linneman
labs
building
breaking
observing
content
···
verified
home
/ tetragon
Tetragon
2026.05.15
Hello, my name is Orca
Any unprivileged app can claim Orca’s D-Bus name and read raw Wayland keystrokes - passwords included.
2026.05.11
Porting Dirty Frag to arm64
On aarch64 the rxrpc path oopses and AppArmor blocks the exploit over SSH. A complain-mode profile transition slips it through.
2026.04.24
Detection Below the Socket Layer
Malware that hand-builds its own packets slips past socket-level monitoring so the detection drops below the socket too.