INTEL_REPORT
LWN.net (kernel & development security) · published 7/14/2026, 1:16:52 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
[$] Sending packets directly from BPF Tetragon , the BPF-based security monitoring tool, uses BPF to monitor different aspects of a running kernel and enforce user-specified policies. It sends its data to a user-space process, which forwards the data to a central monitoring service elsewhere in the network, however. This presents a point of vulnerability: if an attacker can kill Tetragon's user-space agent, it won't be able to properly report on the situation. Song Liu, Mahé…
https://lwn.net/Articles/1081696
sha256:b8775e526e19367bdadaff67500d2e589a661e59e61ce516d9eef061d1c8bc51
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.