Explore top 10 tips to secure your open-source projects now. Read More
×The newly emerged ransomware actively targets both Windows and Linux systems with a double-extortion approach. . Arika ransomware has continued to evolve since emerging as a threat in March, expanding its reach from initially targeting Windows systems to include Linux servers and employing a growing array of tactics, techniques, and procedures (TTPs). An in-depth report on Akira from LogPoint breaks down the "highly sophisticated" ransomware, which encrypts victim files, deletes shadow copies, and demands ransom payment for data recovery. The infection chain actively targets Cisco ASA VPNs lacking multifactor authentication to exploit the CVE-2023-20269 vulnerability as an entry point. As of early September, the group had successfully hit 110 victims, focusing on targets in the US and the UK. . Arika ransomware relentlessly assaults Linux environments, employing innovative strategies in its dual-extortion tactics; explore its techniques and consequences.. Arika Ransomware, Linux Malware, Cyber Threats, Double Extortion. . LinuxSecurity.com Team
Experts have recently discovered an upgraded version of the BPFDoor malware for Linux (opens in new tab) , that’s seemingly harder to spot - and aAs a result, no antivirus programs are still flagging the executable as malicious. . Cybersecurity researchers from Deep Instinct noted that BPFDoor, which was first discovered in 2022, has been active since at least 2017. The tool got its name from the (ab)use of the Berkley Packet Filter (BPF), which it uses to get instructions and bypass any firewalls. Its design allows the threat actors to remain undetected on a compromised Linux system for longer periods of time, it was said. BPFDoor’s key feature is allowing threat actors to see all network traffic and find vulnerabilities, as well as sending out remote code through (now) unfiltered and unblocked channels. . Researchers disclose an enhanced version of the BPFDoor malware targeting Linux, recognized for its ability to avoid antivirus measures and infiltrate devices.. BPFDoor Malware, Linux Cyber Threats, Network Intrusion Detection. . LinuxSecurity.com Team
The threat actor known as Lucky Mouse has developed a Linux version of a malware toolkit called SysUpdate, expanding on its ability to target devices running the operating system. . The oldest version of the updated artifact dates back to July 2022, with the malware incorporating new features designed to evade security software and resist reverse engineering. Cybersecurity company Trend Micro said it observed the equivalent Windows variant in June 2022, nearly one month after the command-and-control (C2) infrastructure was set up. Lucky Mouse is also tracked under the monikers APT27, Bronze Union, Emissary Panda, and Iron Tiger, and is known to utilize a variety of malware such as SysUpdate , HyperBro, PlugX, and a Linux backdoor dubbed rshell. The link for this article located at The Hacker News is no longer available. . The Cunning Fox cybercrime group amplifies its Havoc ransomware functionalities focusing on Windows systems with sophisticated obfuscation methods.. Linux Malware, Cyber Threats, Evasion Techniques, SysUpdate, Malware Analysis. . LinuxSecurity.com Team
Suspected Chinese hackers exploited a recently disclosed FortiOS SSL-VPN vulnerability as a zero-day in December, targeting a European government and an African MSP with a new custom 'BOLDMOVE' Linux and Windows malware. . The vulnerability is tracked as CVE-2022-42475 and was quietly fixed by Fortinet in November. Fortinet publicly disclosed the vulnerability in December, urging customers to patch their devices as threat actors were actively exploiting the flaw. The flaw allows remote unauthenticated attackers to crash targeted devices remotely or gain remote code execution. However, it was not until this month that Fortinet shared more details about how hackers exploited it, explaining that threat actors had targeted government entities with custom malware specifically designed to run on FortiOS devices. . Alleged state-sponsored cybercriminals from China deployed unique malware to take advantage of a zero-day vulnerability in Fortinet systems, focusing on governmental infrastructures.. Fortinet Devices, BOLDMOVE Malware, SSL-VPN Vulnerability, Cyber Attacks. . LinuxSecurity.com Team
Chile's national computer security and incident response team (CSIRT) has announced that a ransomware attack has impacted operations and online services of a government agency in the country. . The attack started on Thursday, August 25, targeting Microsoft and VMware ESXi servers operated by the agency. The hackers stopped all running virtual machines and encrypted their files, appending the ".crypt" filename extension. . A cybercriminal incident affected a governmental organization's virtual systems in Chile, commencing on August 25.. Chilean Government, Server Security, Cybersecurity Incident, Virtual Machine Attack. . Brittany Day
Understand the security benefits and risks associated with Linux containers. . As cloud adoption soars, containers are gaining more popularity, too. Linux Containers (LXC) lead this segment, accounting for 33.5 percent of the containerization market as of 2021. This popularity makes it a tempting option for developers, but it is important to consider its security, too. Containers are sets of one or more processes that are isolated from the rest of the system. This allows the application to run quickly and reliably between computing environments. Containers enable infrastructures to run more productively, efficiently and cost-effectively, which is why they have become so popular. Linux containers have several security advantages, listed below, but reliable cyber security does not come without user action. Developers must understand LXC’s security benefits and risks to make the most of what is available and minimize vulnerabilities. When they know more about how to secure these systems, they can create safer environments. With that in mind, here are five things you need to know about Linux container security. . Comprehend the Advantages and Dangers of Docker Security for Enhanced Defense Against Exploits and Attacks.. Linux Containers, Container Security, Cyber Attack, Security Practices. . Brittany Day
The new year has brought some bad news for Linux users and enthusiasts. Research reveals that Linux-specific malware saw a 35% increase in 2021 compared to a year before. . More specifically, the report here is talking about Linux malware targeting various Internet of Things (IoT) and mobile devices and how some of these malicious softwares are using the IoT to produce massive botnet armies in order to carry out distributed denial-of-service (DDoS) attacks. . In 2021, a notable surge in Linux malware was observed, especially targeting IoT and mobile platforms, creating new security hurdles.. Linux Malware Growth, IoT Security Risks, 2021 Cyber Threats. . Brittany Day
eCommerce servers are being targeted with remote access malware that hides on Nginx servers in a way that makes it virtually invisible to security solutions. “NginRAT essentially hijacks a host Nginx application to stay undetected. To do that, NginRAT modifies core functionality of the Linux host system. When the legitimate Nginx web server uses such functionality (eg dlopen), NginRAT intercepts it to inject itself.” . The threat received the name NginRAT, a combination of the application it targets and the remote access capabilities it provides and is being used in server-side attacks to steal payment card data from online stores. NginRAT was found on eCommerce servers in North America and Europe that had been infected with CronRAT , a remote access trojan (RAT) that hides payloads in tasks scheduled to execute on an invalid day of the calendar. . NginRAT infiltrates online retail platforms by masquerading as a genuine nginx operation, presenting a significant cybersecurity challenge to digital marketplaces.. NginRAT, eCommerce Security, Malware Threats, Remote Access Trojans, Nginx Servers. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.