frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A new stealthy Linux kernel rootkit makes detection nearly impossible

https://github.com/MatheuZSecurity/Singularity
6•matheuzsec•2h ago

Comments

matheuzsec•2h ago
This rootkit doesn't just hide from detection tools, it blinds them at the kernel level. When security tools try to enable ftrace (the standard syscall tracing method), the rootkit intercepts writes to /proc/sys/kernel/ftrace_enabled, pretends it succeeded, stores a fake "enabled" value in memory, and returns it on reads while never actually enabling tracing, so tools like perf and ftrace think they're working but see nothing.

It blocks all dangerous eBPF program types (kprobes, tracepoints, LSM hooks, iterators) making modern security tools like Falco, bpftrace, Tracee, Cilium are completely blind.

This kernel rootkit also can evade detection on modern EDRs like Trend Micro EDR, Crowdstrike falcon (since blocks eBPF operations), Elastic Security, Sophos, and others.

It hooks every read syscall variant (read, pread64, readv, preadv, preadv2, plus 32-bit versions) to filter /proc/kmsg, /var/log/kern.log, /var/log/syslog, dmesg output, and audit logs, removing any lines containing "taint", "hook", "ftrace", or "kallsyms_lookup_name" before they reach userspace. For process hiding, it doesn't just filter /proc but hooks 20+ syscalls (getdents64, stat, lstat, statx, newfstatat, chdir, readlink, openat, kill, getsid, getpgid, pidfd_open) returning ENOENT/ESRCH for hidden PIDs.

It hooks netlink_unicast to drop audit messages about hidden processes before they reach auditd. It hooks init_module and finit_module so you can't load detection kernel modules, always return -ENOEXEC (Exec format error).

It hides network connections by hooking tcp4_seq_show, tcp6_seq_show, and tpacket_rcv.

And it has other very strong and stealthy hooks, which makes it scary because it doesn't have much of an impact on the system, and it doesn't slow it down like other rootkits.

Once a machine is compromised with singularity rootkit, trusting any observability from that kernel becomes impossible, your security tools are running and reporting "all clear" while being completely deceived.

Apple's App Course Runs $20k a Student. Is It Worth It?

https://www.wired.com/story/apple-app-making-course-michigan-state-university/
1•pd33•1m ago•0 comments

Spotify disables accounts after open-source group scrapes 86M songs

https://therecord.media/spotify-disables-scraping-annas
1•speckx•2m ago•0 comments

Show HN: Epstein Files and images (4000 .png files)

https://epstein-files-browser.vercel.app
4•Gerome24•4m ago•0 comments

It's the European Union vs. Musk, Round One

https://read.misalignedmag.com/its-the-european-union-v-musk-round-one-ab565131c510
1•lcubw•5m ago•0 comments

Vcmi-gym: RL-powered combat AI for Heroes of Might and Magic 3

https://github.com/smanolloff/vcmi-gym
1•starkparker•7m ago•0 comments

Knowledge curation (not search) is the AI big data problem

https://www.daft.ai/blog/knowledge-curation-not-search-is-the-big-data-problem-for-ai
2•jaychia•8m ago•0 comments

Thing, Creature, or Mirror? The Standards We Set for AI

https://www.msthgn.com/articles/thing-creature-or-mirror-the-standards-we-set-for-ai
1•i7l•10m ago•0 comments

Back-of-the-Envelope Math on Payouts in Bartz vs. Anthropic Settlement

https://www.authorsalliance.org/2025/12/19/back-of-the-envelope-math-on-what-payouts-we-may-see-i...
1•ilamont•11m ago•0 comments

The one billion dollar billboard

https://www.theonebilliondollarbillboard.com
1•esobarsenior•11m ago•1 comments

Clawdis – Your Own Personal AI Assistant. Talk via WhatsApp, Telegram or Web

https://clawdis.ai/
2•montyanderson•12m ago•0 comments

Stealthy Playwright Mode: Bypass CAPTCHAs and Bot-Detection [video]

https://www.youtube.com/watch?v=PnFD_gSmGUc
2•seleniumbase•12m ago•0 comments

AI apps for visual creation in 11 categories

https://gist.github.com/seinecle/689a53bceca96147a04e93bdc5f83940
1•seinecle•12m ago•0 comments

BuildSherpa – end to end validation platform for your ideas

https://buildsherpa.ai
1•bayeslaw•13m ago•1 comments

Bearer Bond

https://en.wikipedia.org/wiki/Bearer_bond
3•toomuchtodo•15m ago•1 comments

Microsoft's biggest 2026 problem – the fans have checked out

https://www.windowscentral.com/microsoft/heading-into-2026-microsoft-is-losing-the-fans-who-once-...
3•thomasjudge•21m ago•1 comments

Multimodal University: Hybrid Search

1•Beefin•23m ago•0 comments

AI Is About to Get Boring – and That's When It Gets Powerful

https://medium.com/@leeon14/ai-is-about-to-get-boring-and-thats-when-it-gets-powerful-ad5ef0fc1abd
1•sileo-oss•24m ago•0 comments

Show HN: Free tool to auto-index pages and track rankings

https://seoranktracker.solutions
2•brobles•28m ago•1 comments

A global Christmas carol in the terminal

https://twitter.com/i/status/2003852565164036389
1•krupan•28m ago•1 comments

China's reverse-engineered EUV chipmaking tool hasn't produced a single chip

https://www.tomshardware.com/tech-industry/semiconductors/chinas-reverse-engineered-frankenstein-...
3•speckx•28m ago•0 comments

Show HN: AI that edits your files directly, no approvals

1•acro-v•28m ago•0 comments

CSS-Tricks: Thank You (2025 Edition)

https://css-tricks.com/thank-you-2025-edition/
1•herbertl•28m ago•0 comments

Spice: A 40-year old open-source success story (2011)

https://www.edn.com/spice-a-40-year-old-open-source-success-story/
1•stmw•32m ago•1 comments

Wrapped Envy Season

https://www.wreflection.com/p/wrapped-envy-season
1•nowflux•33m ago•0 comments

Crossview – visualize Crossplane compositions and managed resources

https://corpobit.com/products/crossview
1•moeidheidari•34m ago•1 comments

NASA will soon find out if the Perseverance rover can persevere on Mars

https://arstechnica.com/space/2025/12/nasa-will-soon-find-out-if-the-perseverance-rover-can-reall...
3•ohjeez•34m ago•0 comments

Mizzurna Falls

https://bytesizedchunks.net/blog/20251224/
1•mrdosija•34m ago•1 comments

Productivity and AI: it's the tool, not the model

https://nocodefunctions.com/blog/ai-coding-tool-productivity-paradox/
1•seinecle•40m ago•0 comments

"NFTees" > NFTs – Imho

https://mortal.sh
1•tomccc•43m ago•0 comments

Swift concurrenty waits for no one

https://saagarjha.com/blog/2023/12/22/swift-concurrency-waits-for-no-one/
3•marvel_boy•44m ago•0 comments