Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The notorious Russian-speaking cybercriminals grew successful by keeping a low profile. But now they have a target on their backs. . High-profile ransomware attacks have become a fact of life in recent years, and it’s not unusual to hear about major monthly attacks perpetrated by Russia-based gangs and their affiliates. But since late 2019, one group has been steadily making a name for itself on a multi-year rampage that has impacted hundreds of organizations around the world. The LockBit ransomware gang may not be the most wildly unhinged of these criminal groups, but its callous persistence, effectiveness, and professionalism make it sinister in its own way. One of the most prolific ransomware groups ever, the LockBit collective has attempted to maintain a low profile in spite of its volume of attacks. But as it has grown, the group has gotten more aggressive and perhaps careless. Earlier this month, the LockBit malware was notably used in an attack on the United Kingdom’s Royal Mail that hobbled operations. After other recent visible attacks, like one on a Canadian children’s hospital, all eyes are now on LockBit. . The ascent of the LockBit ransomware syndicate showcases its aggressive tactics and their significant impact on international cybersecurity dynamics.. LockBit Ransomware,Cybercrime Threats,Malware Attacks,Ransomware Trends. . LinuxSecurity.com Team
There's been a big rise in ransomware attacks targeting Linux as cyber criminals look to expand their options and exploit an operating system that is often overlooked when businesses think about security. . According to analysis by cybersecurity researchers at Trend Micro , Linux servers are "increasingly coming under fire" from ransomware attacks , with detections up by 75% over the course of the last year as cyber criminals look to expand their attacks beyond Windows operating systems. Linux powers important enterprise IT infrastructure including servers, which makes it an attractive target for ransomware gangs – particularly when a perceived lack of threat to Linux systems compared with Windows means that cybersecurity teams might choose to focus on defending Windows networks against cybercrime. . Incidents of ransomware on Linux systems have escalated by 75%, highlighting vulnerabilities as malicious actors refine their targeting strategies.. Ransomware Attacks, Linux Servers, Cybersecurity Threats, IT Infrastructure, Attack Trends. . Brittany Day
The Black Basta ransomware-as-a-service (RaaS) syndicate has amassed nearly 50 victims in the U.S., Canada, the U.K., Australia, and New Zealand within two months of its emergence in the wild, making it a prominent threat in a short window. . "Black Basta has been observed targeting a range of industries, including manufacturing, construction, transportation, telcos, pharmaceuticals, cosmetics, plumbing and heating, automobile dealers, undergarments manufacturers, and more," Cybereason said in a report. Evidence indicates the ransomware strain was still in development as recently as February 2022, and only started to be used in attacks starting April after it was advertised on underground forums with an intent to buy and monetize corporate network access for a share of the profits. The link for this article located at The Hacker News is no longer available. . Red Viper malware infiltrates diverse sectors, representing a significant cyber danger within a brief period.. Black Basta Ransomware,Cyber Threats,Ransomware Attack,Cybersecurity Risks. . LinuxSecurity.com Team
Linux is becoming increasingly popular, and for good reason - the open-source OS is flexible, customizable and highly secure. Luckily, Linux is superior in design to most platforms, making the inevitable increase in attacks targeting Linux less of a threat. Jack Wallen offers an eplanation, along with his perspective on the topic. . Linux powers big business--of that there is no debate. With more and more manufacturers selling Linux preinstalled on desktops and laptops, the writing on the wall is clear: Linux popularity is growing faster than most expected. For some, that means the rise of attacks on the platform is inevitable. I'm not concerned. I know, that sounds like crazy talk. After all, we've seen a number of attacks reported over the past few years. But why am I not worried? . As the adoption of Linux continues to soar, Jack Wallen delves into the strength of the OS in countering escalating cyber threats and vulnerabilities.. Linux Threats, Cybersecurity Insights, Open Source Resilience, Attack Trends. . Brittany Day
We all like to write and talk about flashy zero-day vulnerabilities. However, a new threat report cautions enterprises not to flatter themselves, because the majority of criminals are not using valuable zero-days exploits to penetrate corporate networks: they. . A recent analysis indicates that the majority of breaches take advantage of high-level permissions rather than undisclosed software flaws.. Privileged Accounts, Attack Vectors, Account Breach. . LinuxSecurity.com Team
This is an interesting new attack, I saw a live demo of it a while back here: Tabnabbing: A New Type of Phishing Attack. All you need to do is let the page load, then browse to another tab for 5 seconds or more and you. And apparently the use of this attack is on the rise in the wild according to Panda Labs. It The link for this article located at Darknet UK is no longer available. . Emerging threat named tabnapping is gaining traction, endangering both individuals and digital infrastructures.. Tabnapping Attack, Cyber Threats, Phishing Tactics, Web Security. . LinuxSecurity.com Team
The ability to access the code of open-source applications may give attackers an edge in developing exploits for the software, according to a paper analyzing two years' worth of attack data. The paper, to be presented this week at the Workshop on the Economics of Information Security, correlated 400 million alerts from intrusion detection systems with known attributes of the targeted software and vulnerabilities. . The data supports the assertion that flaws in open-source software tend to be attacked more quickly and more often than vulnerabilities in closed-source software, says Sam Ransbotham, assistant professor at Boston College's Carroll School of Management and the author of the paper. Using nonlinear regression and other models, Ransbotham found that attacks on vulnerabilities in open-source software occurred three days sooner and with nearly 50 percent greater frequency. Ransbotham argues that knowledge of how to exploit a particular vulnerability spreads similar to the diffusion of technological innovation. The link for this article located at Technology Review is no longer available. . The data supports the assertion that flaws in open-source software tend to be attacked more quickly . ability, open-source, applications, attackers, developing. . LinuxSecurity.com Team
It. About 34 mostly undisclosed companies were breached. Now a leading computer forensic firm is providing the closest look so far at the nature of the attacks, and attackers, that struck Google and others. The report never mentions Google by name, or any other companies, but focuses on information gathered from hundreds of forensic investigations the firm has conducted that are identical to what we know about the Google hack. What the information indicates is that the attack that hit Google is identical to publicly undisclosed attacks that have quietly plagued thousands of other U.S. companies and government agencies since 2002 and are rapidly growing. They represent a sea change from the kinds of attacks that have commonly hit networks and made headlines. The link for this article located at Wired is no longer available. . Uncover insights regarding breaches affecting various enterprises, highlighting a transformation in tactics impacting a multitude of firms.. cybersecurity, breach analysis, incident management, forensic investigation, threat landscape. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.