Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
83

B1txor20: New Botnet Exploiting Log4j To Attack Arm And x86 Systems

A new Linux botnet, B1txor20, that targets Arm and 64-bit x86 systems shows log4j isn't going away any time soon. . We’re months into the disclosure of the log4j vulnerability and new attacks are still popping up. Cybersecurity researchers from Qihoo 360, a Chinese cybersecurity company, have just discovered a new Linux botnet, taking advantage of the flaw to distribute rootkits and steal sensitive data. They named the botnet B1txor20, and claim it uses the log4j vulnerability to target Linux Arm and 64-bit x86 systems. "In addition to traditional backdoor functions, B1txor20 also has functions such as opening a Socket5 proxy and remotely downloading and installing a rootkit," the researchers said. . An emerging Linux botnet, B1texploit21, exploits vulnerabilities in log4j to compromise both Arm and x86 architectures, disseminating malware and exfiltrating sensitive information.. Linux Botnet, Log4j Exploits, Cybersecurity Threats, Rootkit Attack, B1txor20 Malware. . LinuxSecurity.com Team

Calendar 2 Mar 18, 2022 User Avatar LinuxSecurity.com Team Hacks/Cracks
209

Call For Federal Aid In Addressing Log4j Open Source Risks

The tech industry is readying solutions to the security risks posed by the collaborative software that underpins modern-day computing — but aid from Washington could be essential to the project’s success. . The cyber community’s scramble to address major vulnerabilities in the widely used code library Log4j is just the latest wake-up call about the security risks of the open-source software ecosystem — and it’s fueling new calls for more government support in plugging those gaps. The discovery of the Log4j flaw early this month spawned immediate alarm throughout the cyber world because of the enormous number of internet-connected systems it exposed to potential attacks. CISA estimated that “hundreds of millions” of devices run software that uses the Java-language logging tool. The link for this article located at Politico is no longer available. . The recent rush within the tech sector to address significant flaws in OpenSSL underscores a pressing demand for enhanced government assistance.. Log4j Vulnerabilities, Open Source Risks, Cybersecurity Support. . Brittany Day

Calendar 2 Jan 10, 2022 User Avatar Brittany Day Security Trends
78

Debian 11.2: Security Advisory on Critical Bug Fixes and Updates

The Debian project has released a second update for the stable distribution Debian 11 , codenamed “Bullseye”. Although the latest update is not a major revision, it includes more than 40 security updates, in addition to 60+ bug fixes. . Nearly two months after releasing Debian 11.1, the team behind the Linux distro has sent out an incremental update that fixes multiple bugs, and also addresses several security issues. One of the most prominent of the patches, include a fix for actively exploited Log4j vulnerability. If you have been applying updates, you'll automatically be on Debian 11.2. You can check to see if you have the latest updates through the graphical update tool. Alternatively, experienced users can fire up the Terminal and update Debian with the command sudo apt update && sudo apt full upgrade. . Debian 11.2 rolls out numerous enhancements, addressing over 40 vulnerabilities and defects since the preceding 11.1 version. Upgrade today for improved performance.. Debian 11.2 security fixes, Bullseye update, Debian patch details. . LinuxSecurity.com Team

Calendar 2 Dec 21, 2021 User Avatar LinuxSecurity.com Team Vendors/Products
210

Blumira Uncovers New Log4j Attack Vector via Javascript WebSocket

A basic Javascript WebSocket connection can trigger a local Log4j remote code attack via a drive-by compromise. Wonderful. Truly wonderful. . It doesn't rain, but it pours. Previously, one assumption about the 10 out of 10 Log4j security vulnerability was that it was limited to exposed vulnerable servers. We were wrong. The security company Blumira claims to have found a new, exciting Log4j attack vector . You didn't really want to take this weekend off, did you? Of course not! Instead, you'll be chasing down vulnerable Log4j code ever deeper into your network. According to Blumira, this newly-discovered Javascript WebSocket attack vector can be exploited through the path of a listening server on their machine or local network. An attacker can simply navigate to a website and trigger the vulnerability. Adding insult to injury, WebSocket connections within the host can be difficult to gain deep visibility into. That means it's even harder to detect this vulnerability and attacks using it. The link for this article located at ZDNet is no longer available. . Uncovering a fresh vulnerability in Log4j via JavaScript WebSocket communications prompts significant security alarms.. Log4j Attack Vector, Javascript Exploit, Remote CodeExecution. . Brittany Day

Calendar 2 Dec 18, 2021 User Avatar Brittany Day Security Vulnerabilities
210

Log4j Critical Risk: CISA's Jen Easterly Issues Urgent Warning

Jen Easterly, the director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned the recently-revealed Log4j vulnerability was “one of the most serious” she’s seen in her entire career, “if not the most serious”. . “We expect the vulnerability to be widely exploited by sophisticated actors and we have limited time to take necessary steps in order to reduce the likelihood of damage,” Easterly explained. Adding to the conversation was Jay Gazlay, of CISA’s vulnerability office, who said that “hundreds of millions of were likely to be affected by the flaw. . The Log4Shell security flaw presents a pressing danger from advanced cyber adversaries, as noted by the director of CISA.. Log4j Vulnerability,CISA Alert,Cybersecurity Threats. . Brittany Day

Calendar 2 Dec 15, 2021 User Avatar Brittany Day Security Vulnerabilities
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here