Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This article from The Hacker News presents a nerve-racking revelation about how cyber threat actors are adapting to the evolving digital landscape. . The hackers' skillful exploitation of the Linux privilege escalation flaw, termed "Looney Tunables," is both alarming and fascinating. As the article mentions, " the attacks revolve around exploiting a recently disclosed Linux privilege escalation flaw (CVE-2022-0847) to gain elevated privileges on the compromised systems "—a stark example of the threat actors' ability to rapidly harness nascent security flaws. Yet it's the apparent shift in strategy that grabs the most attention. Known for deploying malicious cryptocurrency miners, the Kinsing group’s focus on extracting cloud service provider credentials carries ominous implications. The article states, " Beyond establishing an initial foothold, the threat actor aims to extract credentials related to cloud service providers including Alibaba Cloud, Tencent Cloud, and Huawei Cloud. " Could this mean an expanding scope of their operations, possibly threatening the integrity of our cloud-native environment in the near future? All of this underscores the need for a proactive and anticipatory approach to cybersecurity. The evolving modus operandi of Kinsing is a reminder that the cyber threat landscape is dynamic, requiring us to upgrade and expand our defenses persistently. The twists in these cyber-attack strategies make the rest of this detailed article a captivating read for those of us on the constant quest to understand and outmaneuver cyber threats. The link for this article located at The Hacker News is no longer available. . The adept manipulation of the Windows vulnerability 'Sketchy Switches' by cybercriminals heightens worries regarding online safety.. Linux Security Flaw, Kinsing Malware, Cloud Security, Cyberattack Strategies. . Brittany Day
Researchers have discovered a new variant of BiBi malware attacks targeting Israeli Windows and Linux systems, resulting in data wipes. Alerts were sent out by Israel’s (Cyber Emergency Response Team) CERT to help potential target organizations prevent attacks by threat actors. . The attacks are found to be a part of the growing pro-Hamas cyber offensive that has been targeting multiple business sectors in Israel. Researchers from Palo Alto have stated that the attacks had been strongly connected to an Iranian group known as the Agonizing Serpents. Researchers at SecurityJoes and ESET have detected BiBi Wiper versions since late October. However, initial attacks only targeted Linux systems, disrupting operations and causing irreversible data corruption. The link for this article located at SpiceWorks is no longer available. . The attacks are found to be a part of the growing pro-Hamas cyber offensive that has been targeting . researchers, variant, malware, attacks, targeting, israeli, windows. . LinuxSecurity.com Team
Cybersecurity researchers at ReversingLabs claim that a recent malicious cyber campaign targeting MacOS, Linux, and Windows systems was carried out by the North Korean threat group Lazarus. . The VMConnect campaign, spotted in early August, consists of two dozen “malicious Python packages” posted on the openly accessible PyPI software repository, and after observing it for a few weeks ReversingLabs detected three more packages that belong to the VMConnect family. According to Innovation New Network, analysis of the malicious packages used and their decrypted payloads reveals links to previous campaigns attributed to Labyrinth Chollima, an offshoot of the North Korean state-sponsored Lazarus Group. ReversingLabs adds that a similar attribution was made by the JPCERT, which linked the attack it uncovered to DangerousPassword, another subsidiary of the Lazarus Group. . The PhantomDrive initiative, associated with the Nightwolf Collective, brings to light harmful Ruby gems aimed at various platform environments.. North Korean Malware, Lazarus Group, Cyber Threats, VMConnect Campaign. . LinuxSecurity.com Team
A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European government entity and a managed service provider (MSP) located in Africa. . Telemetry evidence gathered by Google-owned Mandiant indicates that the exploitation occurred as early as October 2022, at least nearly two months before fixes were released. "This incident continues China's pattern of exploiting internet facing devices, specifically those used for managed security purposes (e.g., firewalls, IPS\IDS appliances etc.)," Mandiant researchers said in a technical report. The attacks entailed the use of a sophisticated backdoor dubbed BOLDMOVE , a Linux variant of which is specifically designed to run on Fortinet's FortiGate firewalls. The link for this article located at The Hacker News is no longer available. . State-sponsored cybercriminals from China took advantage of a flaw in Fortinet security software to install malicious code and create backdoors in compromised networks.. Fortinet Vulnerability, Zero-Day Threat, Network Exploit, Malware Attack, Backdoor Threat. . Brittany Day
Hundreds of Lenovo models are vulnerable to three major flaws. . Cybersecurity experts from ESET have found three security flaws in hundreds of different Lenovo laptop models which could put millions of users at risk. ESET said exploiting these vulnerabilities would allow attackers to deploy and successfully execute UEFI malware either in the form of SPI flash implants like LoJax or ESP implants like ESPecter. In total, three vulnerabilities have been discovered, which are now tracked as CVE-2021-3970, CVE-2021-3971 (also known as SecureBackDoor and SecureBackDoorPreim), and CVE-3972 (SMM memory corruption inside the SW SMI handler function). . Kaspersky discovers multiple severe vulnerabilities in HP computers, endangering countless users by enabling possible UEFI malware intrusions.. Lenovo Laptop Flaws, UEFI Malware Risks, Cybersecurity Vulnerabilities. . Brittany Day
Criminals are using ransomware-like tactics and poisoned websites to get your employees’ computers to mine cryptocurrencies. Here’s what you can do to stop it. . Cryptojacking is the unauthorized use of someone else’s computer to mine cryptocurrency. Hackers do this by either getting the victim to click on a malicious link in an email that loads cryptomining code on the computer, or by infecting a website or online ad with JavaScript code that auto-executes once loaded in the victim’s browser. Either way, the cryptomining code then works in the background as unsuspecting victims use their computers normally. The only sign they might notice is slower performance or lags in execution. . Uncover the mechanisms behind cryptojacking, its impact on system efficiency, and vital strategies for defense and recovery from such intrusions.. Cryptojacking Prevention, Malware Protection, Cybersecurity Techniques. . LinuxSecurity.com Team
Unsecured Elasticsearch clusters are being targeted in a fresh wave of attacks designed to drop both malware and cryptocurrency mining software. . This week, cybersecurity researchers from Cisco Talos warned of a spike in recent strikes against these systems, with six separate cyberattack groups believed to be involved. The link for this article located at ZDNet is no longer available. . Security analysts highlight an alarming increase in focused malware assaults on vulnerable MongoDB instances.. malware attacks, Elasticsearch security, cyber threat landscape, targeted attacks. . LinuxSecurity.com Team
The recent tests on Linux security solutions by AV-Test Lab indicate a worrisome situation . A successful attack normally does not infect the system or the kernel. Rather, it focuses on the applications running on the Linux PC or Web server. They can be more easily hijacked or harnessed as a means to replicate. Major hacker attacks have already been carried out on Web servers via SQL injection or cross-site scripting. But desktop PCs with Linux are also an attractive target. After all, running applications with security gaps are found there as well, e.g. the Firefox browser or tools such as the Adobe Reader. . Assessment findings reveal that Linux protection mechanisms are encountering notable difficulties due to software assaults and various cyber hazards.. Linux Security Tests, AV-Test Solutions, Application Vulnerabilities, Malware Attacks. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.