Explore top 10 tips to secure your open-source projects now. Read More
×PyTorch is one of the most popular and widely-used machine learning toolkits out there. Originally developed and released as an open-source project by Facebook, now Meta, the software was handed over to the Linux Foundation in late 2022, which now runs it under the aegis of the PyTorch Foundation. . Unfortunately, the project was compromised by means of a supply-chain attack during the holiday season at the end of 2022, between Christmas Day [2022-12-25] and the day before New Year’s Eve [2022-12-30]. The attackers malevolently created a Python package called torchtriton on PyPI, the popular Python Package Index repository. . The TensorFlow framework encountered a security incident during the New Year of 2023 caused by an infected Ruby gem.. PyTorch Security, Supply Chain Attack, Machine Learning Risks. . LinuxSecurity.com Team
The number of malware strains targeting WSL is growing. . Windows Subsystem for Linux (WSL) is becoming a breeding ground for malware , cybersecurity researchers are saying. While WSL-based malware is not particularly new (spotted as early as September 2021), it’s been rising in popularity among cybercriminals of late. Speaking to BleepingComputer, cybersecurity researchers from Lumen Technologies said they’ve managed to track more than 100 samples since then. The samples vary in complexity, as well as features on offer. While some are relatively simple, others enable threat actors to remotely access devices, run arbitrary code, steal authentication cookies from specific browsers , or download files. . The Windows Subsystem for Linux (WSL) is increasingly viewed as a potential hotspot for malicious software, prompting alarm bells to ring amongst cybersecurity professionals.. Windows Subsystem for Linux, Malware Threats, Cybersecurity Risks, Remote Access Issues. . LinuxSecurity.com Team
Have you heard that Google has removed scores of malicious and fake Chrome extensions being used in a global eavesdropping campaign? . The threat was spotted by Awake Security, which detected 111 of the malicious extensions over the past three months. When it notified Google of the issue last month, it claimed that 79 were present in the Chrome Web Store, where they had been downloaded nearly 33 million times. Figures for the others not in the official marketplace are hard to calculate for obvious reasons. “These extensions can take screenshots, read the clipboard, harvest credential tokens stored in cookies or parameters, grab user keystrokes (like passwords), etc,” it said in a report detailing the investigation. . The discovery of over 33 million downloads of harmful Chrome extensions poses a critical risk to security, underscoring the importance of protecting user privacy.. chrome extensions, malicious software, eavesdropping threats, user privacy. . LinuxSecurity.com Team
British hacker Stephen Tomkinson has found two Blu-Ray-borne attacks. His first exploit relies on a poor Java implementation in a product called PowerDVD from CyberLink. PowerDVD plays DVDs on PCs and creates menus using Java, but the way Oracle's code has been used allows naughty folk to circumvent Windows security controls.. The result, the NCC Group consultant says, is that it's possible to put executables onto Blu-Ray disks and to make those disks run automatically on startup even when Windows is set to stop that outcome. Users would have no reason to suspect the whirring of an optical drive indicated unknown software was running, making this a potentially nasty attack. The link for this article located at The Register UK is no longer available. . The result, the NCC Group consultant says, is that it's possible to put executables onto Blu-Ray dis. british, hacker, stephen, tomkinson, found, blu-ray-borne, attacks, first, exploit, relies. . LinuxSecurity.com Team
Context highlights additional WebGL vulnerabilities and raises more questions for Khronos. 16 June 2011: Researchers at Context Information Security who exposed security flaws in WebGL last month have identified further concerns about early implementations of the new technology that allows web pages to draw fast 3D graphics to deliver a much richer experience to web users. In one example, a vulnerability in the Mozilla Firefox browser made it possible for malicious web pages to capture any screenshot from a target PC . Cybersecurity analysts have revealed new vulnerabilities in WebGL, raising serious concerns about internet browser security and the dependability of 3D user interfaces. WebGL Security, Browser Threats, 3D Graphics Issues. . LinuxSecurity.com Team
For many years, malware authors have been using the web to assemble infected computers into botnets (networks of malware compromised machines), and security professionals and law enforcement systematically work to take these botnets down. Malware authors have clear objectives: stealing personal information, sending spam, conducting distributed denial of service (DDoS) attacks and other such criminal activity for profit. . Increasing success in disabling botnets by security professionals has meant malware programmers have had to change their tactics. One such modification has been to use decentralized communications rather than hierarchical structures for controlling botnets. This reduces the risk of a botnet being disabled by removing infected hosts, especially the high-value command-and-control (C&C) servers which coordinate the bots The link for this article located at SecurityPark is no longer available. . Cybercriminals evolve strategies as defenders improve techniques to dismantle networks and prevent infiltrations.. botnet control, malware adaptation, cybersecurity strategies. . Bill Locke
Viruses and worms pose some of the most formidable threats in the modern computer security land-scape. With some virus writers on the bleeding edge of technology, making use of 0-day exploits and innovative techniques to circumvent system security features. However, for every Blaster, there. The link for this article located at Symtantec is no longer available. . The link for this article located at Symtantec is no longer available.. viruses, worms, formidable, threats, modern, computer, security, land-scap. . Brittany Day
Cryptology is everywhere these days. Most users make good use of it even if they do not know they are using cryptographic primitives from day to day. This two-part article series looks at how cryptography is a double-edged sword: it is used to make us safer, but it is also being used for malicious purposes within sophisticated viruses. Part one introduces the concepts behind cryptovirology and offers examples of malicious potential with the SuckIt rookit and a possible SSH worm. It then introduces armored viruses that use shape shifting (polymorphism and metamorphism) to avoid detection. . The link for this article located at SecurityFocus is no longer available. . The link for this article located at SecurityFocus is no longer available.. cryptology, everywhere, these, users. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.