Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
2026-05-21T19:24:15Z•53742ecc32ca7e5b497f1cbf7bdd920cf3fde19e09cfd045da31fef5ec5e459e
BitLockerSOCKS5VSCode-extensionYellowKeyad-fraudbackdoorcredential-theftgit-actionsgithub-breachgrafanakernel-vulnerabilitylinuxlocal-privilege-escalationmalwarenpmnx-consolepoCpost-exploitationremote-code-executionshowboatsupply-chainwebworm
What happened
A multi-faceted security roundup: researchers disclosed the Showboat Linux modular backdoor (SOCKS5 proxy, remote shell, file transfer) used against a Middle East telecom, and multiple active exploitation and supply-chain incidents were reported. Notable vulnerabilities include Microsoft Defender privilege escalation CVE-2026-41091 (actively exploited), a 9‑year Linux kernel privilege flaw CVE-2026-46333, Drupal Core RCE CVE-2026-9082, the YellowKey BitLocker bypass CVE-2026-45585 (mitigation released), and a DirtyDecrypt Linux kernel LPE PoC (CVE-2026-31635). High-impact supply-chain breaches
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 53742ecc32ca7e5b497f1cbf7bdd920cf3fde19e09cfd045da31fef5ec5e459e
- Enrichment time
- 2026-05-21T19:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.