Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 538
Alerts This Week
Warning Icon 1 538

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
83

AcidPour Malware Implications for Linux Security and Admin Strategies

A new variant of the AcidRain Linux malware called AcidPour has been discovered. This malware targets explicitly Linux systems in Ukraine. AcidPour expands upon its predecessor and poses a significant risk to users. Let's examine the importance of this discovery, the implications for admins and security professionals, and measures you can take to protect against threats like AcidPour. . What Is the Significance of the AcidPour Malware Discovery? AcidPour showcases the evolving landscape of malware threats, particularly in Linux systems. Unlike its predecessor, the AcidPour malware is compiled for Linux x86 devices and is widely used in popular Linux distributions such as Ubuntu, Mint, Fedora, and Debian. This fact alone sparks curiosity as it questions the previous assumptions that Linux systems are inherently more secure . The discovery of AcidPour highlights the need for security practitioners to be vigilant and adaptable in their defense strategies, even when dealing with open-source platforms like Linux. It is crucial to note the distinct differences between AcidPour and AcidRain, especially regarding their codebase and targeted elements. AcidPour introduces new components like Unsorted Block Images (UBI) and virtual block devices associated with Logical Volume Manager (LVM). This expansion in targets indicates a potential evolution in the strategies employed by threat actors. Such evolving tactics raise essential questions regarding the motives and intentions behind these malware campaigns. Security practitioners must stay informed about these shifts to protect their systems and networks effectively. What Are the Security Implications of AcidPour? How Can I Mitigate My Risk? The implications of the AcidPour malware variant can have long-term consequences for Linux admins and sysadmins globally. The fact that it specifically targets Ukraine sets a precedent for potential future attacks targeting specific regions or industries. This highlights the importance of internationalcollaboration among security professionals to share information and develop countermeasures that can be applied globally. Additionally, the specific wiping logic observed in AcidPour, particularly for devices like LVMs, suggests a higher level of sophistication, indicating a need for enhanced security protocols and incident response practices. As security practitioners, it is crucial to remain proactive in countering these evolving threats. We suggest prioritizing cybersecurity training for oneself and employees, emphasizing mitigating phishing attacks , one of the primary entry points for malware infections. Furthermore, leveraging AI-powered solutions such as chatbots to compile concise and comprehensive guides for preventive measures can significantly enhance overall security. Our Final Thoughts on the AcidPour Linux Malware The discovery of AcidPour is a wake-up call for the Linux community. The evolving nature of malware threats demands constant vigilance and adaptability from security practitioners. By staying informed, collaborating globally, and implementing robust security measures, Linux admins, infosec professionals, internet security enthusiasts, and sysadmins can effectively defend against current and future malware variants. The implications of AcidPour and similar threats underscore the importance of understanding the ever-changing landscape of cybersecurity and reinforce the need to enhance security practices continuously. . Uncover the escalating dangers associated with AcidPour malware and find out how to protect your Linux environments with efficiency.. AcidPour Malware, Linux Malware Threats, Cybersecurity Strategies, Admin Defense, Malware Protection. . Brittany Day

Calendar%202 Mar 19, 2024 User Avatar Brittany Day Hacks/Cracks
83

Chaos RAT Targets Linux Cryptomining Systems With Advanced Functions

A type of cryptomining malware targeting Linux-based systems has added capabilities by incorporating an open source remote access trojan called Chaos RAT with several advanced functions that bad guys can use to control remote operating systems. . Trend Micro security researchers discovered the threat last month. Like earlier, similar versions of the miner that also target Linux operating systems, the code kills competing malware and resources that affect cryptocurrency mining performance. The newer malware then establishes persistence "by altering /etc/crontab file, a UNIX task scheduler that, in this case, downloads itself every 10 minutes from Pastebin," wrote Trend Micro researchers David Fiser and Alfredo Oliveira. After that, it downloads an XMRig miner, a configuration file, another payload that continually kills competing malware, and the Chaos RAT (remote access tool), which is written in Go and has a ton of capabilities including restarting and shutting down the victim's machine. . Fortinet discovered a novel phishing toolkit targeting Windows environments, bolstering credential harvesting techniques alongside exploit frameworks.. cryptomining, chaos rat, linux malware, remote access, advanced functions. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2022 User Avatar LinuxSecurity.com Team Hacks/Cracks
209

Malware Delivery Risks in Linux Systems Require Vigilance Against Threats

Linux systems are a popular delivery mechanism for malware. While they’re not the most popular – that distinction goes to HTML and Javascript – don’t think you can ignore them. Linux-based attacks are very much still happening. . When bad actors identify a vulnerability they can exploit, their next move is typically to spread malware to achieve their objectives. When deciding what platforms to employ, hackers have a variety of ways to get malware into systems without attracting attention. This is known as the “hacker’s choice.” And they can also find ways to remain in those systems even longer without being noticed, which is what we’re seeing with advanced persistent crime (APC). Our researchers have observed that over the previous six months, HTML has been the most common method of malware delivery, with a difference of about 10% between it and Javascript. HTML hit a new high in May. . Operating systems like Linux can still pose vulnerabilities for malware infiltration, underscoring the necessity of continuous protective protocols against potential dangers.. Malware Delivery, Linux Systems, Cyber Threat Awareness, Security Practices. . Brittany Day

Calendar%202 Sep 30, 2022 User Avatar Brittany Day Security Trends
215

GNOME's New Feature to Alert on Secure Boot Risks in UEFI Systems

GNOME is planning to protect insecure hardware by notifying users more about their firmware security status. . When you install Linux on your UEFI-enabled computer, you have to disable Secure Boot because the live USB will refuse to boot with the option enabled. Some mainstream Linux distributions support Secure Boot, but it is still challenging to set up for many other distributions (and with Nvidia hardware onboard). While things may not have improved over the years, Secure Boot is an essential protection feature in general. . Explore GNOME's initiatives aimed at alerting users about their firmware security conditions in relation to Secure Boot vulnerabilities.. Secure Boot, GNOME Notifications, UEFI Security, Firmware Status, Linux Hardware Risks. . Brittany Day

Calendar%202 Aug 02, 2022 User Avatar Brittany Day Desktop Security
83

VeriSign's Linux-Based DNS Servers and Their Security Architecture

A few years ago, I had the privilege of seeing some root DNS servers in action at VeriSign's main headquarters. It's something I had wanted to do for over a decade, and I was literally slightly shaking with excitement (yes, I am that big of a geek). Physical security was high. It took three-factor authentication to get me past the two mantraps and the bomb-blast protected walls. My escort had to use handprint geometry, a PIN, a smart card, and a retinal scan to get me into the inner sanctum. . Turns out VeriSign's DNS root servers at this location are composed of two physically separate, 10-high stacked, 1U pizza-box-style IBM eServers (VeriSign said they tested many different servers, and IBM's gave them the best performance per dollar), running Solaris and Red Hat Linux. Not surprisingly, they don't run BIND and keep things intentionally diverse to protect against a platform-specific attack. Watching the network lights rapidly blink under millions of transactions per second was a blast. Did I mention I was a geek? The link for this article located at InfoWorld is no longer available. . Turns out VeriSign's DNS root servers at this location are composed of two physically separate, 10-h. years, privilege, seeing, servers, action, verisign's. . LinuxSecurity.com Team

Calendar%202 Feb 16, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

IBM Assessment of Open Source Security Tools for Linux Systems

To test open source security products, a study was conducted over a period of three months at the IBM Linux Test Integration Center. The goal for the security study was to deploy and compare various open source security tools that were available for free in the industry, and provide solution recommendations.v . The need for security in today's networked world is overwhelming. With e-commerce, e-mail, information distribution and all the benefits of the explosive growth of the Internet, come destructive attacks, identity thefts, access violations, and worms that propagate across networks to infect thousands to millions of computers. The link for this article located at AMEInfo is no longer available. . Delve into an extensive IBM analysis evaluating multiple open source security applications tailored for Linux environments, conducted over a span of ninety days.. Linux Security Tools, Open Source Assessment, Threat Evaluation. . LinuxSecurity.com Team

Calendar%202 Jan 31, 2005 User Avatar LinuxSecurity.com Team Security Projects
79

New Insights: Linux System Exploit Durability Expands To Three Months

New Honeynet Project KYE paper released "Know Your Enemy: Trends". This paper documents how the life expectancy of unpatched or vulnerable deployments of common Linux systems has increased from 3 days to 3 months. This is surprising based on the increase of malicious activity seen in the past 18 months. . The link for this article located at HoneyNet Project is no longer available. . The link for this article located at HoneyNet Project is no longer available.. paper, honeynet, project, released, 'know, enemy, trends', documents. . LinuxSecurity.com Team

Calendar%202 Dec 22, 2004 User Avatar LinuxSecurity.com Team Security Projects
77

Set Up Encrypted NFS on Linux Systems with OpenSSH for Security

NFS is a widely deployed, mature, and understood protocol that allows computers to share files over a network. The main problems with NFS are that it relies on the inherently insecure UDP protocol, transactions are not encrypted, hosts and users cannot . . . . NFS is a widely deployed, mature, and understood protocol that allows computers to share files over a network. The main problems with NFS are that it relies on the inherently insecure UDP protocol, transactions are not encrypted, hosts and users cannot be easily authenticated, and its difficulty in firewalling. This article provides a solution to most of these problems for Linux clients and servers. These principles may also be applied to any UNIX server with ssh installed. This article assumes basic knowledge of NFS and firewalling for Linux. The link for this article located at SysAdmin is no longer available. . Securely implement encrypted NFS using OpenSSH on Linux by utilizing SSH tunneling for data protection during transfers, enhancing file sharing safety. NFS Protocol, OpenSSH, Encrypted File Sharing. . LinuxSecurity.com Team

Calendar%202 Nov 14, 2002 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200