Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence

2026-05-09T14:51:43Z6236e40cae0ef318c29b03f340d926c8a9469d9c8b3c01ce999f3bc3f2d333f5
CISA-KEVCiscoICSIvantiPAN-OSRATcloud-credentialscredential-theftdata-breachexploited-in-the-wildfilelesskernel-vulnerabilitykeystroke-logginglinuxmalwarenation-stateprivilege-escalationransomwaresupply-chainzero-day

What happened

Feed highlights multiple high-impact security incidents and active exploits: a new fileless Linux RAT (Quasar Linux RAT - QLNX) targeting developers for credential theft and persistence; an unpatched Linux kernel local root vulnerability dubbed “Dirty Frag” with public exploit; active exploitation of a Palo Alto PAN-OS zero‑day (CVE-2026-0300) by suspected nation‑state actors to gain root and deploy tunneling tools; and a variety of supply‑chain and account‑compromise incidents (Braintrust AWS account breach exposing API keys, RansomHouse claiming access to Trellix internal systems, and a Shny

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6236e40cae0ef318c29b03f340d926c8a9469d9c8b3c01ce999f3bc3f2d333f5
Enrichment time
2026-05-09T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.