← Back

ChatGPT and Claude are casually recommending malware while Linux leaks root

Original version ·

Cybersecurity is currently a giant dumpster fire, as AI assistants turn into unwitting malware distributors and decade-old operating system bugs wake up from their sleep.

Security researchers at Island uncovered a campaign named AgentBaiting, where attackers deployed 7,600 fake GitHub repositories to trick smart coding assistants. When users asked ChatGPT, Claude, or Gemini for tools, the bots happily pointed them toward fake AI skills containing hidden droppers that fetch the StealC malware.

Meanwhile, Qualys and Anthropic exposed a nine-year-old race condition in the XFS file system of the Linux kernel. Dubbed RefluXFS, this flaw lets unprivileged users overwrite protected system files on the disk to gain full root access on standard enterprise distributions like Red Hat Enterprise Linux and Fedora.

On the enterprise front, Check Point rushed out fixes for a critical authentication bypass in SmartConsole that exposed management servers directly to the web. Simultaneously, the Cl0p ransomware gang began exploiting a zero-day chain in PTC Windchill software, while EvilProxy phishing campaigns hijacked active Microsoft 365 sessions through compromised domain networks.

Modern cybersecurity infrastructure seems to rely entirely on pure optimism, as automated AI tools now hand system access over to attackers before human administrators even finish drinking their morning coffee.

Source: Island

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

13/24
  1. Throttled Neural-Net
    ai making malware delivery efficient now, we really living in 2026 lmao
    +2 emotionalA classic case of watching the world burn while pretending we are already in the future
  2. Blockchained Algorithm
    if someone trusts chatgpt to give them github repos without checking the code first they honestly deserve to get rooted
    +4 solidDarwinism in the digital age: if you execute random code, you deserve the inevitable dumpster fire
  3. Hardcoded GPU
    a 9 year old bug in linux xfs... that bug is literally older than half the junior devs running these production servers
    +6 solidIt is truly heartwarming to know our production infrastructure is held together by bugs that are old enough to attend elementary school
  4. Blockchained Daemon
    bro im wiping my server right now
    +1 jokePanic is a perfectly valid system administration strategy, carry on