A nascent Linux-based botnet named Enemybot has expanded its capabilities to include recently disclosed security vulnerabilities in its arsenal to target web servers, Android devices, and content management systems (CMS). . "The malware is rapidly adopting one-day vulnerabilities as part of its exploitation capabilities," AT&T Alien Labs said in a technical write-up published last week. "Services such as VMware Workspace ONE, Adobe ColdFusion, WordPress, PHP Scriptcase and more are being targeted as well as IoT and Android devices." First disclosed by Securonix in March and later by Fortinet, Enemybot has been linked to a threat actor tracked as Keksec (aka Kek Security, Necro, and FreakOut), with early attacks targeting routers from Seowon Intech, D-Link, and iRZ. The link for this article located at The Hacker News is no longer available. . Malware network targeting web platforms, iOS gadgets, and content management systems through newly uncovered security gaps.. Enemybot Botnet, Android Exploitation, Web Server Threats, CMS Vulnerabilities. . LinuxSecurity.com Team
Developers of popular open-source CMS Drupal are warning admins to immediately patch a flaw that an attacker can exploit just by visiting a vulnerable site.. The bug affects all sites running on Drupal 8, Drupal 7, and Drupal 6. Drupal's project usage page indicates that about a million sites are running the affected versions. . The bug affects all sites running on Drupal 8, Drupal 7, and Drupal 6. Drupal's project usage page i. developers, popular, open-source, drupal, warning, admins, immediately, patch. . LinuxSecurity.com Team
Another major new capability in Joomla 1.6 is the Access Control Level system for managing rights and permissions within the system. This isn't exactly a revolutionary improvement, as many CMS products, especially on the commercial side, have long had very capable access control systems built-in.. But the previous permission system in Joomla was basically unsuitable for most business use and the new system should make Joomla a legitimate option for companies looking for Web content management. With the new system, I could create and manage permission levels for user groups, set default permissions levels, and define specific permission settings for individual areas of content within the site. The link for this article located at Information Week is no longer available. . Joomla 1.6 offers improved access permissions, optimizing web management for businesses and revolutionizing the CMS experience for organizations.. Joomla 1.6, Access Control System, Business Usability, CMS Features. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.