The systemd 261 release brings a software TPM, new OS installer

2026-06-22T02:51:50Z9fcf8273db8e265c09a60b633ff06db527e46f6c05e4947fe6952199d7027ae2
Android developer verification','Accenture','Dragos','runZero','CISA KEVCVE-2026-20253FortinetGitHub abuseHuntressIMDSKlueMastodonSalesforceSplunkVirusTotalYouTubeactive exploitationcredential theftcrypto‑stealing malwaredata breachdynamic librarieshand gestureskexecreCAPTCHAremote code executionsoftware TPMsystemdtwo‑factor authentication

What happened

Collection of security news: systemd 261 released with new features including a software TPM, IMDS cloud metadata subsystem (systemd-imdsd), kexec state preservation, and on-demand library loading. A critical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) is under active exploitation and has been added to CISA’s KEV list. Multiple breaches and abuse campaigns were reported — Klue compromise led to Salesforce data theft affecting vendors like Huntress, ~74k Fortinet firewall credentials were stolen, and a crypto‑stealing malware campaign used fake GitHub activity, YouTube tutorials,和

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
9fcf8273db8e265c09a60b633ff06db527e46f6c05e4947fe6952199d7027ae2
Enrichment time
2026-06-22T02:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The systemd 261 release brings a software TPM, new OS installer · Baitaphish