Researchers from Graz University of Technology disclosed file-notification attacks exploiting inotify on Linux to conduct keystroke-timing and UI-redress attacks, including credential harvesting via fake password windows on KDE. Linux kernel versions released in January provided partial mitigation.