A proof-of-concept rootkit called Curing can bypass traditional system call monitoring using a Linux asynchronous I/O mechanism, called io_uring. Security research firm ARMO found such use of io_uring leaves a gap in Linux security tools, with actions not showing as system calls. Current tools, including Falco and Tetragon, are found to be blind to io_uring-based operations due to their reliance on system call hooking.

“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram
PupkinStealer is a C# malware that steals sensitive data, including browser credentials and desktop files, using Telegram for stealthy data exfiltration. Discovered in April 2025,