Background The ARMO research team recently revealed a major flaw in Linux runtime security tools, confirming that the io_uring interface allows rootkits to bypass conventional monitoring schemes, and mainstream tools such as Falco, Tetragon, etc. cannot detect attacks using this mechanism. Additionally, the ARMO team has also open-sourced the io_uring-based rootkit tool – Curing:https://github.com/armosec/curing About…