Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The first-ever Linux variant of the Clop ransomware has been detected in the wild, but with a faulty encryption algorithm that has made it possible to reverse engineer the process. . "The ELF executable contains a flawed encryption algorithm making it possible to decrypt locked files without paying the ransom," SentinelOne researcher Antonis Terefos said in a report shared with The Hacker News. The cybersecurity firm, which has made available a decryptor , said it observed the ELF version on December 26, 2022, while also noting its similarities to the Windows flavor when it comes using the same encryption method. The detected sample is said to be part of a larger attack targeting educational institutions in Colombia, including La Salle University, around the same time. The university was added to the criminal group's leak site in early January 2023, per FalconFeedsio . The link for this article located at The Hacker News is no longer available. . The initial variant of Clop ransomware for Linux has been discovered to utilize a flawed encryption technique, which allows victims to recover their files without paying the ransom.. Linux Ransomware, Clop Malware, Decryption Method. . LinuxSecurity.com Team
The Clop ransomware gang is now also using a malware variant that explicitly targets Linux servers, but a flaw in the encryption scheme has allowed victims to quietly recover their files for free for months. . This new Linux version of Clop was spotted in December 2022 by Antonis Terefos, a researcher at SentinelLabs , after the threat group used it together with the Windows variant in an attack against a university in Colombia. While very similar to the Windows version, as they both use the same encryption method and almost identical process logic, there still are some differences, mainly limited to OS API calls and features still waiting to be implemented in the Linux variant. . The REvil ransomware group takes advantage of a security vulnerability, enabling Windows users to retrieve data for weeks without being noticed.. Clop Ransomware, Linux Malware, File Recovery Techniques, Cybersecurity Threats. . LinuxSecurity.com Team
It has been discovered that the RansomExx ransomware gang does not correctly lock Linux files during encryption, leading to potentially corrupted files. . In a new report by Profero, Senior Incident Responder Brenton Morris says the RansomEXX decryptor was failing on various files encrypted by the threat actor's Linux Vmware ESXI encryptor for one the victims who paid the ransom. After reverse-engineering the RansomExx Linux encryptor, Profero discovered that the problematic decryption was caused by Linux files not being adequately locked while they were encrypted. . The RedSky hacking group has an encryption methodology that risks damaging files because of flawed locking mechanisms while encrypting.. RansomEXX, Linux Encryption, File Damage, Ransomware Threats, Incident Response. . LinuxSecurity.com Team
Researchers have found a vulnerability in the open-source Facebook Fizz project which is relatively easy to trigger for the purposes of a denial-of-service (DoS) attack. . Facebook Fizz is an open-source TLS 1.3 library written in C++ 14. TLS is one of the newer encryption standards for the Internet available and has been designed to be the successor to SSL. TLS implements stronger encryption standards and also has removed support for older, less secure algorithms. The link for this article located at ZDNet is no longer available. . A significant vulnerability in the Facebook Fizz TLS framework enables straightforward denial-of-service (DoS) assaults. Discover further details regarding this concern.. Facebook Fizz, TLS Library, DoS Attack, Encryption Standards, Open Source Security. . LinuxSecurity.com Team
For years, privacy advocates have pushed developers of websites, virtual private network apps, and other cryptographic software to adopt the Diffie-Hellman cryptographic key exchange as a defense against surveillance from the US National Security Agency and other state-sponsored spies. Now, researchers are renewing their warning that a serious flaw in the way the key exchange is implemented is allowing the NSA to break and eavesdrop on trillions of encrypted connections. . The cost for adversaries is by no means modest. For commonly used 1024-bit keys, it would take about a year and cost a "few hundred million dollars" to crack just one of the extremely large prime numbers that form the starting point of a Diffie-Hellman negotiation. But it turns out that only a few primes are commonly used, putting the price well within the NSA's $11 billion-per-year budget dedicated to "groundbreaking cryptanalytic capabilities." . The cost for adversaries is by no means modest. For commonly used 1024-bit keys, it would take about. years, privacy, advocates, pushed, developers, websites, virtual, private, network. . Dave Wreski
Computer security experts said they've found a new encryption flaw closely related to one found earlier this year that puts Web surfers' data at risk. . The flaw, called LogJam, can allow an attacker to significantly weaken the encrypted connection between a user and a Web or email server, said Matthew D. Green, an assistant research professor in the department of computer science at Johns Hopkins University. The link for this article located at CSO Online is no longer available. . HeartBleed is an emerging vulnerability that poses a threat to encrypted communications, jeopardizing users' data safety during online interactions and email exchanges.. LogJam Flaw, Encryption Issue, Cybersecurity Threat. . LinuxSecurity.com Team
There's more bad news surrounding the HTTPS-crippling FREAK vulnerability that came to light two weeks ago. A recently completed scan of the Internet revealed 10 percent of servers that support the underlying transport layer security protocol remain susceptible.. Even worse, many of these laggards contain an additional weakness that drastically drives down exploitation costs, in the most extreme cases to just pennies per server. As Ars reported almost two weeks ago, so-called FREAK attacks. Even worse, many of these laggards contain an additional weakness that drastically drives down explo. there's, surrounding, https-crippling, freak, vulnerability, light. . LinuxSecurity.com Team
For the nth time in the last couple of years, security experts are warning about a new Internet-scale vulnerability, this time in some popular SSL clients. The flaw allows an attacker to force clients to downgrade to weakened ciphers and break their supposedly encrypted communications through a man-in-the-middle attack.. Researchers recently discovered that some SSL clients, including OpenSSL, will accept weak RSA keys The link for this article located at Wired is no longer available. . Uncover the latest research on weaknesses in SSL client implementations that threaten safe data exchanges.. SSL Clients, OpenSSL Threats, Encryption Weaknesses, Cybersecurity Risks. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.