#linux
5 articles
Education and homelab environments were the primary targets in a series of Linux-focused attacks between April 12 and April 30, 2026, with global impact and a notable concentration in South Asia. The activity involved threat actors Harvester, Payouts King, and The Gentlemen, and leveraged CVE-2026-31431, a vulnerability with a CVSS score of 7.8. The seven articles covering this tag included four high-severity incidents, one medium, and two informational reports, affecting the IoT and maker sectors alongside education and homelab systems.
HIGHGenieLocker Ransomware Targets Windows, Linux, and ESXi Systems
Kaspersky dissects GenieLocker, a custom ransomware from the Toy Ghouls group, targeting Windows, Linux, and ESXi in attacks on Russian manufacturing firms since March 2026.
HIGHLinux 'Copy Fail' LPE CVE-2026-31431 Lets Local Users Gain Root
CVE-2026-31431 (CVSS 7.8) dubbed 'Copy Fail' lets unprivileged local users write four controlled bytes to any readable file's page cache, enabling root on major Linux…
HIGHHarvester Deploys Linux GoGra Backdoor via Microsoft Graph API
The Harvester threat actor deploys a new Linux version of its GoGra backdoor, using Microsoft Graph API and Outlook mailboxes for stealthy C2 communication in attacks targeting…
HIGHThe Gentlemen Ransomware Deploys Dual Lockers for Windows, Linux, and VMware
The Gentlemen ransomware-as-a-service operation has infected over 320 victims, deploying separate encryptors for Windows/Linux and VMware ESXi systems to maximize disruption and ransom pressure on enterprise networks.
HIGHPayouts King Ransomware Deploys QEMU VMs as Stealthy Reverse SSH Backdoors
The Payouts King ransomware group is deploying the open-source QEMU emulator to create hidden virtual machines on compromised hosts, establishing a persistent reverse SSH backdoor that evades conventional endpoint detection.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.