home.social

#rootkit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rootkit, aggregated by home.social.

fetched live
  1. CoolClient backdoor goes deeper: Windows kernel rootkit added

    HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.

    Pulse ID: 6a7ef2da146fb06724520eb4
    Pulse Link: otx.alienvault.com/pulse/6a7ef
    Pulse Author: AlienVault
    Created: 2026-08-14 10:50:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault

  2. CoolClient backdoor goes deeper: Windows kernel rootkit added

    HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.

    Pulse ID: 6a7ef2da146fb06724520eb4
    Pulse Link: otx.alienvault.com/pulse/6a7ef
    Pulse Author: AlienVault
    Created: 2026-08-14 10:50:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault

  3. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

    Indicators extracted from public reporting. Source: securelist.com/honeymyte-coolc

    Pulse ID: 6a7ee620d0cfd8859d00dfd9
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 09:55:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL

  4. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

    Indicators extracted from public reporting. Source: securelist.com/honeymyte-coolc

    Pulse ID: 6a7ee620d0cfd8859d00dfd9
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 09:55:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL

  5. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  6. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  7. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  8. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  9. Reversing a Windows Kernel Driver Rootkit

    Pulse ID: 6a717c19f73dc4fe90461760
    Pulse Link: otx.alienvault.com/pulse/6a717
    Pulse Author: Tr1sa111
    Created: 2026-08-04 05:43:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rootkit #Windows #bot #Tr1sa111

  10. Reversing a Windows Kernel Driver Rootkit

    Pulse ID: 6a717c19f73dc4fe90461760
    Pulse Link: otx.alienvault.com/pulse/6a717
    Pulse Author: Tr1sa111
    Created: 2026-08-04 05:43:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rootkit #Windows #bot #Tr1sa111

  11. Reversing a Windows Kernel Driver Rootkit

    A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24.

    Pulse ID: 6a7059a9cb9e82a2a574651c
    Pulse Link: otx.alienvault.com/pulse/6a705
    Pulse Author: AlienVault
    Created: 2026-08-03 09:04:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CobaltStrike #CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #Rootkit #Windows #bot #AlienVault

  12. Reversing a Windows Kernel Driver Rootkit

    A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24.

    Pulse ID: 6a7059a9cb9e82a2a574651c
    Pulse Link: otx.alienvault.com/pulse/6a705
    Pulse Author: AlienVault
    Created: 2026-08-03 09:04:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CobaltStrike #CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #Rootkit #Windows #bot #AlienVault

  13. Breaking eBPF Security: How Kernel Rootkits Blind Observability Tools | 0xMatheuZ

    matheuzsecurity.github.io/hack

    > Deep technical analysis of bypassing eBPF-based security solutions through kernel-level hooks targeting BPF iterators, ringbuffers, and perf events

    #eBPF #security #Linux #kernel #rootkit #observabilty

  14. Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

    Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.

    Pulse ID: 6a5775d3b8fe983226594b7c
    Pulse Link: otx.alienvault.com/pulse/6a577
    Pulse Author: AlienVault
    Created: 2026-07-15 11:58:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #China #CyberSecurity #InfoSec #Malware #Manufacturing #OTX #OpenThreatExchange #RAT #Rootkit #TCP #Trojan #Windows #bot #AlienVault

  15. Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

    Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.

    Pulse ID: 6a5775d3b8fe983226594b7c
    Pulse Link: otx.alienvault.com/pulse/6a577
    Pulse Author: AlienVault
    Created: 2026-07-15 11:58:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #China #CyberSecurity #InfoSec #Malware #Manufacturing #OTX #OpenThreatExchange #RAT #Rootkit #TCP #Trojan #Windows #bot #AlienVault

  16. A friendly reminder: Don't be afraid of #Linux #rootkits.

    I have just released version 0.3.0 of rk-expose, a modern self-contained #rootkit detection tool that uses several techniques to detect signs of process hiding, file hiding, file content tampering from kernel or user space and can be used for hunting in large, diverse environments. rk-expose is written in #Rust.

    Notable changes include:

    • Clearer output format
    • Generic improvements to process hiding detection to avoid false positives
    • Improvements to cgroupfs process hiding detections
    • A Velociraptor artifact
    • An "auto" subcommand that runs checks using sensible defaults and interprets results
  17. A friendly reminder: Don't be afraid of #Linux #rootkits.

    I have just released version 0.3.0 of rk-expose, a modern self-contained #rootkit detection tool that uses several techniques to detect signs of process hiding, file hiding, file content tampering from kernel or user space and can be used for hunting in large, diverse environments. rk-expose is written in #Rust.

    Notable changes include:

    • Clearer output format
    • Generic improvements to process hiding detection to avoid false positives
    • Improvements to cgroupfs process hiding detections
    • A Velociraptor artifact
    • An "auto" subcommand that runs checks using sensible defaults and interprets results
  18. Detect and unhook SSDT entries using Volatility 2's ssdt plugin. Compares current pointers to KiServiceTable base, overwrites hooked addresses with clean kernel values. Supports Win7 SP1 x64 to Win10 1903. #volatility #ssdt #rootkit #ValtersIT

    valtersit.com/vault/ssdt-hook-

  19. Don't be afraid of the #rootkit bit of the malicious bonus material that shipped with some #ArchLinux #AUR packages recently , it is not really hard to detect in a generic way.

    In the past few months I had been doing some research on #Linux #rootkits and figured out some techniques I hadn't seen implemented before. Since existing tools seemed inadequate for hunting for rootkits in large, diverse environments, I wrote rk-expose which compiles to a smallish (<1MB) static binary. It comes with lots of well-known and some novel rootkit detection techniques – and detects the malware distributed with the "atomic arch" campaign using its "ps-diff" command out of the box.

  20. Don't be afraid of the #rootkit bit of the malicious bonus material that shipped with some #ArchLinux #AUR packages recently , it is not really hard to detect in a generic way.

    In the past few months I had been doing some research on #Linux #rootkits and figured out some techniques I hadn't seen implemented before. Since existing tools seemed inadequate for hunting for rootkits in large, diverse environments, I wrote rk-expose which compiles to a smallish (<1MB) static binary. It comes with lots of well-known and some novel rootkit detection techniques – and detects the malware distributed with the "atomic arch" campaign using its "ps-diff" command out of the box.

  21. Господа арчеводы (и арчебейздоводы на Manjaro, CachyOS, EdeavourOS, etc), вам там подвезли добра в AUR:

    https://ioctl.fail/preliminary-analysis-of-aur-malware/

    TL;DR: в ~400+ пакетов (о которых известно на данный момент) в AUR добавили малварь, которая ворует креды и имеет встроенный руткит.
    Если недавно (несколько дней) обновлялись из AUR не вычитывая сорцы пакетов - стоит напрячься.

    Вот тут есть список пакетов, о которых известно:
    https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

    @rf
    #Linux #Arch #AUR #security #malware #rootkit #news

  22. Господа арчеводы (и арчебейздоводы на Manjaro, CachyOS, EdeavourOS, etc), вам там подвезли добра в AUR:

    https://ioctl.fail/preliminary-analysis-of-aur-malware/

    TL;DR: в ~400+ пакетов (о которых известно на данный момент) в AUR добавили малварь, которая ворует креды и имеет встроенный руткит.
    Если недавно (несколько дней) обновлялись из AUR не вычитывая сорцы пакетов - стоит напрячься.

    Вот тут есть список пакетов, о которых известно:
    https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

    @rf
    #Linux #Arch #AUR #security #malware #rootkit #news

  23. Erst vor zwei Tagen #Manuskript installiert, war darin bereits ein Übeltäter versteckt. Das #bash-Skript legte dies offen. Eine erste Überprüfung lies nicht erkennen, dass die eigentliche #Backdoor schon nachgeladen wurde und aktiv ist. Ich wollte nun mit #ClamAV sicher gehen, doch die Installation ist mir viel zu kompliziert. Daran scheitere ich kläglich.

    Schon Schade auf Sicherheit zu verzichten, weil deren Nutzung maximal erschwert wird.

    #Arch #Linux #ArchLinux #AUR #Rootkit

    discourse.ifin.network/t/400-a

  24. Erst vor zwei Tagen #Manuskript installiert, war darin bereits ein Übeltäter versteckt. Das #bash-Skript legte dies offen. Eine erste Überprüfung lies nicht erkennen, dass die eigentliche #Backdoor schon nachgeladen wurde und aktiv ist. Ich wollte nun mit #ClamAV sicher gehen, doch die Installation ist mir viel zu kompliziert. Daran scheitere ich kläglich.

    Schon Schade auf Sicherheit zu verzichten, weil deren Nutzung maximal erschwert wird.

    #Arch #Linux #ArchLinux #AUR #Rootkit

    discourse.ifin.network/t/400-a

  25. QLNX: Neuer Remote-Access-Trojaner zielt auf Linux-Entwickler

    Hinter Quasar Linux (QLNX) steckt kein Betriebssystem, sondern ein Supply-Chain-Angriffstool, das sich nur schwer erkennen und entfernen lässt.

    heise.de/news/QLNX-Neuer-Remot

    #DevOps #IT #Linux #Malware #Rootkit #Security #Trojaner #news

  26. QLNX: Neuer Remote-Access-Trojaner zielt auf Linux-Entwickler

    Hinter Quasar Linux (QLNX) steckt kein Betriebssystem, sondern ein Supply-Chain-Angriffstool, das sich nur schwer erkennen und entfernen lässt.

    heise.de/news/QLNX-Neuer-Remot

    #DevOps #IT #Linux #Malware #Rootkit #Security #Trojaner #news

  27. @buffyleigh @jepyang Those were the days, when Sony tried slipping their #rootkit into their CDs and everybody was like FUCK NO! And they had to back off bc nobody was buying that shit

  28. @buffyleigh @jepyang Those were the days, when Sony tried slipping their #rootkit into their CDs and everybody was like FUCK NO! And they had to back off bc nobody was buying that shit

  29. Android-Rootkit „NoVoice“: Über 50 Play-Store-Apps kompromittierten Millionen Geräte

    Achtphasiger Angriffsprozess

    Die als „Operation NoVoice“ bezeichnete Kampagne nutzte 22 bekannte Sicherheitslücken aus, erlangte Root-Rechte auf betroffenen Geräten und war in der Lage, WhatsApp-Sitzungen vollständig zu klonen.

    all-about-security.de/android-

    #android #rootkit #whatsapp #googleplay

  30. Mensch lädt sich eine "harmlose App" im PlayStore herunter – vielleicht einen SystemCleaner, Taschenrechner oder eine Wettervorhersage. Doch im Hintergrund öffnet sich eine Backdoor, durch die Cyberkriminelle nicht nur die Daten stehlen, sondern die komplette Kontrolle über das Smartphone übernehmen. Genau das passierte jetzt mit dem und durch das „NoVoice"-Rootkit,

    Mehr dazu: digiprax.maniabel.work/archiv/

    #novoice #rootkit #infosec #android #Google #PlayStore #up2date

  31. Как работают руткиты и можно ли им противодействовать на примере Singularity

    Всем привет. Экспрементируя со способами закрепления на Linux системах в рамках разработки своей системы мониторига безопасности, я наткнулся на руткит с открытым исходным кодом Singularity . Он показался мне очень интересным, так как использует большое количество методов для сокрытия себя от обнаружения, а открытый исходный исходный код позволяет досконально изучить эти методы. В данной статье я подробно расскажу вам, с помощью каких подходов руткиты закрепляются на Linux системах на примере Singularity.

    habr.com/ru/articles/996568/

    #rootkit #rootkits #руткиты #руткит #ядро_linux #мониторинг #ebpf #обнаружение_атак #информационная_безопасность #защита_сервера

  32. Проект Singularity развивает открытый руткит, обходящий SELinux, Netfilter, LKRG и eBPF

    #infosec #singularity #rootkit #floss

    opennet.ru/opennews/art.shtml?

    > Матеус Алвес ( Matheus Alves ), исследователь безопасности, специализирующийся на вредоносном ПО, опубликовал обновление проекта Singularity , развивающего открытый руткит для ядра Linux, распространяемый под лицензией MIT.

    Целью проекта является демонстрация методов, позволяющих скрыть своё присутствие после получения root-доступа и сохранить возможность скрытого выполнения привилегированных операций. Предполагается, что Singularity может быть полезен исследователям безопасности для тестирования и разработки утилит обнаружения и блокирования руткитов

  33. 🎉 Ah yes, the revolution we've all been waiting for: a #rootkit for #Linux that lets hackers live their "open-source dreams" too! 🙃 Who wouldn't want to give malicious actors a chance to show off their coding skills in the name of freedom? 🤦‍♂️ Let's all celebrate with a round of applause for #security nightmares! 👏
    lwn.net/SubscriberLink/1053099 #open-source #nightmares #hacking #HackerNews #ngated

  34. 🎉 Ah yes, the revolution we've all been waiting for: a #rootkit for #Linux that lets hackers live their "open-source dreams" too! 🙃 Who wouldn't want to give malicious actors a chance to show off their coding skills in the name of freedom? 🤦‍♂️ Let's all celebrate with a round of applause for #security nightmares! 👏
    lwn.net/SubscriberLink/1053099 #open-source #nightmares #hacking #HackerNews #ngated

  35. 🥳 Oh look, yet another ✨ "stealthy" ✨ #rootkit trying to make #Linux less secure! Because who doesn't love a good kernel bypass party? 🎉 GitHub's just thrilled to add "invisible chaos" to its menu of developer delights! 😂
    github.com/MatheuZSecurity/Sin #Security #KernelBreach #GitHub #Chaos #HackerNews #ngated