Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 71 articles for you...
83

China: Cyberattack on Telecom Industry Raises Encryption Backdoor Risks

U.S. authorities are on high alert as they investigate an alleged Chinese state-sponsored hack targeting major U.S. telecommunications companies. This attack has reignited debate about encryption backdoors , an ongoing contention among security practitioners. . To help you understand this incident and the security implications of encryption backdoors, I'll discuss these recent attacks, lawmakers' reactions, the role of encryption backdoors in this threat, and why many security professionals—including us at LinuxSecurity.com —oppose their usage. Understanding This Hack Federal authorities have quickly investigated a cyberattack known as Salt Typhoon, linked to China-backed hackers. According to an anonymous U.S. official, these attackers targeted multiple U.S. telecommunications firms, including Verizon, AT&T, and Lumen Technologies. They compromised systems explicitly used by government intelligence collection capabilities such as wiretaps. The implications of this breach extend far beyond corporate walls, posing potential threats to national security. Chinese hackers compromised telecom systems and breached U.S. intelligence systems used for lawful surveillance, such as wiretapping. Investigators are meticulously studying the depth to which hackers have penetrated these networks and whether these criminals have extracted sensitive data. Lawmakers' Reaction to This Incident This incident has sparked significant concern among U.S. lawmakers, with Senator Ron Wyden of Oregon leading the charge by calling upon both the Justice Department and Federal Communications Commission (FCC) to implement stringent security standards for telecom companies' wiretapping systems. He specifically mentioned an outdated regulatory framework as he expressed disappointment over how the DOJ dealt with cyberattacks, which he considered negligent. Wyden suggested setting baseline cybersecurity standards that can be enforced through fines while conducting annual third-party cybersecurity auditsby an independent firm. He also advocated for full transparency regarding data breaches among Congress, investigators, and the public, holding negligent corporations responsible - an approach that signals a shift toward corporate accountability rather than prosecuting foreign hackers who rarely find justice in U.S. court systems. What Are Encryption Backdoors? Encryption backdoors are built into encrypted systems to give authorized authorities access to encrypted data for regulatory or national security reasons. Still, if discovered, they can potentially be exploited by malicious actors. Encryption is at the core of modern cybersecurity, protecting sensitive information from unintended access and modification. Robust encryption protocols also facilitate secure communications, safeguard individual privacy, and enhance national security. Examining the Pros & Cons of Encryption Backdoors Encryption backdoors offer both advantages and drawbacks. On one side, they can improve national security by aiding law enforcement with lawful surveillance operations and efficient investigations by providing necessary access to encrypted data. On the other hand, however, they could threaten national security. Encryption backdoors may help ensure compliance in critical infrastructure sectors like telecom and finance; however, their advantages come with potential drawbacks that should not be ignored. Backdoors introduce inherent vulnerabilities into systems, rendering them insecure without discriminating between good and bad actors. Unauthorized individuals could exploit them to access sensitive data. Recent hacks by China have illustrated how malicious actors can exploit backdoors to access data via backdoors, thus endangering national security and corporate confidentiality. Encryption backdoors can potentially erode public trust in cybersecurity and privacy efforts, discouraging users from adopting encryption technologies. Finally, exploited backdoors may lead to security breaches with substantial financiallosses, legal liabilities, and damage to corporate reputations. What Is the Security Community's Stance on Encryption Backdoors? Security experts have long opposed encryption backdoors as contrary to encryption's very purpose. China-backed hacks prove that backdoors can be dangerous. By exploiting backdoor access mechanisms, hackers can gain entry to systems considered secure by encryption. Leading cybersecurity experts advocate for solid encryption without any backdoors. Vital, unbreakable encryption is critical for protecting against sophisticated cyber threats, ensuring personal privacy, and maintaining national security systems' integrity. Responsible encryption involves designing systems to minimize risks without including backdoors. Our Final Thoughts: The Potential Risks of Encryption Backdoors Outweigh Their Advantages Recent attacks targeting U.S. telecom companies highlight the vulnerabilities posed by encryption backdoors. Although intended for national security and regulatory compliance purposes, backdoors present vulnerabilities that malicious actors can exploit—even state-sponsored hackers—looking for vulnerabilities they can use to breach national security and regulatory compliance. As digital ecosystems mature and cyber threats grow increasingly sophisticated, robust encryption without backdoors remains essential to safeguard sensitive information, maintain personal privacy, and fortify national security systems from unintended access. Instead of compromising encryption standards, policymakers should improve cybersecurity protocols, revise regulatory frameworks, and hold corporations accountable for their security practices. Encryption backdoors may seem beneficial regarding law enforcement and regulatory compliance, yet their inherent risks far outweigh their perceived advantages. This is demonstrated by China-backed hacks, such as those perpetrated against our digital infrastructures by hackers armed with access devices from China. Robust encryption without backdoorsmust be implemented for optimal digital security. . The U.S. investigation into hacking by Chinese operatives raises tensions, impacting corporate regulations, international alliances, and public trust in technology security.. Telecom Cybersecurity, Encryption Backdoors, Cybersecurity Legislation, National Security Issues. . Brittany Day

Calendar%202 Oct 16, 2024 User Avatar Brittany Day Hacks/Cracks
83

Noodle RAT Threat Analysis: Strategies For Linux Security

A new backdoor, "Noodle RAT" has caused widespread alarm across the cybersecurity landscape. Research highlights this previously undisclosed malware used by Chinese-speaking groups engaged in cybercrime and espionage activities. . This article seeks to provide a thorough understanding of this threat for Linux administrators who wish to better protect themselves against Noodle RAT and similar attacks. We'll focus specifically on the Linux variant of this cross-platform malware and how it infects targeted systems. Understanding Noodle RAT Since 2022, Noodle RAT has been under scrutiny due to targeted attacks in the Asia-Pacific region. At first, it was thought to be part of existing malware such as Gh0st RAT or Rekoobe, but intensive research revealed it as being brand new. The malware, available on Windows and Linux, has been employed by Chinese-speaking groups for espionage and cybercrime activities, demonstrating its widespread impact. Noodle RAT typically exhibits capabilities such as downloading/uploading files/running additional in-memory modules, and acting as TCP proxy on infected computers, underscoring its widespread usage among target systems. The Linux Version of Noodle RAT: How Does It Infect Targeted Systems? Linux.NOODLERAT stands out from its Windows counterpart through its design and capabilities, which have been widely employed for financial gain and espionage purposes by various groups for their ends. Employed for different motivations, including financial gains or spying operations, its design features include reverse shell functionality, file download/upload features, scheduling execution of scheduled processes, and SOCKS tunneling capabilities. After infiltrating public-facing applications, the backdoor copies itself to an identified location before performing process name spoofing and connecting back with its C&C server per predefined settings, making its design unique from its Windows counterpart regarding design vs. capabilities. Practical Advice for ProtectingAgainst Noodle RAT and Similar Threats With cyber threats evolving almost daily, Linux administrators must take proactive measures to ward off threats like Noodle RAT. Here are several practical steps you can take to reinforce the security posture of your systems: Implement Comprehensive Access Controls: Comprehensive access controls and user permissions can significantly limit unauthorized access and help stop the installation and execution of malicious payloads. Prioritize Regular System Updates and Patch Management: Timely installation of software updates and security patches can address known vulnerabilities exploited by backdoors like Noodle RAT. Implement Strong Authentication Measures: Establishing multifactor authentication and enforcing robust password policies are great strategies for protecting against any unauthorized access attempts. Utilize Network Segmentation: Dividing the network into distinct zones according to traffic patterns and user roles can help contain malware spread and limit its impact in case of breach. Implement Intrusion Detection and Prevention Systems: Installing and configuring effective intrusion detection and prevention systems is one way to detect and respond quickly to attempted infiltration by Noodle RAT or similar threats. Utilize Behavior-Based Monitoring: Behavior-based monitoring tools can enable administrators to detect suspicious and potentially malicious behaviors that indicate backdoor activities. Regular Security Audits and Penetration Testing: Conducting periodic security audits and penetration tests is one way to identify vulnerabilities before threat actors exploit them. User Education and Awareness Programs: Raising users' awareness of the potential dangers of social engineering tactics and phishing attacks can significantly lower the odds of successful backdoor installations. Our Final Thoughts on Noodle RAT & Preventing Attacks Noodle RAT's rise as an emerging backdoor threatunderscores the necessity of strong cybersecurity measures for Linux systems. By understanding its functionality and employing proactive security practices to strengthen defenses against this malicious malware, administrators can better protect themselves and reduce the risks from falling victim. As the cyber threat landscape changes rapidly, remaining vigilant and proactive when protecting essential infrastructure and sensitive data against emerging threats like Noodle RAT is imperative for maintaining and securing its integrity and safety. . Gain insights on Noodle RAT's impact on Linux systems and strategies to enhance security against this new backdoor threat.. backdoor, noodle, rat', caused, widespread, alarm, across, cybersecurity, landscape, researc. . Dave Wreski

Calendar%202 Jun 11, 2024 User Avatar Dave Wreski Hacks/Cracks
83

Gomir Linux Backdoor Threat Analysis: Kimsuky APT Insights and Defense

The Kimsuky APT group, reportedly linked to North Korea's Reconnaissance General Bureau (RGB), has been identified deploying a Linux version of its GoBear backdoor called Gomir. The Gomir backdoor is structurally similar to GoBear, leading to concerns within the cybersecurity community. The overlapping code between malware variants raises questions regarding the extent of the threat and the potential implications for targeted organizations. Let's explore the significance of this discovery and its implications for the Linux community so you are better prepared to protect against Gomir and other Linux malware variants. . How Does Gomir Work & What Are Its Implications for Linux Admins? In technical terms, Gomir, the Linux backdoor, supports several commands, enabling its operators to carry out file operations, initiate a reverse proxy, pause command-and-control communications, execute shell commands, and terminate its own process. The existence of these capabilities demands robust security protocols within Linux systems , including monitoring and controlling command executions to prevent the misuse of these privileges by threat actors. Security researchers initially documented GoBear in connection with a campaign involving malware known as Troll Stealer, suggesting that these activities are part of a larger, coordinated effort by the Kimsuky APT group to infiltrate organizations in South Korea. Moreover, the distribution of the malware through trojanized security programs downloaded from a South Korean construction-related association's website is noteworthy. This points to the pressing need for organizations to meticulously assess the integrity of the software they download and use. Using rogue installers for Wizvera VeraPort to deliver Troll Stealer further emphasizes the need for improved supply chain security measures to prevent the spread of malicious software. This includes modernizing processes, reviewing and updating permissions throughout the supply chain, and verifying code beforedeploying it. The broader implication of this report is the emerging pattern of software installation packages and updates being exploited as favored infection vectors for espionage activities. Recognizing this trend is essential for security practitioners and underscores the urgency of ensuring the authenticity and security of software updates and installation packages. Our Final Thoughts on Gomir The emergence of Gomir and the tactics employed by the Kimsuky APT group in targeting South Korean organizations demonstrate the need for enhanced vigilance and proactive security measures. Linux admins should take note of these developments and evaluate their security postures to mitigate the risk such advanced persistent threat groups pose to their systems. . Gomir, a concerning malware variant, poses threats to Linux security. Understanding its tactics is vital for enhancing system defenses against such intrusions. Linux Backdoor,Kimsuky APT,Security Threats,Malware Defense,Linux Security. . Brittany Day

Calendar%202 May 30, 2024 User Avatar Brittany Day Hacks/Cracks
210

XZ Utils Backdoor Incident: Lessons and Implications for Linux Security

The alarming discovery of a backdoor in the xz data compression library , which had the potential to compromise Linux systems, has dominated recent security news. While the backdoor did not make its way into production Linux distributions, the incident raises crucial questions about open-source security and the need for vigilance in the face of emerging threats. . How Was This Backdoor Introduced? What Were the Motives Behind It? A Microsoft software engineer, Andres Freund, detected the slow performance of the SSH remote security code in the Debian Linux beta. This discovery led Freund to investigate and identify that Jia Tan, the chief programmer and maintainer of the xz library , had inserted a backdoor to enable attackers to gain control over Linux systems. This incident is notable because, until now, malware has not been successfully concealed within Linux code. Linux managed to evade a potentially catastrophic situation thanks to its open-source nature . Mark Atwood, Amazon's open-source program office principal engineer, highlights that the attack failed precisely because the code was open and accessible to scrutiny. In contrast, closed-source components often present challenges in detecting and mitigating covert attacks. The motives behind the backdoor are unknown, but we can speculate the possibility of crypto miners attempting to infiltrate high-powered Linux systems to capitalize on the surging value of cryptocurrencies. While the exact identity of the attacker remains unknown, their extensive efforts to compromise the xz project in 2021 and push the infected program into Linux distributions are evident. What Are the Implications of This Backdoor? What Can the Community Learn from This Issue? This issue raises critical questions about the security implications of open-source software and the Linux community's underlying responsibility to ensure its code's safety. It underscores the importance of continuous code review, especially within the open-source supply chain , toidentify and address vulnerabilities promptly. The incident with the xz backdoor serves as a wake-up call for Linux admins, infosec professionals, internet security enthusiasts, and sysadmins. The potential consequences of such an attack could have been catastrophic, compromising individual systems and entire infrastructures. It highlights the need for a proactive approach to security and the constant evolution of defensive measures to match emerging threats. This incident also sheds light on the possibility of additional open-source malware programs that have yet to be discovered. This raises questions about the overall security posture of the Linux ecosystem and the measures put in place to detect and prevent future attacks. It prompts security practitioners to reflect on the current defenses and collaborate on strengthening the entire open-source supply chain against persistent threats. Our Final Thought on the XZ Utils Linux Backdoor The close call that Linux encountered with the xz backdoor incident highlights the critical need for continuous code review and an engaged security community. It underscores the importance of maintaining a disciplined and vigilant approach to open-source security rather than relying solely on the assumption that open-source code is inherently secure. Security practitioners, Linux admins, infosec professionals, internet security enthusiasts, and sysadmins play a crucial role in upholding the security and integrity of open-source software. This incident serves as a reminder to stay alert , actively contribute to code review efforts, and collaborate with the broader community to safeguard against potential threats that may have long-term consequences. . The xz utils backdoor incident has highlighted vulnerabilities in open-source software, stressing the need for rigorous code audits, secure supply chains, and a security-first mindset. xz Utils, Open Source Threats, Backdoor Security, Linux Risks. . Brittany Day

Calendar%202 Apr 21, 2024 User Avatar Brittany Day Security Vulnerabilities
210

Red Hat & Debian: Critical Backdoor in xz Utility Impacts SSH Security

A backdoor in the widely used xz compression utility has been discovered, posing a severe threat to Linux users. The issue is tracked as CVE-2024-3094 and has a maximum CVSS score of 10. Read on to learn if you're using a vulnerable version. . This revelation has significant implications for Linux admins and infosec professionals. We'll explore how this vulnerability works, the implications and consequences, and how you can secure your systems against this threat. How Does This Threat Work? A significant security vulnerability, identified as CVE-2024-3094, involving a backdoor within the widely used xz compression utility, has been brought to light. This presents a potentially severe threat to Linux distributions, including Red Hat and Debian. The backdoor, detected in xz Utils versions 5.6.0 and 5.6.1, was discovered before infiltration into major Linux production releases, narrowly avoiding severe consequences for encrypted SSH connections globally. This episode underscores the peril within open-source supply chains, highlighting the indispensable roles played by community vigilance and technical scrutiny. This threat was embedded within beta releases of Fedora and Debian distros but was identified swiftly thanks to the attentiveness of the development community. The backdoor mechanism was cleverly engineered to compromise SSH authentication by injecting malicious code into the sshd binary, potentially allowing unauthorized access to affected systems. The urgency and significance of this discovery cannot be overstated, prompting immediate action within the open-source community to mitigate risks and secure affected systems. The swift response to this threat illustrates the critical importance of proactive security measures, the collective responsibility of the open source community in safeguarding the ecosystem, and the ongoing challenges posed by software supply chain security. What Are the Security Implications of This Backdoor? One intriguing aspect of this threat is the methodused to compromise the utility. The malicious actors added obfuscated .m4 files to the xz tarballs, which were heavily disguised to hide their true intentions. This raises questions about the security practices surrounding the xz project . How did an active contributor to the xz project include these files without being detected? Were there vulnerabilities in the project's code review process? The consequences of this backdoor are far-reaching. Modifying the compression library liblzma affects Linux distributions that incorporate libsystemd, which is dependent on liblzma. This means SSH services in these Linux distros could be exposed to unauthorized access. The potential compromise of SSH has severe implications for security practitioners, as SSH is a fundamental tool used to access and manage systems remotely. Furthermore, the involvement of an active contributor to the xz project for two years raises concerns about insider threats and the trust placed in open-source contributors. It highlights the need for robust vetting processes and continuous monitoring of open-source projects , especially those widely used. How Can I Mitigate My Risk? The urgency of the issue is reflected in the response from authorities. The U.S. Cybersecurity & Infrastructure Security Agency (CISA) released an alert emphasizing the severity of the backdoor and urging developers and users to downgrade xz to a safe version. Red Hat also published an urgent security alert , advising users to halt the use of Fedora Rawhide and downgrade Fedora Linux 40 to safeguard against potential compromises. These actions indicate the seriousness of the threat and the importance of immediate action. Our Final Thoughts on Securing Linux Systems Against This Backdoor The discovery of a backdoor in the widely used xz compression utility poses a significant threat to Linux distributions and SSH services. This article brings attention to the gravity of the situation, raises pertinent questions about open-source security practices, andhighlights the need for immediate action and ongoing vigilance . As security practitioners, it is crucial to stay informed, carefully vet open-source contributions, and take proactive measures to protect systems from potential compromises. . A critical vulnerability in the zip archiving tool endangers Windows platforms and remote login capabilities. Swift response is crucial!. xz Utility Backdoor, SSH Security, Open Source Threats, Linux Admin Guide. . Brittany Day

Calendar%202 Apr 03, 2024 User Avatar Brittany Day Security Vulnerabilities
83

APT10: New Linux Backdoor Derived From Trochilus Malware

Researchers have discovered a never-before-seen backdoor for Linux that’s being used by a threat actor linked to the Chinese government. . The new backdoor originates from a Windows backdoor named Trochilus, which was first seen in 2015 by researchers from Arbor Networks, now known as Netscout. They said that Trochilus executed and ran only in memory, and the final payload never appeared on disks in most cases. That made the malware difficult to detect. Researchers from NHS Digital in the UK have said Trochilus was developed by APT10, an advanced persistent threat group linked to the Chinese government that also goes by the names Stone Panda and MenuPass. Other groups eventually used it, and its source code has been available on GitHub for more than six years. Trochilus has been seen being used in campaigns that used a separate piece of malware known as RedLeaves. . Uncover the fresh Linux exploit associated with the Chinese state-sponsored APT10 faction, tracing its roots back to Trochilus.. Linux Backdoor,APT10 Threat,Chinese Cybersecurity,Malware Threats,Advanced Persistent Threats. . LinuxSecurity.com Team

Calendar%202 Sep 19, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Free Download Manager Breached: Three Years of Malware on Linux

Researchers discovered a free download manager site that has been compromised to serve Linux malware to users for more than three years. . Researchers from Kaspersky discovered a free download manager site that has been compromised to serve Linux malware. While investigating a set of suspicious domains, the experts identified that the domain in question has a deb.fdmpkg[.]org subdomain. Visiting the subdomain with the browser, the researchers noticed a page claiming that the domain is hosting a Linux Debian repository of software named ‘Free Download Manager’. This package turned out to contain an infected postinst script that is executed upon installation. This script drops two ELF files to the paths /var/tmp/crond and /var/tmp/bs. It then establishes persistence by creating a cron task (stored in the file /etc/cron.d/collect) that launches the /var/tmp/crond file every 10 minutes.” reported Kasperksy. The “Free Download Manager” version installed by the malicious package was released on January 24, 2020. The experts found comments in Russian and Ukrainian, including information about improvements made to the malware, in the postinst script. . Cybersecurity analysts from Kaspersky have revealed a prolonged breach lasting three years that distributed Linux malware through a hacked download manager platform.. Linux Malware Threats, Backdoor Exploits, Compromised Software, Security Risks. . LinuxSecurity.com Team

Calendar%202 Sep 16, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Barracuda Email Security: Exploitation Of SUBMARINE Backdoor Threat

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday disclosed details of a "novel persistent backdoor" called SUBMARINE deployed by threat actors in connection with the hack on Barracuda Email Security Gateway (ESG) appliances. . "SUBMARINE comprises multiple artifacts — including a SQL trigger, shell scripts, and a loaded library for a Linux daemon — that together enable execution with root privileges, persistence, command and control, and cleanup," the agency said . The findings come from an analysis of malware samples obtained from an unnamed organization that had been compromised by threat actors exploiting a critical flaw in ESG devices, CVE-2023-2868 (CVSS score: 9.8), which allows for remote command injection. Evidence gathered so far shows that the attackers behind the activity, a suspected China nexus-actor tracked by Mandiant as UNC4841, leveraged the flaw as a zero-day in October 2022 to gain initial access to victim environments and implanted backdoors to establish and maintain persistence. To that end, the infection chain involved sending phishing emails with booby-trapped TAR file attachments to trigger exploitation, leading to the deployment of a reverse shell payload to establish communication with the threat actor's command-and-control (C2) server, from where a passive backdoor known as SEASPY is downloaded for executing arbitrary commands on the device. SUBMARINE, also codenamed DEPTHCHARGE by the Google-owned threat intelligence firm, is the latest malware family to be discovered in connection with the operation. Executed with root privileges, it resides in a Structured Query Language (SQL) database on the ESG appliance. The link for this article located at The Hacker News is no longer available. . AQUANAUT infiltration tactic leverages SQL procedures and code, targeting a significant vulnerability in Cisco Web Security Appliances.. Barracuda Email Security,SUBMARINE,Command Injection,Cyber Threat. . LinuxSecurity.com Team

Calendar%202 Jul 29, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200