A disclosed bypass tied to the Singularity Linux rootkit shows how module-load visibility, not just files or processes, can become the first thing attackers try to silence.
A research demo against Elastic Defend highlights a harder problem for Linux security: if the kernel telemetry path can be tampered with, the alert may never fire.
Researchers say the group is using AI to scale attacks against Windows and Linux web servers, while SPECTRE adds kernel-level stealth that can make defense far harder once a foothold exists.
A weekly threat roundup points to a harder problem for defenders: intrusions that try to blend into the systems, accounts, and workflows people already trust.
A long-running Linux rootkit is drawing fresh attention because it appears to target the very mechanisms that make logins and privilege checks work, turning trusted system components into capture points.
A Linux rootkit, a macOS stealer, and WebSocket skimmers point to one problem attackers keep exploiting: the places defenders trust the most are often the hardest to verify.
A new breed of Linux rootkit, VoidLink, leverages AI and hybrid kernel trickery to evade the world’s toughest cloud security.
A hybrid malware weaponizes eBPF and kernel modules to outsmart defenders and haunt cloud environments.
A new breed of stealth rootkit is rewriting the rules of Linux defense, outsmarting even the most advanced detection tools with surgical log evasion.
A new breed of kernel-level rootkit rewrites the rules of cyber-stealth, leaving defenders scrambling for answers.