Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 7 articles for you...
83

The Rise of Cloud-Native Ransomware Threats and Prevention Strategies

Over the past few years, ransomware has evolved into a highly advanced type of malicious software, targeting individual systems and entire enterprises with increasingly sophisticated attacks. However, the most recent and worrying trend in this evolution is the advent of the cloud-native ransomware. . Unlike conventional ransomware, which targets endpoints or local servers, cloud-native versions are specifically designed to target cloud infrastructure. As more businesses shift their workloads to platforms like AWS, Azure, and Google Cloud, threat actors are adapting their strategies to keep pace. For example, SOC Managed Services have played a pivotal role in this environment, assisting organizations to track, identify, and counter these new threats in real time. The need to defend against ransomware is no longer met by the traditional approach since attackers can now exploit native cloud features and configurations. Many organizations now rely on third-party security monitoring to provide 24/7 visibility and response capabilities tailored to complex cloud environments Learning the Cloud-Native Ransomware Threat Cloud-native ransomware is created to target applications, data, and backup in a cloud environment. Such attacks do not simply encrypt the data on an individual machine, but rather exploit misconfigurations in cloud services to gain access to complete storage buckets, database instances, or containerized applications. After gaining access, such strains of ransomware can spread horizontally within cloud accounts, destroy backup snapshots, and encrypt essential resources. The stealth of this new wave of ransomware is one of its most concerning aspects. Most of these attacks never even get detected by the endpoint, since they do not use traditional file-based malware. They would rather employ APIs , automated scripts, and stolen credentials via phishing or identity theft. The attackers can go undetected until it is too late by taking advantage of the cloud infrastructuredirectly. Such a change represents a paradigm shift in the way organizations must approach security. The traditional perimeter-based endpoint and network firewall defense model does not translate well to the cloud. Identity, access management, and automation controls are the new gatekeepers in the cloud--and they are constantly under attack. The Reason Cloud Environments are a Popular Target The cloud infrastructure offers massive scalability and flexibility, but it also creates a much broader attack surface. Attackers access through misconfigured storage buckets, overly permissive roles, and weak credential hygiene, to name only a few. This is further complicated in a multi-cloud and hybrid environment where there may be significant differences in visibility and control across platforms. The second way that makes cloud environments such good targets is the use of backups and disaster recovery systems. These are intended to be the last resort for an organization. Yet, contemporary ransomware gangs are aware of this as well. Access to the control plane allows them typically to destroy or corrupt cloud backups before initiating the encryption stage of their attack. This makes organizations unable to restore data without paying the ransom, which makes a payout more likely. The risks can be mitigated through a cloud security assessment. Periodic review of configuration, access controls, and backup procedures is a good way to identify vulnerabilities before they are exploited. Security teams should also evaluate process vulnerabilities, as they may enable attackers to use automation scripts or API keys in publicly available repositories. Case Studies and Practical Influence Several high-profile cases of ransomware actors targeting cloud-native services have already occurred. Attackers have primarily used poorly configured permissions to gain access and encrypt object storage services, such as Amazon S3 or Azure Blob Storage. In others, they compromised administrative credentials, disabled security monitoring tools , and deleted system logs. Such attacks are financially devastating. In addition to the ransom itself, which may cost millions of dollars, organizations have to cope with downtime, reputational loss, and regulatory and legal risks. In controlled sectors such as healthcare or finance, the ramifications of a data breach resulting from an incident involving ransomware may include compliance fines and reputational damage. Furthermore, cloud-native attacks may be on a much bigger scale than conventional ransomware attacks. Since cloud services tend to concentrate essential data and functions, one breach can cause a chain effect on various applications and departments. The Changing Perimeter in a Cloud-First World Organizations should include a cloud-first cybersecurity strategy to keep up with these threats. This involves the incorporation of security in each phase of the cloud lifecycle, including design and deployment, maintenance, and monitoring. It also implies the automation of not only operations, but also the enforcement of security. Cloud-based security tools, such as cloud workload protection platforms (CWPP) and cloud security posture management (CSPM), as well as identity governance solutions, are increasingly critical tools in the ransomware battle. These tools help monitor the configurations, policy enforcement, and detect anomalous behavior, which could imply that an attack is in progress. Cloud teams often turn to CIEM to understand who really has access to sensitive workloads and to cut back excessive permissions before they are abused. Teams trying to reduce hidden exposure are increasingly looking to Identity Security Posture Management for better visibility into risky permissions, weak controls, and identity misconfigurations. However, it is not only the technology. A contemporary ransomware response strategy should include playbooks tailored to specific cloud events. These playbooks should be tested by the teams regularly, and the membersshould simulate their attacks to know where they are vulnerable. The presence of an escalation plan, with legal and communications strategies, would help significantly to eliminate the confusion during a real incident. The Future of Ransomware Is in the Cloud The hypothetical threat of cloud-native ransomware is not a thing. It is upon us and is transforming the scenery of cybercrime , compelling organizations to reimagine their security measures on an entirely new level. With more companies using cloud-based infrastructure, the targets are growing too, and with it, the sophistication of attacks. Although no system is immune to it, being vigilant by conducting proactive assessments, robust access controls, and constant monitoring can greatly minimize it. The advanced tooling, coupled with well-trained teams, presents the most significant possibility of defense in a world where data is no longer stored in physical vaults but is freely passed across the cloud. Organizations that will succeed in this new age are those that view security not as a reactive role, but as an ongoing, seamless component of their cloud strategy. . As cyber threats evolve, cloud-native ransomware emerges as a major risk, targeting cloud infrastructures and critical data with advanced tactics that exploit vulnerabilities. Cloud-Native Ransomware, Cybersecurity Threats, Data Breach Prevention, Cloud Infrastructure Security. . MaK Ulac

Calendar%202 Aug 13, 2025 User Avatar MaK Ulac Hacks/Cracks
83

CentOS 7: TeamTNT Attack Advisory moderate: Brute Force Total Compromise

Security researchers have recently observed an alarming resurgence of TeamTNT , a notorious hacking group known for targeting cloud infrastructures. Their latest campaign zeroes in on Virtual Private Server (VPS) environments running CentOS, particularly version 7. . On a broader scale, this threat highlights the growing complexity of securing cloud infrastructure and the risks associated with running outdated systems like CentOS 7. To help you better understand and proactively address this emerging threat, I'll discuss the nature of these attacks, what makes CentOS 7 an attractive attack target, and practical steps Linux admins and organizations can take to mitigate risk. The Anatomy of the Attack TeamTNT's attack methodology has evolved over the years, making it a significant threat to cloud infrastructures. The latest campaign begins with a Secure Shell (SSH) brute force attack on the target's assets. Once access is gained, a malicious script is uploaded, which initiates a series of harmful actions to compromise the server's security. The script is multifaceted, involving the following tactics and steps: Disable Security Features: It starts by disabling the existing security mechanisms to avoid detection. Log Deletion & System Modification: It deletes logs and modifies crucial system files to cover its tracks. Crypto Miner Killer: The script searches for and kills existing cryptocurrency mining processes, ensuring that TeamTNT can monopolize the system's resources. DNS Setting Changes: DNS settings are altered to Google’s servers, possibly to bypass existing security filters. Rootkit Installation: The script installs the Diamorphine rootkit , a loadable kernel module that covertly allows the attacker to execute malicious activities. Backdoor Creation: It also creates a backdoor user with root access and installs a public key for secure access. The Diamorphine rootkit provides covert capabilities such as silent execution, hiding processes,and allowing the attacker to gain root access at will. Additionally, the script further locks down the system by modifying file attributes, making it difficult for administrators to unlock and recover protected files. Why Is CentOS 7 Particularly Vulnerable? CentOS 7, while widely used, is particularly vulnerable for several reasons: Discontinued Support: Although still prevalent, CentOS 7 no longer receives regular updates and security patches, making these systems an easy target for attackers. Older Kernel Vulnerabilities: CentOS 7 runs on older Linux kernel versions, which may contain vulnerabilities that have been patched in later releases. Usage in Cloud Environments: CentOS 7 is commonly used in VPS and cloud environments, making it an attractive target for cryptojacking and other resource-intensive attacks. These inherent vulnerabilities and often lax security practices in cloud setups make CentOS 7 an ideal target for TeamTNT's malicious campaigns. TeamTNT's Resurgence Highlights The Growing Complexity of Securing Cloud Infrastructures The resurgence of TeamTNT underscores a broader trend: the increasing complexity of securing cloud environments. The attack surface has significantly expanded with the rapid adoption of cloud-native technologies like Kubernetes and Docker. Sophisticated threat actors can easily exploit misconfigurations and weak security practices. As cloud deployments become more complex, so do threat actors' tactics, requiring organizations to evolve their security measures continually. Practical Mitigation Strategies for Admins & Organizations To protect against these sophisticated attacks, Linux administrators must adopt a multi-layered security approach. Here are some specific and practical steps they can implement: Strengthen SSH Configurations: Use strong, unique passwords or SSH keys for authentication. Disable root login via SSH and create a separate user with sudo privileges. Implement rate limiting and intrusion detectiontools like Fail2Ban to thwart brute force attacks. Regular Updates and Patch Management: Update your OS regularly and apply the latest security patches . For CentOS 7, consider using community-supported repositories for essential updates. Kernel Hardening: Use module signing and disable loadable kernel modules unless necessary. Implement kernel hardening measures like SELinux or AppArmor. Monitor for Rootkits: Employ rootkit detection tools like chkrootkit and rkhunter . Regularly check for unusual system behaviors that could indicate rootkit installation. Secure Containerized Environments: Ensure Docker and Kubernetes configurations follow security best practices. This includes setting resource limits, network segmentation, and enabling role-based access control. Firewall Configuration: Set firewalls to allow only essential services and restrict SSH access to a select set of IP addresses. Enhanced Security Measures: Utilize security tools that rapidly detect and respond to advanced threats. Security Information and Event Management (SIEM) solutions and Intrusion Detection Systems (IDS) can mitigate risks before they escalate. Our Final Thoughts on This Emerging Linux Security Threat The resurgence of TeamTNT serves as a stark reminder of the growing threats to cloud infrastructures. While CentOS 7 remains a popular choice for VPS, its discontinuation and associated vulnerabilities make it an attractive target for sophisticated cybercriminals. By implementing robust security practices, regularly updating systems, and continuously monitoring for threats, Linux administrators can significantly mitigate the risks posed by groups like TeamTNT. Securing cloud environments is an ongoing battle, but organizations can stay one step ahead of malicious actors with the right strategies and tools in place. . Analyzes the emergence of TeamTNT as a formidable menace targeting CentOS VPS, focusing on their tactics, exploited weaknesses, and countermeasures for Linuxsystem administrators.. TeamTNT Threats, Securing CentOS 7, VPS Security Best Practices, Linux Attack Mitigation, Cloud Security Challenges. . Anthony Pell

Calendar%202 Sep 23, 2024 User Avatar Anthony Pell Hacks/Cracks
212

How to Protect Linux Cloud Infrastructure From 8220 Gang Attacks

A recent increase in attacks has been observed from the 8220 Gang, a cybercriminal group from China. The group has become notorious for infiltrating cloud-based infrastructure and exploiting vulnerabilities to mine cryptocurrency from Linux and Windows users. . How Do These Attacks Work & How Can I Mitigate My Risk? One of the most significant concerns surrounding these attacks is the group's use of well-known vulnerabilities, such as CVE-2021-44228 and CVE-2022-26134 , which poses a heightened risk to cloud security worldwide. The 8220 Gang identifies potential entry points through internet scans and exploits unpatched vulnerabilities to gain unauthorized access to cloud systems. This shift towards more sophisticated techniques is a critical evolution in cyber threats facing cloud infrastructure today. The implications of these attacks are far-reaching, affecting countless organizations that rely on cloud infrastructure. The group's use of tools, including Tsunami malware , XMRIG cryptominer, masscan, and spirit, allows them to deploy cryptocurrency miners on compromised Linux and Windows hosts. This poses significant risks to the integrity and performance of the affected systems and will enable cybercriminals to profit from unauthorized mining operations. Organizations must prioritize cloud security and adopt comprehensive strategies to protect against these advanced threats. This includes ensuring that all systems are regularly updated and patched , implementing robust security measures, and maintaining vigilance for any signs of compromise. As the 8220 Gang continues to evolve its strategies, the cybersecurity community must remain proactive in detecting and mitigating these threats. This situation raises several questions regarding the responsibility of organizations to ensure their cloud infrastructure remains secure, particularly in the wake of new and more sophisticated techniques used by cybercriminals. Companies need to invest in cybersecurity and prioritize responses toemerging cyber threats. Furthermore, the 8220 Gang's recent campaigns highlight the need for further collaboration and information sharing between international cybersecurity experts to prevent such attacks from becoming widespread. Our Final Thoughts on Combating This Increase in Attacks The 8220 Gang's recent escalation in attacks on both Linux and Windows users is concerning. Organizations must ensure all systems are regularly updated and patched and adopt robust security measures to protect against advanced threats. The cybersecurity community must remain proactive in detecting and mitigating these threats. Be sure to subscribe to our newsletters to stay up-to-date on critical news, trends, and advisories impacting the security of your Linux systems. . Uncover the techniques utilized by the 8220 Syndicate to leverage system flaws for cryptocurrency mining on both Linux and Windows platforms. Secure your devices!. Linux Security, Cloud Cybersecurity, Malware Threats, Cryptocurrency Mining, Cybersecurity Preparedness. . Brittany Day

Calendar%202 Feb 27, 2024 User Avatar Brittany Day Cloud Security
76

KubeCon Highlights Future IT Trends with Kubernetes Innovations

Cloud has become synonymous with enterprise IT, but let’s not get ahead of ourselves. Though enterprises now spend roughly $545 billion annually on cloud infrastructure, according to IDC, and 41% of that spend goes to the top five cloud providers, the reality is that a substantial amount of money, even “cloud” money, isn’t being spent with the big hyperscalers. . Instead, it’s being plowed into other companies pitching Kubernetes and associated infrastructure. “Open and approachable” may define the future of the $500 billion cloud infrastructure market. If you want to see the future of enterprise IT, you’d do well to pay attention to this week’s KubeCon in Chicago. As has been the case for years, open source is driving the future of enterprise infrastructure, with projects such as eBPF/Cilium, Tetragon, and OpenTelemetry playing major roles. But it’s not just about open access to code. If anything, these projects may benefit more from how they make difficult domains accessible to mere mortals. . Organizations invest in container orchestration and foundational systems, guiding the trajectory of corporate technology in light of shifting paradigms.. Kubernetes, Cloud Infrastructure, Enterprise IT, Open Source Innovations. . Brittany Day

Calendar%202 Nov 09, 2023 User Avatar Brittany Day Organizations/Events
77

Discover The Best Free Linux Server Distributions For 2023

Learn about the selection of excellent - and free! - server distros available to Linux users in 2021. . Linux is an open-source software platform developed initially for home computers but later become a dominated Server operating system. Linux Server OS are popular because of their small size and ability to quickly convert to perform some specific operations such as Web server, File server, monitoring tool, etc. That’s why you will see almost all computing cloud platforms prefer Linux servers to distribute their computing services. Apart from powring thousands of racks at hosting companies, in server farms, and at cloud providers, you can also see Linux command line servers nested in container instances or in virtual machines, in short Linux keeps the Internet alive. As a server, Linux today supports more architectures and processors than any other kernel – from very large to very small. . In 2023, top free Linux server distributions shine with stellar performance and versatility for hosting tasks, including Ubuntu Server, CentOS Stream, Debian, Arch Linux, and Fedora Server.. Linux Server Distributions, Free OS, Open Source Hosting, Server Operating Systems. . LinuxSecurity.com Team

Calendar%202 Mar 15, 2023 User Avatar LinuxSecurity.com Team Server Security
209

Cyberattacks Striking Linux Systems Every Minute: BlackBerry Report

Threat actors are evolving to target a wide variety of systems and infrastructure, BlackBerry says in a new report. "In addition, attacks against Linux systems and cloud infrastructure will increase as threat actors look to install backdoors on target systems and gain visibility into organizations for further activities." . A new report from BlackBerry reveals that threat actors are launching an attack about once every minute, with the resurgence of the Emotet botnet, phishing attacks and infostealers dominating the attack landscape. The Ontario-based intelligent security software and services provider’s first Global Intelligence Report on the fourth quarter of 2022 find that the company’s AI-driven prevention-first technology stopped more than 1.75 million malware-based attacks. According to BlackBerry, the most common tools used in attacks include the Emotet botnet, the Qakbot phishing threat and an increase in infostealers such as GuLoader. . A recent study by McAfee indicates that cybercriminals are executing a breach roughly every 60 seconds, focusing on digital infrastructures.. Linux Threat Actors,Cybersecurity Report,Cloud Attack Trends. . Brittany Day

Calendar%202 Jan 26, 2023 User Avatar Brittany Day Security Trends
78

Rocky Linux Project Schedule for Releases in the Second Quarter of 2021

It has now been almost two weeks since the announcement of Red Hat dropping support for CentOS Linux 8 and shifting full focus to its future CentOS Stream - a decison which has led to the creation of Rocky Linux by CentOS creator Greg Kurtzer. . Now, in the very first community update, Rocky Linux Community Manager Jordan Pisaniello has shared all the progress done so far and updates for future releases of Rocky Linux. The team has targeted 2021 Q2 that includes April, May, and June to deliver the first release of Rocky Linux. And the release won’t just be available in standard commercial regions, but it will also be available in AWS GovCloud, and China. The core team is already laying down the infrastructure to deliver and support an initial release. It has also selected AWS (Amazon Web Services) as the primary build platform for the development of Rocky Linux. . The Community Director of Rocky Linux provides insights regarding the launch of Q2 2021, emphasizing advancements and strategies for infrastructure development.. Rocky Linux, Linux Distribution, Community Update, Cloud Infra. . LinuxSecurity.com Team

Calendar%202 Dec 23, 2020 User Avatar LinuxSecurity.com Team Vendors/Products
209

Integrating Linux into Your Comprehensive Security Strategy

Linux is a pervasive operating system—and for good reason. It’s lightweight, flexible, multi-architecture supportive and open source, all leading to loads of opportunity. Security is one of the main reasons Linux is chosen. In some ways, it can be a more stable and secure base OS to start from, no matter the use case. . Today, Linux-based systems run servers, mainframes, routers, smart cars, cloud workloads and more. Linux is scalable, modular, reliable and efficient. It offers a backbone for specific implementations that is simple to tailor and adapt. The cloud and IoT are two technologies that are built almost exclusively on Linux due to these benefits. . Linux is a powerful OS known for its security features, adaptability, and open-source nature, making it a preferred choice for secure computing globally. Linux Security, Open Source Solutions, Cloud Infrastructure, IoT Integration, System Flexibility. . Brittany Day

Calendar%202 Nov 13, 2020 User Avatar Brittany Day Security Trends
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200