ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
Made by Linux. 31 of its vulnerabilities are known to have been exploited.
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.
The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux. A partial list of changes is available in the Git log . Interested in switching release channels? Find out how . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Chrome Release Team Google Chrome…
Hi, everyone! We've just released Chrome 154 (154.0.8037.126) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Android releases contain the same security fixes as their corresponding Desktop releases (Windows &…
The Stable channel has been updated to 154.0.8037.97/.98 for Windows and Mac and 154.0.8037.97 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log Security changes will be updated shortly Interested in switching release channels? Find out how here . If you find a new issue, please let us know by filing a bug . The community help forum is also a…
The Chrome team is excited to announce the promotion of Chrome 156 to the Beta channel for Windows, Mac and Linux. Chrome 156.0.8078.4 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore - please head to the Chromium blog to learn more! A partial list of changes is available in the Git log . Interested in switching release channels? Find out how…
Hi, everyone! We've just released Chrome 154 (154.0.8037.92) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Android releases contain the same security fixes as their corresponding Desktop releases (Windows &…
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
The Dev channel has been updated to 156.0.8072.0 for Windows, Mac and Linux. A partial list of changes is available in the Git log . Interested in switching release channels? Find out how . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Chrome Release Team Google Chrome…
The Beta channel has been updated to 155.0.8059.12 for Windows, Mac and Linux. A partial list of changes is available in the Git log . Interested in switching release channels? Find out how . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Chrome Release Team Google Chrome…
Hi, everyone! We've just released Chrome 154 (154.0.8037.57) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Android releases contain the same security fixes as their corresponding Desktop releases (Windows &…
The Chrome team is delighted to announce the promotion of Chrome 154 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks. Chrome 154.0.8037.57 (Linux) 154.0.8037.57/.58 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log . Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in…
Apply the vendor's security update for Windows, Chrome and Linux.
View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIPLUS and SIMATIC Products are…
Apply the vendor's security update for Linux.
CISA added CVE-2025-39964 (Linux Kernel) to its Known Exploited Vulnerabilities catalog on September 18, 2026, which means there is reliable evidence of exploitation in the wild. Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
CISA lists this as exploited in the wild. Unpatched Linux systems are exposed to active attacks now.
Apply the vendor's security update for Linux.
CISA added CVE-2026-53266 (Linux Kernel) to its Known Exploited Vulnerabilities catalog on September 18, 2026, which means there is reliable evidence of exploitation in the wild. Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The…
CISA lists this as exploited in the wild. Unpatched Linux systems are exposed to active attacks now.
Apply the vendor's security update for Linux.
CISA added CVE-2025-39682 (Linux Kernel) to its Known Exploited Vulnerabilities catalog on September 18, 2026, which means there is reliable evidence of exploitation in the wild. Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling…
CISA lists this as exploited in the wild. Unpatched Linux systems are exposed to active attacks now.
Treat this as an emergency.
The latest developments from the last 30 days, newest first.
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Basis: Reporting by Dark Reading
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
Basis: Reporting by SecurityWeek
Chrome Dev for Desktop Update
Basis: Google Chrome Releases (vendor advisory)
Chrome for Android Update
Basis: Google Chrome Releases (vendor advisory)
Stable Channel Update for Desktop
Basis: Google Chrome Releases (vendor advisory)
Chrome Beta for Desktop Update
Basis: Google Chrome Releases (vendor advisory)
Chrome for Android Update
Basis: Google Chrome Releases (vendor advisory)
New Spectre v2 attack variant leaks Linux root password hash in minutes
Basis: Reporting by BleepingComputer
Linux Kernel
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel
Linux Kernel Race Condition Vulnerability
Linux Kernel
Linux Kernel Unspecified Vulnerability
Linux Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel
Linux Kernel Improper Authentication Vulnerability
Linux Kernel
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux Kernel
Linux Kernel Integer Overflow Vulnerability
Linux Kernel
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux Kernel
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
Linux Kernel
Linux Kernel Improper Ownership Management Vulnerability
Linux Kernel
Linux Kernel Out-of-Bounds Access Vulnerability
Linux Kernel
Linux Kernel Out-of-Bounds Read Vulnerability
Linux Kernel
Linux Kernel Use of Uninitialized Resource Vulnerability
Linux Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux Kernel
Linux Kernel Heap-Based Buffer Overflow Vulnerability
Linux Kernel
Linux Kernel Use-After-Free Vulnerability
Linux Kernel
Linux Kernel Use-After-Free Vulnerability
Linux Kernel
Linux Kernel Improper Input Validation Vulnerability