Related Threat Clusters
-
Critical Januscape Vulnerability in Linux KVM Exposes Cloud Servers to Attacks
A critical vulnerability in Linux KVM, named Januscape (CVE-2026-53359), has been discovered after lying dormant for 16 years. This flaw allows attackers with root access in a guest virtual machine to escape to the host…
31 articles · Updated July 7, 2026 -
Critical QEMU Vulnerabilities Affect Ubuntu Systems
Multiple vulnerabilities in QEMU have been identified, impacting Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. The issues include improper memory handling in the LSI53C895A SCSI Host Bus Adapter (CVE-2024-6519) and…
2 articles · Updated April 10, 2026 -
Critical Privilege Escalation Vulnerabilities in Canonical LXD Discovered
Three critical vulnerabilities (CVE-2026-34177, CVE-2026-34178, CVE-2026-34179) have been identified in Canonical LXD versions 4.12 through 6.7, allowing authenticated users to escalate privileges to cluster admin and…
2 articles · Updated April 13, 2026 -
Critical Denial of Service Vulnerabilities in SUSE Linux QEMU
SUSE Linux has released updates addressing multiple vulnerabilities in QEMU, affecting versions of SUSE Linux Micro 6.0 and 6.1. Key vulnerabilities include CVE-2025-14876, CVE-2026-0665, CVE-2026-2243, CVE-2026-3195,…
6 articles · Updated June 2, 2026 -
Powercat Malware Campaign Targets Gamers with Infostealer Disguised as Cheats
A malware campaign named Powercat is delivering a sophisticated infostealer disguised as cheat software for popular games like Roblox and Minecraft. The campaign primarily targets users on gaming and social platforms,…
8 articles · Updated August 3, 2026 -
DesckVB RAT Campaign Exploits Google DoubleClick for Malspam Delivery
In May 2026, a malspam campaign utilizing the Google DoubleClick domain was identified, delivering the DesckVB remote access trojan (RAT). The attack begins with an HTML email attachment that redirects users through…
6 articles · Updated June 3, 2026 -
Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
8 articles · Updated April 17, 2026 -
PavinLoader Malware Exploits ClickFix and Fake Downloads to Deploy Amatera Stealer
PavinLoader, a multi-stage .NET malware loader, is being utilized in ClickFix and fake software download campaigns to deploy the Amatera Stealer. Victims are lured through deceptive pages, such as fake Cloudflare…
2 articles · Updated August 25, 2026 -
Multiple QEMU Vulnerabilities Affecting Ubuntu Systems
On June 9, 2026, Ubuntu announced several vulnerabilities in QEMU affecting versions 14.04 LTS to 20.04 LTS. The vulnerabilities include denial of service risks and potential arbitrary code execution due to improper…
5 articles · Updated June 9, 2026 -
Local Privilege Escalation Vulnerability in QEMU (CVE-2026-3886)
An important advisory was issued for SUSE Micro 6.1 regarding a vulnerability in QEMU, specifically CVE-2026-3886. This flaw arises from inadequate validation of user-supplied data in the 'virtio-gpu' driver,…
2 articles · Updated August 31, 2026
Recent Intelligence Reports
- SUSE Micro 6.1 Advisory 2026-23351-1 Highlights CVE-2026 — Linuxsecurity · August 31, 2026
- SUSE 2026-23362-1 QEMU Important Local Escalation Fix CVE-2026 — Linuxsecurity · August 31, 2026
- PavinLoader Malware Spreads via ClickFix and Fake Download Campaigns — Technadu · August 25, 2026
- Defeating AI-Assisted Reverse Engineering (or at Least Trying To) — Blog.Quarkslab · August 19, 2026
- Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign — Acronis · August 19, 2026
- Powercat Malware Campaign Fake Game Cheats Deliver Infostealer Targeting Discord Roblox And Crypto Wallets — www.threatlocker.com · August 6, 2026
- Januscape Flaw in Linux KVM’s MMU Code Enables VM Escape on Intel and AMD — Thecyberexpress · July 8, 2026
- Critical Linux KVM bug lets hackers take over servers for 16 years — Cybernews · July 7, 2026