🚨 Zero-Day Linux LPE Exploit Offered on Dark Web for $170,000
A threat actor on an underground forum is advertising the sale of a claimed zero-day Linux Local Privilege Escalation (LPE) exploit for $170,000.
According to the listing, the exploit allegedly affects multiple major Linux distributions, including:
- RHEL 10
- CentOS Stream 10
- Rocky Linux 10
- AlmaLinux 10
- Ubuntu 22.04 / 24.04 / 25.04
- Debian 13
- Fedora 41 / 42
- openSUSE Tumbleweed
- Arch Linux rolling releases
The threat actor claims the vulnerability is TOCTOU-based (Time-of-Check Time-of-Use), capable of stable local privilege escalation without causing system crashes, and leverages a shared object (.so) payload dropped into the /tmp directory.
#Linux #Exploit #DarkWeb #ThreatIntelligence #CTI #Malware #GitHubAbuse #TeamPCP #ShaiHulud