NatJack NAT Attack Hijacks TCP Sessions and Spoofs DNS
August 6, 2026 Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation connection state to hijack active TCP sessions, spoof DNS responses, and disclose victim IP addresses and mapped…
RefluXFS CVE: Nine-Year-Old Linux Kernel Flaw Grants Root
July 23, 2026 A nine-year-old race condition in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on disk and gain persistent root access. The flaw, dubbed RefluXFS by Qualys,…
Arch Linux AUR Supply Chain Attack: 400+ Packages Hijacked with Rootkit and Infostealer
June 12, 2026 Attackers hijacked more than 400 packages in the Arch Linux community repository this week. Furthermore, the malicious build scripts installed a Rust credential stealer and an optional eBPF rootkit on developer workstations. This Arch Linux…
Miasma Supply Chain Attack: Red Hat npm Packages Compromised
June 01, 2026 A new supply chain attack campaign codenamed Miasma has compromised multiple @redhat-cloud-services npm packages. The attack steals developer credentials and CI/CD secrets through install-time malware. It also delivers a self-propagating…
CIFSwitch Linux Flaw Grants Root Access on Major Distros
May 30, 2026 A newly discovered Linux kernel privilege escalation vulnerability named CIFSwitch allows local attackers to forge CIFS authentication key descriptions, abuse the kernel’s key request mechanism, and gain root privileges on multiple…
Apache HTTP Server Double-Free Vulnerability
May 10, 2026 The Apache Software Foundation released an emergency security patch on May 5, 2026, to address CVE-2026-23918, a critical HTTP/2 double-free vulnerability in the Apache HTTP Server that enables remote code execution (RCE). With a CVSS v3.1…
Dirty Frag Linux Kernel Vulnerability Grants Root Access
May 8, 2026 A critical local privilege escalation vulnerability known as Dirty Frag (CVE-2026-43284) has been disclosed, affecting the Linux kernel’s xfrm-ESP subsystem. First reported to the Linux kernel maintainers on April 30, 2026, this…