INTELLEGIXNEWS ▶ Reels

Get news alerts

A notification when a new edition publishes.

Seven Thousand Fake Repositories and a Nine-Year-Old Hole in the Linux Kernel

Ask about this with Perplexity AI-written from the broadcast
▶ The reel · AI-generated from this story · watch full screen ↗
How this was made Verified AI

Every Intellegix briefing is generated from that day's broadcast and run through automated checks before it publishes — with a human paged on any flag. Here is the trail for this edition.

Sources 12 sources traced for this edition Traced
Guardrail Every figure and proper name traced back to the broadcast Pass
Fact-check 2 confirmed · 3 checked against live web sources · 1 flagged to editor 1 flag
Human loop Operator paged on every flag before publish On
Green and white lines of programming code scrolling across a dark monitor screen.
Photo: tookapic · pixabay

Two major cybersecurity disclosures on Wednesday illustrate how quickly the threat landscape is evolving — and how long vulnerabilities can hide in plain sight. Security researchers identified 7,600 fake GitHub repositories designed specifically to target AI coding agents rather than human developers. Rather than tricking a programmer into running malicious code, attackers set up fake repositories built to look like legitimate open-source projects so that automated AI coding assistants — tools like GitHub Copilot or similar agentic systems — pull malware into whatever they are building. The scale and coordination of the campaign reflects a new attack surface that barely existed two years ago.

The second disclosure is in some respects more alarming for its duration. Security firm Qualys has disclosed a critical flaw in the Linux kernel's XFS filesystem — the format used by many enterprise Linux distributions — that has gone undetected for nine years. The vulnerability allows any local user with basic system access to silently escalate privileges to full root access. In enterprise security terms, that means any compromised account or malicious insider who gains a foothold instantly becomes a full system administrator. Qualys estimates more than 16 million enterprise systems worldwide are potentially affected.

The persistence of the flaw across nine years of intensive review raises uncomfortable questions about the limits of open-source security auditing. The Linux kernel is among the most scrutinized codebases in existence, with thousands of contributors and extensive review processes. That a critical privilege-escalation vulnerability survived all of that is a sobering reminder that review intensity has ceilings.

On the surveillance front, the ACLU's campaign against Flock Safety — the company that sells AI-powered license plate readers now deployed at over 100,000 locations across 49 states — is gaining political traction. Cities are beginning to cancel contracts and a coalition is forming around concerns that the networked cameras, which log every passing vehicle and create detailed travel histories linked to specific plates, constitute comprehensive tracking without legal framework. The Supreme Court's 2018 Carpenter decision established that cell phone location data requires a warrant, but whether that reasoning extends to license plate reader networks remains legally unsettled.

The FCC's ban on devices containing Chinese-made chips and modules carries long supply chain implications that extend well beyond consumer electronics into industrial equipment, telecommunications infrastructure, and automotive components. Identifying which specific chips in a given device are 'Chinese-made' versus manufactured by a non-Chinese company using Chinese intellectual property is, in practice, a genuinely complicated undertaking across the deeply integrated global semiconductor supply chain.

▶ Listen to this story
Follow this story: Security Chinese Systems →