FlipSwitch: a Novel Syscall Hooking Technique
FlipSwitch: a Novel Syscall Hooking Technique Syscall hooking, particularly by overwriting pointers to syscall handlers, has been a cornerstone of Linux rootkits like Diamorphine and…
FlipSwitch: a Novel Syscall Hooking Technique Syscall hooking, particularly by overwriting pointers to syscall handlers, has been a cornerstone of Linux rootkits like Diamorphine and…
Revisiting WARMCOOKIE Elastic Security Labs continues to track developments in the WARMCOOKIE codebase, uncovering new infrastructure tied to the backdoor. Since our original post, we…
For the fourth consecutive year, Elastic Security Labs presents its 2025 Global Threat Report, distilling real-world user telemetry to offer critical insights into the evolving…
Introduction Elastic Security Labs is observing malicious campaigns delivering a multi-stage infection involving a previously undocumented loader. The infection begins when users are diverted to…
Preamble Last Monday night I was working late and a Slack alert came in from a monitoring tool I had built three days earlier. Axios…
Introduction Recent Linux kernel privilege escalation vulnerabilities, Copy Fail (CVE-2026-31431) , Copy Fail 2, and DirtyFrag, highlight how subtle page cache corruption bugs can become…
Acknowledgments: Special thanks to Ben Nahorney and Aaron Deal for their contributions to this investigation and writeup. Background Huntress has identified a surge in phishing…
When a ransomware attack hits a hospital or bank, it’s not just company data or customer emails that are vulnerable. These organizations have access to…
On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers…
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new…
Shadow AI is already taking root across financial services and many firms are discovering it only after the fact. Employees are turning to AI tools…
Python script to identify hosts infected with the BPFDoor malware. Download bpfdoor-scanner.tar.gz Getting Started This tool provides a Python script to identify hosts that are…