Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Aqua Security's Cloud Native Threats report reveals that 50% of new Docker instances are attacked within 56 minutes, among other key findings. . Fifty percent of new misconfigured Docker instances are attacked by botnets within 56 minutes of being set up, Aqua Security said in its 2020 Cloud-Native Report. Five hours, on average, is all it takes for an attacker to scan a new honeypot , the pure-play cloud native security company said. The majority of attacks were focused on crypto mining , which may be perceived as “ more of a nuisance than a severe threat,” Aqua Security noted. However, 40% of attacks also involved backdoors to gain access to the victim’s environment and networks. Backdoors were enabled by dropping dedicated malware or creating new users with root privileges and SSH keys for remote access. More than 36% of attacks involved worms to detect and infect new victims. . Cybercriminals exploit nearly 50% of improperly secured Docker deployments in just under an hour, highlighting severe vulnerabilities in system security practices.. Docker Security, Containerized Attacks, Cloud Native Threats, Malware Trends. . Brittany Day
Botnet operators have always been able to easily infect and convert PCs into bots, but they also are increasingly going after servers -- even building networks of compromised servers. Web servers, FTP servers, and even SSL servers are becoming prime targets for botnet operators, not as command and control servers or as pure zombies, but more as a place to host their malicious code and files, or in some cases to execute high-powered spam runs.. "FTP servers are a hot commodity in the underground. They are regularly used by drive-by download malware as well as a downloading component for regular bots," says Mikko Hypponen, chief research officer at F-Secure. "Another thing we've noticed is the use of SSL servers. Sites with a valid SSL certificate get hacked and are used by drive-by-downloads." Why SSL servers? "If a drive-by download gets the malware file through an HTTPS connection, proxy and gateway scanners won't be able to scan for the malware in transit, making it easier to sneak in," Hypponen explains. The link for this article located at Dark Reading is no longer available. . 'FTP servers are a hot commodity in the underground. They are regularly used by drive-by download ma. botnet, operators, always, easily, infect, convert. . Alex
Get the latest Linux and open source security news straight to your inbox.