Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise

2026-04-28T20:51:46Z7bd0b448a74e86223d14499b9569160f696abd8f0f035860afed526541485cfb
Chrome extensionsCisco FirepowerFIRESTARTERLinuxMicrosoft EntraMicrosoft TeamsPack2TheRootPackageKitSNOW malwareShinyHuntersUNC6692Vidarbackdoordata breachdata exfiltrationinfostealerlocal rootmalspampatchingpersistenceprivacyprivilege escalationservice principaltenant takeovervulnerability

What happened

This feed highlights multiple high-impact security issues: Pack2TheRoot — a newly disclosed, 12‑year‑old PackageKit vulnerability that can grant full root on multiple Linux distributions; FIRESTARTER — a Linux backdoor targeting Cisco Firepower appliances that evades patches and maintains persistence across firmware updates; and several active commodity threats including UNC6692 deploying SNOW via malicious Microsoft Teams lures and a new Vidar infostealer spreading via fake CAPTCHAs and hidden JPEG/TXT carriers. Other notable items: 82 Chrome extensions found selling user data (~6.5M users),a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
7bd0b448a74e86223d14499b9569160f696abd8f0f035860afed526541485cfb
Enrichment time
2026-04-28T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.