ZCyberNews
中文

#linux

5 articles

Education and homelab environments were the primary targets in a series of Linux-focused attacks between April 12 and April 30, 2026, with global impact and a notable concentration in South Asia. The activity involved threat actors Harvester, Payouts King, and The Gentlemen, and leveraged CVE-2026-31431, a vulnerability with a CVSS score of 7.8. The seven articles covering this tag included four high-severity incidents, one medium, and two informational reports, affecting the IoT and maker sectors alongside education and homelab systems.

Diagram of GenieLocker ransomware infection chain across Windows, Linux, and ESXi systemsHIGH
Malware

GenieLocker Ransomware Targets Windows, Linux, and ESXi Systems

Kaspersky dissects GenieLocker, a custom ransomware from the Toy Ghouls group, targeting Windows, Linux, and ESXi in attacks on Russian manufacturing firms since March 2026.

3 min readToy Ghouls
Linux 'Copy Fail' LPE CVE-2026-31431 Lets Local Users Gain RootHIGH
Vulnerabilities

Linux 'Copy Fail' LPE CVE-2026-31431 Lets Local Users Gain Root

CVE-2026-31431 (CVSS 7.8) dubbed 'Copy Fail' lets unprivileged local users write four controlled bytes to any readable file's page cache, enabling root on major Linux…

CVE-2026-31431
2 min read
Harvester Deploys Linux GoGra Backdoor via Microsoft Graph APIHIGH
Malware

Harvester Deploys Linux GoGra Backdoor via Microsoft Graph API

The Harvester threat actor deploys a new Linux version of its GoGra backdoor, using Microsoft Graph API and Outlook mailboxes for stealthy C2 communication in attacks targeting…

2 min readHarvester
The Gentlemen Ransomware Deploys Dual Lockers for Windows, Linux, and VMwareHIGH
Malware

The Gentlemen Ransomware Deploys Dual Lockers for Windows, Linux, and VMware

The Gentlemen ransomware-as-a-service operation has infected over 320 victims, deploying separate encryptors for Windows/Linux and VMware ESXi systems to maximize disruption and ransom pressure on enterprise networks.

3 min readThe Gentlemen
Payouts King Ransomware Deploys QEMU VMs as Stealthy Reverse SSH BackdoorsHIGH
Malware

Payouts King Ransomware Deploys QEMU VMs as Stealthy Reverse SSH Backdoors

The Payouts King ransomware group is deploying the open-source QEMU emulator to create hidden virtual machines on compromised hosts, establishing a persistent reverse SSH backdoor that evades conventional endpoint detection.

4 min readPayouts King

Stay Updated

Get the latest cybersecurity news delivered to your inbox.