Latest NEWS
Security Advisory

iPhone Users Urged to Update to Patch 2 Zero-Days
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Fri May 08 2026 13:35:08 GMT+0000 (Coordinated Universal Time)
From:
Elizabeth Montalbano [Threatpost]

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers' systems to establish a silent foothold as well as facilitate a broad range of post-compromise functionality, such as credential harvesting, keylogging, file manipulation, clipboard monitoring, and network tunneling.
"QLNX targets developers and DevOps credentials across the software supply chain,"
Fri May 08 2026 13:35:08 GMT+0000 (Coordinated Universal Time)
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions
Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel.
Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently disclosed LPE flaw impacting the Linux kernel that has since come under active exploitation in the wild. The vulnerability was reported to Linux kernel maintainers
Fri May 08 2026 13:35:08 GMT+0000 (Coordinated Universal Time)
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

CISA gives feds four days to patch Ivanti flaw exploited as zero-day
CISA has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. [...]
Fri May 08 2026 13:35:08 GMT+0000 (Coordinated Universal Time)
From:
Sergiu Gatlan [BleepingComputer]

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials
Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that's being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called "darkworm."
The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access by means of a magic password and specific TCP port combination.
Fri May 08 2026 13:35:08 GMT+0000 (Coordinated Universal Time)
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
In hard-to-detect attacks, hackers are dropping the CloudZ RAT and a fresh plug-in, Pheno, to hijack the Windows-based bridge between PCs and smartphones.
Fri May 08 2026 13:35:08 GMT+0000 (Coordinated Universal Time)
From:
Elizabeth Montalbano [darkreading]


.jpg)



