eBPF (extended Berkeley Packet Filter) is a Linux kernel technology that lets users run sandboxed programs inside the kernel for tasks such as networking, tracing, and security.
eBPF (extended Berkeley Packet Filter) is a Linux kernel technology that lets users run sandboxed programs inside the kernel for tasks such as networking, tracing, and security. It provides deep visibility and kernel-space control, which attackers can abuse to hide activity or maintain persistence. Recent findings show BPFDoor and Symbiote rootkits leveraging eBPF filters to compromise Linux systems, underscoring a kernel-level attack surface in cybersecurity.
Linux rootkits utilizing advanced eBPF and io_uring techniques have emerged as a significant threat, particularly in cloud, IoT, and high-performance computing environments. Attackers are engineering these rootkits to…
A significant supply chain attack has compromised over 400 packages in the Arch User Repository (AUR), with attackers injecting malicious build scripts that deploy credential-stealing malware and rootkits. The campaign,…
The VoidLink rootkit has been identified as a significant threat to Linux systems, utilizing a combination of Loadable Kernel Modules (LKMs) and extended Berkeley Packet Filter (eBPF) programs for stealthy infiltration.…
BPFDoor and Symbiote rootkits are exploiting vulnerabilities in eBPF filters to compromise Linux systems. These advanced threats are designed to evade detection and have raised alarms in the cybersecurity community.…
A new LKM rootkit named Singularity has been identified, targeting systems that utilize eBPF security tools. The rootkit is capable of evading detection and exploiting vulnerabilities in the eBPF framework, affecting…
Cloudflare has introduced Programmable Flow Protection, a new feature for Magic Transit customers aimed at enhancing DDoS mitigation for custom UDP protocols. This feature allows customers to upload their own stateful…