View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Bad Epoll Linux kernel flaw lets unprivileged users gain root

🚨 ACTIVE EXPLOITS & INCIDENTS

  • NetNut proxy network disrupted, 2 million infected devices cut off — BleepingComputer A coordinated takedown involving Google dismantled the NetNut residential proxy network, which leveraged millions of compromised Android devices including smart TVs and streaming boxes. This disruption cuts off a major source of abused infrastructure used for fraud, scraping, and anonymized attacks.

🔓 VULNERABILITIES & CVEs

🕵️ THREAT RESEARCH & DEEP DIVES

  • New Avalon Malware Framework Packs CrownX Ransomware Capabilities — The Hacker News Researchers uncovered "Avalon," a modular malware framework distributed via multi-stage phishing that bypasses traditional defenses. Avalon integrates credential theft, lateral movement, remote access, recovery disruption, and ransomware (CrownX), representing a sophisticated all-in-one threat chain.
  • North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets — The Hacker News North Korean threat actors deployed malicious npm packages ("rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core") impersonating legitimate Rollup polyfill tooling. These packages enable remote access and exfiltration of developer secrets, highlighting ongoing supply chain risks in open source ecosystems.

📰 LESSER-KNOWN / UNDER-REPORTED

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check