<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: MSI Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving MSI.</description><lastBuildDate>Sat, 12 Sep 2026 21:30:25 GMT</lastBuildDate><item><title>UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities</title><link>https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities</link><guid isPermaLink="false">cst-4776</guid><description>Cisco Talos identified UAT-10147, a Chinese-speaking intrusion group operating the SPECTRE cross-platform backdoor, which combines custom malware with kernel-level rootkits and bring-your-own-vulnerable-driver (BYOVD) techniques to disable endpoint detection and response (EDR) products. The Windows and Linux variants support extensive command sets for persistence, privilege escalation, credential theft, and process injection, while the integrated Specter Linux rootkit uses ftrace hooking for stealthy kernel-level hiding. Evidence suggests the threat actor incorporates artificial intelligence (AI)-assisted code generation in developing malware components and leverage SEO fraud utilities, open-source post-exploitation tools, and multiple commodity backdoors to maintain access to compromised IIS and Linux servers. Sources: Cisco Talos.</description><pubDate>Thu, 20 Aug 2026 10:00:50 GMT</pubDate></item></channel></rss>