Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 84 articles for you...
83

Protect Your Linux Servers from Nood RAT Malware Threats

The Nood RAT malware is a new threat to Linux servers worldwide. Security researchers say Nood RAT is designed to steal sensitive information from targeted servers. This article warns Linux admins and infosec professionals of the risks posed by the malware and how to prevent such cyberattacks. . How Does Nood RAT Malware Threaten Linux Servers? Nood RAT is a variant of the Gh0st RAT malware. Gh0st RAT for Windows is well-known and has been circulating for over a decade; however, this is one of the first Gh0st RAT strains to target Linux systems. Like its Windows counterpart, Nood RAT is a backdoor malware that can perform malicious operations such as downloading harmful files, stealing internal system files, and executing commands. Nood RAT has an encryption function that can evade network packet identification, which can be concerning for Linux admins and infosec professionals tasked with detecting and preventing such attacks. Additionally, the malware can receive commands from its threat actors and execute various harmful operations, putting sensitive data at risk of theft. Nood RAT can also impersonate itself as an authentic program and that threat actors can choose the malware's fake process name during its development phase. This makes detection more challenging, and it's a task that requires vigilance on the part of an organization's security team. The Chinese C. Rufus Security Team is the developer of Gh0st RAT and that its source code is available to the public. As a result, hackers have been using it in their attacks. In the case of Nood RAT, threat actors exploit the codes to create malware variations, putting Linux servers worldwide at risk of data theft. How Can I Protect Against Nood RAT? There are various measures that security practitioners can take to protect against Nood RAT. Investing in an Endpoint Detection and Response (EDR) solution that provides threat hunting and incident response capabilities can help detect and prevent malware attacks like Nood RAT. Linuxusers must keep their systems updated with the latest security patches and examine their environment configuration to avoid such security concerns. It is essential to remain vigilant in the fight against cyber threats. Our Final Thoughts on Nood RAT: What Can We Learn? Nood RAT is a new threat to Linux servers, and its implications are severe. This article warns Linux admins, infosec professionals, and security practitioners that such attacks are becoming more frequent. However, by being vigilant, staying informed , and investing in the right security solutions, we can stay ahead of cybercriminals and protect critical data from being stolen or compromised. . Nood RAT aims at Linux systems, introducing significant dangers. Remain updated to safeguard confidential information against digital attacks.. Nood RAT, Linux Malware, Cybersecurity Threats, Data Protection, Endpoint Security. . Brittany Day

Calendar%202 Mar 04, 2024 User Avatar Brittany Day Hacks/Cracks
210

HAProxy: Critical Risk Advisory - Remote Data Leak Threat

It was discovered that the HAProxy load balancing reverse proxy incorrectly handled URI components containing the hash character ( CVE-2023-45539 ). This vulnerability is very straightforward for a remote attacker to exploit and severely threatens impacted users’ sensitive information, making it among the worst bugs we’ve seen in a while! . How Do These Vulnerabilities Affect Linux Systems & What Can You Do to Stay Safe? With over 44% of the proxy server market share, this flaw has a widespread impact on Linux users’ security. A remote attacker could easily exploit this bug to steal impacted users’ sensitive data. An important HAProxy update has been released to mitigate this severe bug. Given this vulnerability's damaging repercussions on impacted systems, if left unpatched, we urge all affected users to apply the updates issued by Debian , Debian LTS , SUSE , and Ubuntu immediately to protect against data leakage. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on X for real-time updates on advisories for your distro(s) . . Remain informed about the HAProxy vulnerability and protect confidential information by implementing essential updates for improved security.. HAProxy Exploit, Linux Security Updates, Remote Data Theft. . Brittany Day

Calendar%202 Dec 31, 2023 User Avatar Brittany Day Security Vulnerabilities
77

Linux SSH Servers Targeted: Protect Against Cryptojacking Attacks

It's no secret that cryptocurrencies are a valuable target for hackers. Bitcoin, Ethereum, and Litecoin are all coins worth stealing, and hackers have been working hard to get their hands on them. . One of the most common ways to steal cryptocurrency is through what's known as cryptojacking: installing malicious code on websites and then using the site's visitors' computers to mine for cryptocurrency without their knowledge. Now, we're seeing another way hackers get into cryptocurrencies: through poorly secured Linux SSH servers. This makes it easier than ever for hackers to access your system and steal your valuable data. According to The Hacker News, "Poorly secured Linux SSH servers are being targeted by bad actors to install port scanners and dictionary attack tools with the goal of targeting other vulnerable servers and co-opting them into a network to carry out cryptocurrency mining and distributed denial-of-service (DDoS) attacks ." This is why it's important for Linux admins and infosec professionals to secure their systems properly. Stay up-to-date on the latest Linux security information and insights required to secure your systems by subscribing to our weekly newsletters. Have additional questions about securing your SSH servers? Connect with us on X @lnxsec - we're here to help! Stay safe out there, fellow Linux users! . Strengthen your SSH servers to protect against unauthorized entry and cryptojacking risks targeting cryptocurrencies.. Linux SSH Security, Cryptojacking Threats, Protect Cryptocurrency, Data Theft Prevention, Server Security. . LinuxSecurity.com Team

Calendar%202 Dec 27, 2023 User Avatar LinuxSecurity.com Team Server Security
77

Krasue RAT Threat: Remote Access and Data Theft Risks for Linux Servers

The Krasue Rat malware is a new threat to Linux servers that has been discovered by security researchers. The malware installs itself on the server, and then hides in the form of a rootkit, allowing it to hide from security software. . The malware uses a variety of techniques to avoid detection, including hiding its file system activity and moving around its files so they are not easily found by scanning programs. It also uses fake certificates and authentication processes to make sure that it doesn't get detected by anti-virus programs. The Krasue Rat malware can be used as both a remote access tool for hackers and as an information stealer for criminals. It also has potential use in targeted attacks against specific organizations or companies, as it could be used to steal sensitive data without being detected. I found the article linked below very helpful in understanding this threat, and I wanted to share it with you. Be sure to give it a read! . Explore the methods by which Krasue RAT malware breaches Linux environments, employing advanced rootkit techniques to remain undetected.. Krasue RAT, Linux Malware, Server Security Threats. . LinuxSecurity.com Team

Calendar%202 Dec 07, 2023 User Avatar LinuxSecurity.com Team Server Security
210

LockBit Ransomware Exploits Severe Citrix Bleed Flaw to Encrypt Data

LockBit ransomware is exploiting a critical Citrix bleed vulnerability to break into enterprise networks. The malware spreads via infected USB sticks and allows hackers to steal data and install more malware. . LockBit is being distributed as a self-extracting archive (SFX) file that contains an executable named "Citrix_1.exe," which runs the malicious code on a machine without requiring any user interaction. The file can be distributed over email or any other means of file transfer. After infection, LockBit starts encrypting files on a victim's computer by using AES encryption with a hardcoded key. The malware then displays a ransom note in a text document: "Your files are encrypted! Your personal ID: 1234567890." The malware also installs itself as a service for persistence, which allows it to start automatically when the system boots up. To prevent users from accessing other applications on their systems, LockBit also installs an application lock that prevents users from closing or minimizing windows open in the background while they're trying to work with their files. The link for this article located at The Hacker News is no longer available. . Maze ransomware leverages severe Microsoft Exchange flaw to penetrate systems and lock up data.. LockBit Ransomware, Citrix Bleed Exploit, Cybersecurity Threats. . Brittany Day

Calendar%202 Nov 25, 2023 User Avatar Brittany Day Security Vulnerabilities
83

Kinsing Attack on ActiveMQ: Rootkit Deployment and Data Theft

A team of Chinese hackers known as Kinsing has discovered a little-known security vulnerability in the Apache ActiveMQ message broker software. The vulnerability allowed the attackers to implant rootkits on Linux servers remotely and steal sensitive information such as usernames, passwords, and SSH keys. . The Kinsing threat group has a history of targeting misconfigured containerized environments for cryptocurrency mining, often utilizing compromised server resources to generate illicit profits for the attackers. According to security researchers, "Once Kinsing infects a system, it deploys a cryptocurrency mining script that exploits the host's resources to mine cryptocurrencies like Bitcoin, resulting in significant damage to the infrastructure and a negative impact on system performance. Kinsing doubles down on its persistence and compromise by loading its rootkit in /etc/ld.so.preload, which completes a full system compromise." The link for this article located at The Hacker News is no longer available. . Kinsing cybercriminals take advantage of Nginx vulnerabilities to install Windows trojans and access private information.. Kinsing Attack, ActiveMQ Security, Linux Exploit, Rootkit Threat. . LinuxSecurity.com Team

Calendar%202 Nov 25, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

StripedFly Malware Infects Over A Million Systems: Remote Access Threat

StripedFly malware is capable of grabbing screenshots and stealing passwords. . Cybersecurity researchers have discovered an “impressive” malware threat hiding in plain sight for half a decade. Called StripedFly, the malware’s earliest evidence of activity dates back to 2017, Kaspersky claims, where at one point it was discovered but dismissed as a “mere” cryptocurrency miner. However, a new investigation has shown that StripedFly is capable of a lot more than just mining cryptocurrency: it can execute commands remotely, grab screenshots and execute shellcodes, steal passwords and other sensitive data, record sounds using the integrated microphone, move to adjacent endpoints using previously stolen credentials, abuse the EternalBlue exploit to worm into other systems, and lastly - mine Monero. . Experts in cybersecurity have revealed the remarkable functions of StripedFly malware, which can effectively harvest confidential information and perform various operations.. StripedFly Malware, Remote Access Threat, Cybersecurity Analysis, Malicious Software. . LinuxSecurity.com Team

Calendar%202 Oct 29, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Canonical Snap Store Incident: Investigating Malicious Apps Threat

Several fake cryptography applications have appeared on Canonical's Snap Store . These web application security vulnerabilities seek to steal user funds and inflict other damaging data and network security issues. Canonical is investigating the matter, and access is restricted while investigating the risky cryptography today.. Snap users have reported these recently published Snaps since they are potentially malicious in stealing user funds. The Snap Store has removed the reported risks and incorporated a manual review requirement for new registrations so threat actors cannot impersonate legitimate applications with similar names to manipulate Snap users. Here is the report Canonical’s Snap Store has utilized to notify users: "If you try registering a new snap while the requirement is active, you will be prompted to ‘request reserved name.’ The name will be registered upon a successful manual review from the Snap Store staff. Uploading and releasing revisions for existing snaps will not be affected. We apologize for any inconvenience this may cause our Snap publishers and developers. It is the most prudent action at this moment. We want to thoroughly investigate this incident without introducing any noise into the system. More importantly, we want to ensure that our users have a safe and trusted experience with the Snap Store. Please bear with us while we conduct our investigation. We will provide a more detailed update in the coming days." . Users report malicious apps in Canonical's Snap Store, leading to enhanced security measures being implemented during the ongoing investigation. Malicious Applications,Snap Store Safety,Canonical Security,Data Theft Risks,Web Application Threats. . LinuxSecurity.com Team

Calendar%202 Oct 01, 2023 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200