logo

DomainTools | 18. The Machine Kernel of Truth

ID: 04b1c5fd-a645-5039-8f76-06becae95307

STIX ID: report--04b1c5fd-a645-5039-8f76-06becae95307

Feed Name: DomainTools

Threat Score
80/100

Date Published: 2026-01-07

Date Updated: 2026-04-27

Author: domaintools.com

...
...

**Executive summary:** This podcast/blog post highlights two security issues: critical TCP/IP SACK implementation vulnerabilities in Linux and FreeBSD (including SACK Panic which can crash kernels and other SACK-based DoS variants) with vendor patches and mitigations discussed, and an active Turla APT campaign that deployed multiple backdoors (Neptun on Exchange, Meterpreter disguised as .wav, PowerShellRunner-derived implants), reused and combined leaked Equation Group tools, leveraged living-off-the-land techniques, and targeted government, ICT, and education sectors while opportunistically using OilRig infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.