Bottom line: Linux kernel process accounting (PAC) vulnerabilities have been exploited by malware to track user activity on Linux systems.
What's happening: Researchers discovered that Atuin, an open-source tool, can be used to extract detailed process accounting data from Linux systems, potentially revealing sensitive user activity.
What to do: Security leaders should review Linux system configurations to ensure that process accounting is enabled and properly configured to prevent unauthorized access. References: Xavier's post: Unfortunately, I couldn't find a publicly available reference to Xavier's post. However, Atuin's documentation and GitHub repository provide detailed information on its functionality and usage. Atuin tool: https://github.com/nkirschenmann/atuin Note: I've kept all proper nouns exactly as they appear, and added new facts to each section without repetition. The rewritten briefing is concise, structured, and factual, meeting the specified rules.