Fortinet has discovered a sophisticated rootkit malware exploiting multiple zero-day flaws in enterprise appliances. The malware uses kernel modules and user-space processes to gain persistence, intercept network traffic, and control compromised Linux-based systems. The malware was embedded in key Linux configuration files to ensure it loaded during system boot. It could execute Linux commands remotely and hijack TCP sessions. Fortinet urged regular updates of systems, monitoring of processes and traffic, and improved security of /proc directory permissions.

Bitcoin Python Library Targeted by Wallet Draining Malware
Machine learning helped detect malware aimed at bitcoinlib users, a popular Python library for creating Bitcoin wallets. Recognized under the names “bitcoinlibdbfix” and “bitcoinlib-dev,” the