A new and previously undetected malware dubbed 'Lightning Framework' targets Linux systems and can be used to backdoor infected devices using SSH and deploy multiple types of rootkits. . Described as a "Swiss Army Knife" in a report published today by Intezer, Lightning Framework is a modular malware that also comes with support for plugins. "The framework has both passive and active capabilities for communication with the threat actor, including opening up SSH on an infected machine, and a polymorphic malleable command and control configuration," Intezer security researcher Ryan Robinson said . . Tempest Suite is an emerging Linux malicious software that deploys rootkits and covert entry points, enabling unauthorized SSH connections for cybercriminals.. Linux Malware, Rootkit Threats, DDoS Backdoor, Lightning Framework, Open Source Security. . LinuxSecurity.com Team
In the field of cryptography, a secretly planted . Now one group of crypto experts has published an appraisal of different methods of weakening crypto systems, and the lesson is that some backdoors are clearly better than others The link for this article located at Wired is no longer available. . Examining tactics to breach encryption frameworks, informed by specialist evaluations of vulnerabilities in cryptographic practices.. Encryption Techniques,Cryptography Analysis,Security Backdoors,Attack Methods,Crypto Weaknesses. . LinuxSecurity.com Team
At the beginning of the year, I did something I've never done before: I made a new year's resolution. From here on out, I pledged, I would install only digitally signed software I could verify hadn't been tampered with by someone sitting between me and the website that made it available for download. . It seemed like a modest undertaking, but in practice, it has already cost me a few hours of lost time. With practice, it's no longer the productivity killer it was. Still, the experience left me smarting. In some cases, the extra time I spent verifying signatures did little or nothing to make me more secure. And too many times, the sites that took the time to provide digital signatures gave little guidance on how to use them.. Examining the critical role of software validation in cryptocurrency applications, to guarantee digital security and integrity.. Secure Software, Digital Signature Verification, Crypto Backdoors. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.