Explore top 10 tips to secure your open-source projects now. Read More
×StripedFly malware is capable of grabbing screenshots and stealing passwords. . Cybersecurity researchers have discovered an “impressive” malware threat hiding in plain sight for half a decade. Called StripedFly, the malware’s earliest evidence of activity dates back to 2017, Kaspersky claims, where at one point it was discovered but dismissed as a “mere” cryptocurrency miner. However, a new investigation has shown that StripedFly is capable of a lot more than just mining cryptocurrency: it can execute commands remotely, grab screenshots and execute shellcodes, steal passwords and other sensitive data, record sounds using the integrated microphone, move to adjacent endpoints using previously stolen credentials, abuse the EternalBlue exploit to worm into other systems, and lastly - mine Monero. . Experts in cybersecurity have revealed the remarkable functions of StripedFly malware, which can effectively harvest confidential information and perform various operations.. StripedFly Malware, Remote Access Threat, Cybersecurity Analysis, Malicious Software. . LinuxSecurity.com Team
The digital age offers opportunities but also increases the importance of cybersecurity as threats grow in complexity and sophistication, making preparedness a top priority. . Open-source botnets are now a hot topic in cybersecurity due to their accessibility and rapid adaptability against security measures. Cybersecurity researchers at SOCRadar recently reported about an open-source botnet, Supershell, that obtains SSH shell access. Supershell is an open-source botnet that offers rapid one-click Docker-based deployment with integrated reverse SSH for team collaboration and interactive control. The link for this article located at CyberSecurity News is no longer available. . Discover Supershell, a collaborative open-source botnet featuring SSH connectivity and Docker-based deployment designed for seamless team interaction.. open source botnet, SSH access, Docker deployment. . LinuxSecurity.com Team
SecurityWeek reports that pro-Ukraine hacktivist group GhostSec is having its claims of launching the first-ever ransomware attack against an industrial control system device questioned by cybersecurity experts. . GhostSec alleged that it was able to compromise a remote terminal unit in Belarus, a major ally of Russia, and while files were encrypted as a result of the intrusion, no ransom has been demanded. However, SynSaber noted that attacks against the targeted device, a Teleofis RTU968, which runs on the popular Linux OS OpenWrt, have been done before. "Given that these devices are running generic Linux kernels that happen to be providing connectivity to serial devices (which, of course, could be industrial), theres nothing in the evidence supplied by GhostSec that industrial was specifically attacked or that this attack represents a new paradigm shift in industrial hacking," said SynSaber Chief Technology Officer Ron Fabela. . Cyber group GhostSec reports it breached a remote terminal unit in Belarus, but specialists in industrial control systems express skepticism.. Hacktivist Group, ICS Ransomware, OpenWrt Security, Cybersecurity Threats, Remote Terminal Units. . LinuxSecurity.com Team
The number of malware strains targeting WSL is growing. . Windows Subsystem for Linux (WSL) is becoming a breeding ground for malware , cybersecurity researchers are saying. While WSL-based malware is not particularly new (spotted as early as September 2021), it’s been rising in popularity among cybercriminals of late. Speaking to BleepingComputer, cybersecurity researchers from Lumen Technologies said they’ve managed to track more than 100 samples since then. The samples vary in complexity, as well as features on offer. While some are relatively simple, others enable threat actors to remotely access devices, run arbitrary code, steal authentication cookies from specific browsers , or download files. . The Windows Subsystem for Linux (WSL) is increasingly viewed as a potential hotspot for malicious software, prompting alarm bells to ring amongst cybersecurity professionals.. Windows Subsystem for Linux, Malware Threats, Cybersecurity Risks, Remote Access Issues. . LinuxSecurity.com Team
To tackle the growing threat of attacks on the software supply chain, Google has proposed the Supply chain Levels for Software Artifacts framework, or SLSA which is pronounced "salsa". Can Google's 'salsa' make life harder for supply chain attackers? Comment below - we want to hear what you think! . Sophisticated attackers have figured out that the software supply chain is the soft underbelly of the software industry. Beyond the game-changing SolarWinds hack, Google points to the recent Codecov supply chain attack, which stung cybersecurity firm Rapid7 via a tainted Bash uploader. While supply chain attacks aren't new, Google notes they've escalated in the past year, and has shifted the focus from exploits for known or zero-day software vulnerabilities. . Advanced threat actors are targeting the software development pipeline; Google's SLSA initiative strengthens defenses against these vulnerabilities.. Software Supply Chain, Google Security, SLSA Framework, Software Attacks, Open Source Security. . LinuxSecurity.com Team
In the wake of several major cybersecurity incidents - the most recent being the Colonial Pipeline ransomware attack, the government wants to shore up its software supply chain. There’s no silver bullet, but Open Source shows significant promise in meeting this challenge. . Recent intrusions into federal agencies and critical infrastructure are causing the government to more closely examine how software is made, in addition to who’s making it and where. Even before President Joe Biden and his transition team entered the White House amid the unfurling SolarWinds crisis, the executive branch was working to collectively reduce weaknesses in the government’s software supply chain. A new executive order gets deeper into core software development techniques than anything from previous administrations. . Recent incidents involving federal agencies underscore vulnerabilities within government software supply chains, prompting an examination of open-source threats.. Software Supply Chain, Open Source Security, Cybersecurity Threats, Software Integrity. . Brittany Day
After the shut down of most of its critical infrastructure, the infamous TrickBot malware is now targeting Linux systems. . Efforts to disrupt TrickBot may have shut down most of its critical infrastructure, but the operators behind the notorious malware aren't sitting idle. According to new findings shared by cybersecurity firm Netscout , TrickBot's authors have moved portions of their code to Linux in an attempt to widen the scope of victims that could be targeted. TrickBot, a financial Trojan first detected in 2016, has been traditionally a Windows-based crimeware solution, employing different modules to perform a wide range of malicious activities on target networks, including credential theft and perpetrate ransomware attacks. . Reports indicate key components have been adapted and relocated to sustain operational capabilities, with TrickBot's operators likely to innovate further amid continued cyber threats. TrickBot Linux, TrickBot Malware, Cyber Threats, Financial Crimeware. . LinuxSecurity.com Team
Have you heard that hackers havestolen a massive trove of sensitive data and defaced the website of SyTech, a major contractor working for Russian intelligence agency FSB (Federal Security Service)? BBC Russia, which reported the breach, said âitâs possible that this is the largest data leak in the history of the work of Russian special services on the Internet.â The documents included descriptions of dozens of internal projects the company was working on, including ones on de-anonymization of users of the Tor browser and researching the vulnerability of torrents. . The link for this article located at The Next Web is no longer available. . Major security incident disclosed concerning Russian cyber operations targeting Tor anonymity mechanisms and weaknesses in torrent protocols.. Tor De-Anonymization,Russian Intelligence,Data Breach,Cybersecurity Threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.