logo

Trend Micro Deep Security Agent Flaw Allows Repeatable Security Bypass

ID: 6d56b932-7f7f-5584-a0ff-92bf08d8de7b

STIX ID: report--6d56b932-7f7f-5584-a0ff-92bf08d8de7b

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Divya

...
...

Trend Micro Deep Security Agent for Linux has a behavior-monitoring design flaw: an unprivileged local "event storm" can cause ds_am.init to repeatedly rmmod and reload the bmhook and tmhook kernel modules, producing short (1–2s) protection gaps during a longer livepatch cycle (~20s) that an attacker can weaponize to stage or execute malware that would otherwise be blocked. The issue affects Linux endpoints with the DSA kernel support pack, is not a remote code execution, and is characterized as a local, repeatable protection bypass.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.