Pardon the naive question...
Pardon the naive question...
Posted May 9, 2026 17:59 UTC (Sat) by NightMonkey (subscriber, #23051)Parent article: More stable kernels with partial Dirty Frag fixes
... but is there a path to determining if these security vulnerabilities have been exploited *in the past*? Since these are 'zero-days', I'd like to be able to investigate a system I'm responsible for and determine with some certainty that a past breach has occurred.
I know it is of course difficult (and perhaps impossible, really) because you cannot rely on a system that has been compromised to report on it's own condition, but I thought I'd see if the community has some insights or approaches. But, perhaps there's a way to scan the storage of such a suspect system after booting from an known-uncomporomised kernel? Is there a project that takes that approach?
Cheers.
