Author: Tr1sa111
Created: 2026-08-04 05:43:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rootkit #Windows #bot #Tr1sa111
-
Reversing a Windows Kernel Driver Rootkit
Pulse ID: 6a717c19f73dc4fe90461760
Pulse Link: https://otx.alienvault.com/pulse/6a717c19f73dc4fe90461760
Pulse Author: Tr1sa111
Created: 2026-08-04 05:43:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rootkit #Windows #bot #Tr1sa111
-
Reversing a Windows Kernel Driver Rootkit
A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24.
Pulse ID: 6a7059a9cb9e82a2a574651c
Pulse Link: https://otx.alienvault.com/pulse/6a7059a9cb9e82a2a574651c
Pulse Author: AlienVault
Created: 2026-08-03 09:04:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CobaltStrike #CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #Rootkit #Windows #bot #AlienVault
-
Reversing a Windows Kernel Driver Rootkit
A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24.
Pulse ID: 6a7059a9cb9e82a2a574651c
Pulse Link: https://otx.alienvault.com/pulse/6a7059a9cb9e82a2a574651c
Pulse Author: AlienVault
Created: 2026-08-03 09:04:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CobaltStrike #CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #Rootkit #Windows #bot #AlienVault
-
Breaking eBPF Security: How Kernel Rootkits Blind Observability Tools | 0xMatheuZ
https://matheuzsecurity.github.io/hacking/ebpf-security-tools-hacking/
> Deep technical analysis of bypassing eBPF-based security solutions through kernel-level hooks targeting BPF iterators, ringbuffers, and perf events
-
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.
Pulse ID: 6a5775d3b8fe983226594b7c
Pulse Link: https://otx.alienvault.com/pulse/6a5775d3b8fe983226594b7c
Pulse Author: AlienVault
Created: 2026-07-15 11:58:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #China #CyberSecurity #InfoSec #Malware #Manufacturing #OTX #OpenThreatExchange #RAT #Rootkit #TCP #Trojan #Windows #bot #AlienVault
-
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.
Pulse ID: 6a5775d3b8fe983226594b7c
Pulse Link: https://otx.alienvault.com/pulse/6a5775d3b8fe983226594b7c
Pulse Author: AlienVault
Created: 2026-07-15 11:58:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #China #CyberSecurity #InfoSec #Malware #Manufacturing #OTX #OpenThreatExchange #RAT #Rootkit #TCP #Trojan #Windows #bot #AlienVault
-
A friendly reminder: Don't be afraid of #Linux #rootkits.
I have just released version 0.3.0 of rk-expose, a modern self-contained #rootkit detection tool that uses several techniques to detect signs of process hiding, file hiding, file content tampering from kernel or user space and can be used for hunting in large, diverse environments. rk-expose is written in #Rust.
Notable changes include:
- Clearer output format
- Generic improvements to process hiding detection to avoid false positives
- Improvements to cgroupfs process hiding detections
- A Velociraptor artifact
- An "auto" subcommand that runs checks using sensible defaults and interprets results
-
A friendly reminder: Don't be afraid of #Linux #rootkits.
I have just released version 0.3.0 of rk-expose, a modern self-contained #rootkit detection tool that uses several techniques to detect signs of process hiding, file hiding, file content tampering from kernel or user space and can be used for hunting in large, diverse environments. rk-expose is written in #Rust.
Notable changes include:
- Clearer output format
- Generic improvements to process hiding detection to avoid false positives
- Improvements to cgroupfs process hiding detections
- A Velociraptor artifact
- An "auto" subcommand that runs checks using sensible defaults and interprets results
-
Detect and unhook SSDT entries using Volatility 2's ssdt plugin. Compares current pointers to KiServiceTable base, overwrites hooked addresses with clean kernel values. Supports Win7 SP1 x64 to Win10 1903. #volatility #ssdt #rootkit #ValtersIT
https://www.valtersit.com/vault/ssdt-hook-detection-with-unhooking-via-volatility-2-29fff0/
-
Don't be afraid of the #rootkit bit of the malicious bonus material that shipped with some #ArchLinux #AUR packages recently , it is not really hard to detect in a generic way.
In the past few months I had been doing some research on #Linux #rootkits and figured out some techniques I hadn't seen implemented before. Since existing tools seemed inadequate for hunting for rootkits in large, diverse environments, I wrote rk-expose which compiles to a smallish (<1MB) static binary. It comes with lots of well-known and some novel rootkit detection techniques – and detects the malware distributed with the "atomic arch" campaign using its "ps-diff" command out of the box.
-
Don't be afraid of the #rootkit bit of the malicious bonus material that shipped with some #ArchLinux #AUR packages recently , it is not really hard to detect in a generic way.
In the past few months I had been doing some research on #Linux #rootkits and figured out some techniques I hadn't seen implemented before. Since existing tools seemed inadequate for hunting for rootkits in large, diverse environments, I wrote rk-expose which compiles to a smallish (<1MB) static binary. It comes with lots of well-known and some novel rootkit detection techniques – and detects the malware distributed with the "atomic arch" campaign using its "ps-diff" command out of the box.
-
Господа арчеводы (и арчебейздоводы на Manjaro, CachyOS, EdeavourOS, etc), вам там подвезли добра в AUR:
https://ioctl.fail/preliminary-analysis-of-aur-malware/
TL;DR: в ~400+ пакетов (о которых известно на данный момент) в AUR добавили малварь, которая ворует креды и имеет встроенный руткит.
Если недавно (несколько дней) обновлялись из AUR не вычитывая сорцы пакетов - стоит напрячься.Вот тут есть список пакетов, о которых известно:
https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/ -
Господа арчеводы (и арчебейздоводы на Manjaro, CachyOS, EdeavourOS, etc), вам там подвезли добра в AUR:
https://ioctl.fail/preliminary-analysis-of-aur-malware/
TL;DR: в ~400+ пакетов (о которых известно на данный момент) в AUR добавили малварь, которая ворует креды и имеет встроенный руткит.
Если недавно (несколько дней) обновлялись из AUR не вычитывая сорцы пакетов - стоит напрячься.Вот тут есть список пакетов, о которых известно:
https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/ -
Over 400 #ArchLinux packages compromised to push #rootkit, #infostealer
-
Over 400 #ArchLinux packages compromised to push #rootkit, #infostealer
-
Erst vor zwei Tagen #Manuskript installiert, war darin bereits ein Übeltäter versteckt. Das #bash-Skript legte dies offen. Eine erste Überprüfung lies nicht erkennen, dass die eigentliche #Backdoor schon nachgeladen wurde und aktiv ist. Ich wollte nun mit #ClamAV sicher gehen, doch die Installation ist mir viel zu kompliziert. Daran scheitere ich kläglich.
Schon Schade auf Sicherheit zu verzichten, weil deren Nutzung maximal erschwert wird.
#Arch #Linux #ArchLinux #AUR #Rootkit
https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
-
Erst vor zwei Tagen #Manuskript installiert, war darin bereits ein Übeltäter versteckt. Das #bash-Skript legte dies offen. Eine erste Überprüfung lies nicht erkennen, dass die eigentliche #Backdoor schon nachgeladen wurde und aktiv ist. Ich wollte nun mit #ClamAV sicher gehen, doch die Installation ist mir viel zu kompliziert. Daran scheitere ich kläglich.
Schon Schade auf Sicherheit zu verzichten, weil deren Nutzung maximal erschwert wird.
#Arch #Linux #ArchLinux #AUR #Rootkit
https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
-
AUR Packages Compromised with Infostealer and Rootkit
https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
#HackerNews #AUR #Packages #Compromised #Infostealer #Rootkit #Cybersecurity #Vulnerabilities
-
AUR Packages Compromised with Infostealer and Rootkit
https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
#HackerNews #AUR #Packages #Compromised #Infostealer #Rootkit #Cybersecurity #Vulnerabilities
-
@buffyleigh @jepyang Those were the days, when Sony tried slipping their #rootkit into their CDs and everybody was like FUCK NO! And they had to back off bc nobody was buying that shit
-
@buffyleigh @jepyang Those were the days, when Sony tried slipping their #rootkit into their CDs and everybody was like FUCK NO! And they had to back off bc nobody was buying that shit
-
Android-Rootkit „NoVoice“: Über 50 Play-Store-Apps kompromittierten Millionen Geräte
Achtphasiger Angriffsprozess
Die als „Operation NoVoice“ bezeichnete Kampagne nutzte 22 bekannte Sicherheitslücken aus, erlangte Root-Rechte auf betroffenen Geräten und war in der Lage, WhatsApp-Sitzungen vollständig zu klonen.
-
Mensch lädt sich eine "harmlose App" im PlayStore herunter – vielleicht einen SystemCleaner, Taschenrechner oder eine Wettervorhersage. Doch im Hintergrund öffnet sich eine Backdoor, durch die Cyberkriminelle nicht nur die Daten stehlen, sondern die komplette Kontrolle über das Smartphone übernehmen. Genau das passierte jetzt mit dem und durch das „NoVoice"-Rootkit,
Mehr dazu: https://digiprax.maniabel.work/archiv/1168
#novoice #rootkit #infosec #android #Google #PlayStore #up2date
-
Как работают руткиты и можно ли им противодействовать на примере Singularity
Всем привет. Экспрементируя со способами закрепления на Linux системах в рамках разработки своей системы мониторига безопасности, я наткнулся на руткит с открытым исходным кодом Singularity . Он показался мне очень интересным, так как использует большое количество методов для сокрытия себя от обнаружения, а открытый исходный исходный код позволяет досконально изучить эти методы. В данной статье я подробно расскажу вам, с помощью каких подходов руткиты закрепляются на Linux системах на примере Singularity.
https://habr.com/ru/articles/996568/
#rootkit #rootkits #руткиты #руткит #ядро_linux #мониторинг #ebpf #обнаружение_атак #информационная_безопасность #защита_сервера
-
Проект Singularity развивает открытый руткит, обходящий SELinux, Netfilter, LKRG и eBPF
#infosec #singularity #rootkit #floss
https://www.opennet.ru/opennews/art.shtml?num=64663
> Матеус Алвес ( Matheus Alves ), исследователь безопасности, специализирующийся на вредоносном ПО, опубликовал обновление проекта Singularity , развивающего открытый руткит для ядра Linux, распространяемый под лицензией MIT.
Целью проекта является демонстрация методов, позволяющих скрыть своё присутствие после получения root-доступа и сохранить возможность скрытого выполнения привилегированных операций. Предполагается, что Singularity может быть полезен исследователям безопасности для тестирования и разработки утилит обнаружения и блокирования руткитов
-
Questo #rootkit #Linux è open source (e serve a capire perché i sistemi di difesa falliscono)
https://go.squidapp.co/n/iW7sXS9 -
🎉 Ah yes, the revolution we've all been waiting for: a #rootkit for #Linux that lets hackers live their "open-source dreams" too! 🙃 Who wouldn't want to give malicious actors a chance to show off their coding skills in the name of freedom? 🤦♂️ Let's all celebrate with a round of applause for #security nightmares! 👏
https://lwn.net/SubscriberLink/1053099/19c2e8180aeb0438/ #open-source #nightmares #hacking #HackerNews #ngated -
🎉 Ah yes, the revolution we've all been waiting for: a #rootkit for #Linux that lets hackers live their "open-source dreams" too! 🙃 Who wouldn't want to give malicious actors a chance to show off their coding skills in the name of freedom? 🤦♂️ Let's all celebrate with a round of applause for #security nightmares! 👏
https://lwn.net/SubscriberLink/1053099/19c2e8180aeb0438/ #open-source #nightmares #hacking #HackerNews #ngated -
A free and open-source rootkit for Linux
https://lwn.net/SubscriberLink/1053099/19c2e8180aeb0438/
#HackerNews #freeopensource #rootkit #Linux #cybersecurity #open-source
-
A free and open-source rootkit for Linux
https://lwn.net/SubscriberLink/1053099/19c2e8180aeb0438/
#HackerNews #freeopensource #rootkit #Linux #cybersecurity #open-source
-
🥳 Oh look, yet another ✨ "stealthy" ✨ #rootkit trying to make #Linux less secure! Because who doesn't love a good kernel bypass party? 🎉 GitHub's just thrilled to add "invisible chaos" to its menu of developer delights! 😂
https://github.com/MatheuZSecurity/Singularity #Security #KernelBreach #GitHub #Chaos #HackerNews #ngated