The systemd 261 release brings a software TPM, new OS installer
2026-06-22T02:51:50Z•9fcf8273db8e265c09a60b633ff06db527e46f6c05e4947fe6952199d7027ae2
Android developer verification','Accenture','Dragos','runZero','CISA KEVCVE-2026-20253FortinetGitHub abuseHuntressIMDSKlueMastodonSalesforceSplunkVirusTotalYouTubeactive exploitationcredential theftcrypto‑stealing malwaredata breachdynamic librarieshand gestureskexecreCAPTCHAremote code executionsoftware TPMsystemdtwo‑factor authentication
What happened
Collection of security news: systemd 261 released with new features including a software TPM, IMDS cloud metadata subsystem (systemd-imdsd), kexec state preservation, and on-demand library loading. A critical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) is under active exploitation and has been added to CISA’s KEV list. Multiple breaches and abuse campaigns were reported — Klue compromise led to Salesforce data theft affecting vendors like Huntress, ~74k Fortinet firewall credentials were stolen, and a crypto‑stealing malware campaign used fake GitHub activity, YouTube tutorials,和
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 9fcf8273db8e265c09a60b633ff06db527e46f6c05e4947fe6952199d7027ae2
- Enrichment time
- 2026-06-22T02:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.