Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux’s community package collection, and it is separate
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux’s community package collection, and it is separate
Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
The network is said to be behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider, per the tech giant.
“The operation weaponized Gemini to help
phpBB forum fixes auth bypass bug lurking for a decade
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no
Ukrainian national pleads guilty to role in Conti ransomware operation
Over 400 Arch Linux packages compromised to push rootkit, infostealer
In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
Other noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&T accused of hack cover-ups.
The post In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine appeared first on SecurityWeek.
