UPDATES
threat
UPDATES
GLOBAL
Residential proxies are one of cybersecurity’ s hottest topics, but many are not residential at all. Infoblox Threat Intel researchers traced what initially appeared to be an isolated malware campaign to a broader operation dating back several years. The actor, tracked as Lurking Lizard, is linked to more than 230 domains used to infect victim devices, operate proxy infrastructure, impersonate known proxy providers and market related services.
Lurking Lizard appears to be a Chinese actor who affiliates with other proxy providers to resell access to bandwidth from compromised residential proxies. External researchers previously identified overlap between infrastructure connected to Lurking Lizard and IPIDEA, a major proxy provider that was disrupted earlier this year by a coordinated industry and law enforcement action. While there have been multiple disruptions of proxy providers this year, the ability for threat actors like Lurking Lizard to continue operating the botnet devices demonstrates how hard it remains to dismantle the malicious residential proxy market.
The operation is vertically integrated, controlling several stages of acquisition, promotion and monetisation. It builds new proxy nodes by distributing malware through lookalike domains tied to major software brands, then boosts those lures through search poisoning and online ads.
GLOBAL
Qualys has announced the discovery of CVE-2026-64600, dubbed“ RefluXFS,” a critical Linux kernel vulnerability uncovered through a structured research initiative between the Qualys Threat Research Unit( TRU) and Anthropic’ s Claude Mythos Preview. The vulnerability is a race condition in the Linux kernel’ s XFS filesystem copy-on-write path that allows an attacker with an ordinary local account to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode.
According to Qualys’ analysis, the vulnerability has existed since Linux kernel version 4.11( 2017) and potentially affects more than 16.4 million systems worldwide, including deployments running Red Hat Enterprise Linux( RHEL), Oracle Linux, Amazon Linux and Fedora.
Qualys said RefluXFS enables an unprivileged local user to overwrite the on-disk contents of any readable file on a reflinkenabled XFS volume, a capability that“ converts directly into host root privileges.” The company added that exploitation is highly reliable, leaves no kernel log output and that on-disk modifications survive a system reboot.
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 35