Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise
2026-04-28T20:51:46Z•7bd0b448a74e86223d14499b9569160f696abd8f0f035860afed526541485cfb
Chrome extensionsCisco FirepowerFIRESTARTERLinuxMicrosoft EntraMicrosoft TeamsPack2TheRootPackageKitSNOW malwareShinyHuntersUNC6692Vidarbackdoordata breachdata exfiltrationinfostealerlocal rootmalspampatchingpersistenceprivacyprivilege escalationservice principaltenant takeovervulnerability
What happened
This feed highlights multiple high-impact security issues: Pack2TheRoot — a newly disclosed, 12‑year‑old PackageKit vulnerability that can grant full root on multiple Linux distributions; FIRESTARTER — a Linux backdoor targeting Cisco Firepower appliances that evades patches and maintains persistence across firmware updates; and several active commodity threats including UNC6692 deploying SNOW via malicious Microsoft Teams lures and a new Vidar infostealer spreading via fake CAPTCHAs and hidden JPEG/TXT carriers. Other notable items: 82 Chrome extensions found selling user data (~6.5M users),a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 7bd0b448a74e86223d14499b9569160f696abd8f0f035860afed526541485cfb
- Enrichment time
- 2026-04-28T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.