Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence

2026-05-10T02:51:48Z450bbc93ceb1074c38732049ef8ec51dc5392b6df52fb0a147926277e16bb4a6
CVE-2026-0300CVE-2026-20034CVE-2026-20035CVE-2026-6973CiscoDirty FragICSIvantiPAN-OSQLNXRATRansomHousecloud-credentialscritical-infrastructurecyberwarfaredata-breachkernelknown-exploited-vulnerabilitylinuxmalwarenation-stateprivilege-escalationransomwaresupply-chainzero-day

What happened

The feed aggregates multiple high‑impact incidents: researchers disclosed QLNX, a fileless Linux RAT targeting developers and DevOps for credential theft and remote access; a new unpatched Linux kernel local privilege escalation dubbed “Dirty Frag” with public exploits; and nation‑state actors actively exploiting a critical Palo Alto PAN‑OS zero‑day (CVE‑2026‑0300). Other notable items include a Braintrust AWS account compromise exposing API keys, RansomHouse claiming a Trellix breach, confirmed ICS breaches at five Polish water plants, a Zara customer data exposure via a third‑party, CISA’sKE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
450bbc93ceb1074c38732049ef8ec51dc5392b6df52fb0a147926277e16bb4a6
Enrichment time
2026-05-10T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.