Explore top 10 tips to secure your open-source projects now. Read More
×Vulnerabilities have been discovered in Bluetooth technology that affect various operating systems. As Linux admins, infosec professionals, Internet security enthusiasts, and sysadmins, it is crucial to understand the implications of these vulnerabilities and the impact they may have on our work. Let's have a closer look at these flaws, how they work, their impact on Linux users, and how to mitigate your risk. . What Are These Vulnerabilities & How Do They Impact My Security? Researchers have discovered zero-click Bluetooth flaws that enable attackers to secretly pair with devices as keyboards and inject keystrokes without user interaction. The vulnerabilities affect Android, iOS, Linux, macOS, and Windows, posing a serious threat to billions of devices worldwide. Bluetooth technologies power wireless keyboards, mice, game controllers, and other peripherals used by billions of devices around the globe, highlighting the widespread nature of these vulnerabilities and the potential for malicious actors to exploit them across various platforms. The Linux Bluetooth implementation allows keyboards to initiate pairing without authentication or user confirmation ( CVE-2023-45866 ). This means that an attacker could remotely pair as a Bluetooth keyboard and inject keystrokes without the user's knowledge. The implications of these vulnerabilities are significant. They expose a potential attack vector that could compromise a wide range of devices. For Linux admins, it highlights the importance of keeping Bluetooth settings secure and applying the available patch in BlueZ. How Can I Mitigate My Risk? Infosec professionals and sysadmins must be aware of the vulnerabilities within their respective operating systems and take necessary measures to mitigate the risks, such as promptly applying patches as they are released by their distribution(s). Additionally, it raises questions about the overall security of Bluetooth technology and the need for cryptographic authentication and consent for allpairing attempts. From a broader perspective, these vulnerabilities highlight the ongoing cat-and-mouse game between security researchers and malicious actors. As technology evolves, so do the methods used by attackers to exploit it. This constant battle emphasizes the need for a proactive approach to security, with regular updates and patches and adopting best practices to secure Bluetooth connections. Our Final Thoughts on the Recent Zero-Click Bluetooth Flaws In conclusion, the article sheds light on the serious threats posed by zero-click Bluetooth attacks across major operating systems. It highlights vulnerabilities in Android, iOS, Linux, macOS, and Windows and raises important questions about the security of Bluetooth technology as a whole. As security practitioners, it is crucial to stay informed about these vulnerabilities, apply patches and updates, and advocate for improved authentication and consent mechanisms in Bluetooth pairing. By taking these steps, we can better protect the devices and systems we manage and mitigate the risks associated with these vulnerabilities. . What Are These Vulnerabilities & How Do They Impact My Security? Researchers have discovered zero-cl. vulnerabilities, bluetooth, technology, affect, various, operating, systems. . Brittany Day
A new malware wiper known as BiBi-Linux is being used to destroy data in attacks targeting Linux systems belonging to Israeli companies. . Security Joes' Incident Response team discovered the malicious payload while investigating the breach of an Israeli organization's network. Currently, only two security vendors' malware scanning engines detect BiBi-Linux as malicious, according to VirusTotal. The malware reveals its true nature by not dropping a ransom note or providing victims with a way to reach out to the attackers to negotiate payment for a decryptor, even though it fakes file encryption, "This new threat does not establish communication with remote Command & Control (C2) servers for data exfiltration, employ reversible encryption algorithms, or leave ransom notes as a means to coerce victims into making payments," said Security Joes. "Instead, it conducts file corruption by overwriting files with useless data, damaging both the data and the operating system." The payload (an x64 ELF executable named bibi-linux.out) found on the victim's systems allows the attackers to choose what folders to encrypt via command-line parameters. It can completely wipe a compromised device's operating system when run with root privileges if the attackers do not provide a target path, as it will attempt to delete the entire '/' root directory. . A recently identified malware wiper, Crypto-Linux, has emerged, specifically aiming at firms in the United States, erasing crucial information without solicitation for ransom.. BiBi-Linux Malware, Linux Attacks, Wiper Malware. . LinuxSecurity.com Team
A new ransomware operation has been targeting Windows and Linux systems with a combination of payloads relying on leaked LockBit and Babuk code and custom-developed tools. . Researchers said the threat actor behind the campaign, Blacktail, hasn’t been linked to any existing cybercrime group. The group’s recent campaign, called Buhti, first was publicly exposed in February when security researchers found it targeting Linux systems. Researchers in a Thursday analysis found that the group was also targeting Windows systems and leveraging a new set of vulnerabilities for initial access. “While the reuse of leaked payloads is often the hallmark of a less-skilled ransomware operation, Blacktail’s general competence in carrying out attacks, coupled with its ability to recognize the utility of newly discovered vulnerabilities, suggests that it is not to be underestimated,” said researchers. The group has been exploiting vulnerabilities soon after they are disclosed, including a flaw in IBM’s Aspera Faspex file exchange application (CVE-2022-47986) and, more recently, a known bug in the popular PaperCut print management software (CVE-2023-27350) that enables bad actors to remotely execute code. The link for this article located at Duo Security is no longer available. . ShadowCrypt is an emerging ransomware collective focusing on attacks against both Windows and Linux platforms, leveraging newly discovered exploits with tailored software.. Linux Attacks, Ransomware Threats, Cybersecurity Risks. . LinuxSecurity.com Team
A new ransomware binary targeting Linux systems has been attributed to the ransomware-as-a-service (RaaS) RTM group. . Security researchers at Uptycs shared the findings in an advisory published on Wednesday, saying this is the first time the group had created a Linux binary. “Its locker ransomware infects Linux, NAS, and ESXi hosts and appears to be inspired by Babuk ransomware’s leaked source code,” explained the company. Similarities in the code include methods to generate random numbers. They also share the type of files they encrypt. Finally, both use advanced encryption techniques to make it difficult to recover the encrypted files without the attacker’s private key. . Uptycs reveals a new malware variant aimed at Linux environments, sharing insights on its encryption techniques and tracing its roots to the RTM group.. Linux Ransomware,RaaS Threats,RTM Group Attack,Cybersecurity Research. . LinuxSecurity.com Team
The first-ever Linux variant of the Clop ransomware has been detected in the wild, but with a faulty encryption algorithm that has made it possible to reverse engineer the process. . "The ELF executable contains a flawed encryption algorithm making it possible to decrypt locked files without paying the ransom," SentinelOne researcher Antonis Terefos said in a report shared with The Hacker News. The cybersecurity firm, which has made available a decryptor , said it observed the ELF version on December 26, 2022, while also noting its similarities to the Windows flavor when it comes using the same encryption method. The detected sample is said to be part of a larger attack targeting educational institutions in Colombia, including La Salle University, around the same time. The university was added to the criminal group's leak site in early January 2023, per FalconFeedsio . The link for this article located at The Hacker News is no longer available. . The initial variant of Clop ransomware for Linux has been discovered to utilize a flawed encryption technique, which allows victims to recover their files without paying the ransom.. Linux Ransomware, Clop Malware, Decryption Method. . LinuxSecurity.com Team
Thirty security vulnerabilities in numerous outdated WordPress plugins and themes are being leveraged by a novel Linux malware to facilitate malicious JavaScript injections, reports BleepingComputer . . Both 32- and 64-bit Linux systems are being targeted by the new malware, which uses a set of successively running hardcoded exploits to compromise WordPress sites, according to a Dr. Web report. Outdated and vulnerable plugins and themes including WP Live Chat Support Plugin, Easysmtp, WordPress - Yuzo Related Posts, Thim Core, Google Code Inserter, WP Live Chat, and Hybrid would prompt the malware to retrieve a malicious JavaScript from its command-and-control server prior to script injection. Attackers could then use the infected sites for phishing and malvertising campaigns, as well as malware distribution initiatives. . A suite of exploits targeting twenty-five security holes in obsolete Joomla components is exploited by fresh Windows malware to facilitate harmful operations.. Linux Malware, WordPress Plugin Exploits, Malware Attacks. . Brittany Day
While relevant Intel and AMD processors have been mitigated for the recent Retbleed security vulnerability affecting older generations of processors, those mitigations currently just work for x86_64 kernels and will not work if running an x86 (32-bit) kernel on affected hardware. But it's unlikely to get fixed unless some passionate individual steps up as the upstream developers and vendors have long since moved on to just caring about x86_64. . Last week following the flurry of Linux patches for mitigating this newest speculative execution attack, it was pointed out that Linux x86 32-bit kernels are still vulnerable to Retbleed. It turns out Linaro still has a 32-bit Debian box in their functional test farm and they The link for this article located at Phoronix is no longer available. . The latest updates address Retbleed vulnerabilities for x86_64 architectures; however, 32-bit x86 systems still face exposure with no resolution currently available.. Retbleed Vulnerability, x86 32-Bit Vulnerability, Linux Kernel Security. . Brittany Day
Security researchers have discovered some new Linux-based ransomware that's being used to attack VMware ESXi servers, a bare-metal hypervisor for creating and running several virtual machines (VMs) that share the same hard drive storage. Called Cheerscrypt, the bad app is following in the footsteps of other ransomware programs—such as LockBit, Hive and RansomEXX—that have found ESXi an efficient way to infect many computers at once with malicious payloads. . Roger Grimes, a defense evangelist with security awareness training provider KnowBe4, explains that most of the world's organizations operate using VMware virtual machines. "It makes the job of ransomware attackers far easier because they can encrypt one server—the VMware server—and then encrypt every guest VM it contains. One compromise and encryption command can easily encrypt dozens to hundreds of other virtually run computers all at once." "Most VM shops use some sort of VM backup product to back up all guest servers, so finding and deleting or corrupting one backup repository kills the backup image for all the hosted guest servers all at once," Grimes adds. . Linux-oriented Cheerscrypt malware targets VMware ESXi environments, locking down numerous virtual machines in a single assault.. Linux Ransomware, VMware Security, Cheerscrypt Malware, ESXi Server Threat, Cybersecurity Risks. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.