Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 18 articles for you...
212

Kinsing Group Targets Cloud Credentials Using Linux Flaw

This article from The Hacker News presents a nerve-racking revelation about how cyber threat actors are adapting to the evolving digital landscape. . The hackers' skillful exploitation of the Linux privilege escalation flaw, termed "Looney Tunables," is both alarming and fascinating. As the article mentions, " the attacks revolve around exploiting a recently disclosed Linux privilege escalation flaw (CVE-2022-0847) to gain elevated privileges on the compromised systems "—a stark example of the threat actors' ability to rapidly harness nascent security flaws. Yet it's the apparent shift in strategy that grabs the most attention. Known for deploying malicious cryptocurrency miners, the Kinsing group’s focus on extracting cloud service provider credentials carries ominous implications. The article states, " Beyond establishing an initial foothold, the threat actor aims to extract credentials related to cloud service providers including Alibaba Cloud, Tencent Cloud, and Huawei Cloud. " Could this mean an expanding scope of their operations, possibly threatening the integrity of our cloud-native environment in the near future? All of this underscores the need for a proactive and anticipatory approach to cybersecurity. The evolving modus operandi of Kinsing is a reminder that the cyber threat landscape is dynamic, requiring us to upgrade and expand our defenses persistently. The twists in these cyber-attack strategies make the rest of this detailed article a captivating read for those of us on the constant quest to understand and outmaneuver cyber threats. The link for this article located at The Hacker News is no longer available. . The adept manipulation of the Windows vulnerability 'Sketchy Switches' by cybercriminals heightens worries regarding online safety.. Linux Security Flaw, Kinsing Malware, Cloud Security, Cyberattack Strategies. . Brittany Day

Calendar%202 Nov 21, 2023 User Avatar Brittany Day Cloud Security
83

Pro-Hamas BiBi Wiper Cyber Attack Affects Israeli Windows And Linux Systems

Researchers have discovered a new variant of BiBi malware attacks targeting Israeli Windows and Linux systems, resulting in data wipes. Alerts were sent out by Israel’s (Cyber Emergency Response Team) CERT to help potential target organizations prevent attacks by threat actors. . The attacks are found to be a part of the growing pro-Hamas cyber offensive that has been targeting multiple business sectors in Israel. Researchers from Palo Alto have stated that the attacks had been strongly connected to an Iranian group known as the Agonizing Serpents. Researchers at SecurityJoes and ESET have detected BiBi Wiper versions since late October. However, initial attacks only targeted Linux systems, disrupting operations and causing irreversible data corruption. The link for this article located at SpiceWorks is no longer available. . The attacks are found to be a part of the growing pro-Hamas cyber offensive that has been targeting . researchers, variant, malware, attacks, targeting, israeli, windows. . LinuxSecurity.com Team

Calendar%202 Nov 15, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

North Korean Lazarus Group: VMConnect Malware Targets Linux Systems

Cybersecurity researchers at ReversingLabs claim that a recent malicious cyber campaign targeting MacOS, Linux, and Windows systems was carried out by the North Korean threat group Lazarus. . The VMConnect campaign, spotted in early August, consists of two dozen “malicious Python packages” posted on the openly accessible PyPI software repository, and after observing it for a few weeks ReversingLabs detected three more packages that belong to the VMConnect family. According to Innovation New Network, analysis of the malicious packages used and their decrypted payloads reveals links to previous campaigns attributed to Labyrinth Chollima, an offshoot of the North Korean state-sponsored Lazarus Group. ReversingLabs adds that a similar attribution was made by the JPCERT, which linked the attack it uncovered to DangerousPassword, another subsidiary of the Lazarus Group. . The PhantomDrive initiative, associated with the Nightwolf Collective, brings to light harmful Ruby gems aimed at various platform environments.. North Korean Malware, Lazarus Group, Cyber Threats, VMConnect Campaign. . LinuxSecurity.com Team

Calendar%202 Sep 04, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
72

Fortinet: May 2023 Security Advisory Critical: 0-Day Malware Exploit

A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European government entity and a managed service provider (MSP) located in Africa. . Telemetry evidence gathered by Google-owned Mandiant indicates that the exploitation occurred as early as October 2022, at least nearly two months before fixes were released. "This incident continues China's pattern of exploiting internet facing devices, specifically those used for managed security purposes (e.g., firewalls, IPS\IDS appliances etc.)," Mandiant researchers said in a technical report. The attacks entailed the use of a sophisticated backdoor dubbed BOLDMOVE , a Linux variant of which is specifically designed to run on Fortinet's FortiGate firewalls. The link for this article located at The Hacker News is no longer available. . State-sponsored cybercriminals from China took advantage of a flaw in Fortinet security software to install malicious code and create backdoors in compromised networks.. Fortinet Vulnerability, Zero-Day Threat, Network Exploit, Malware Attack, Backdoor Threat. . Brittany Day

Calendar%202 Jan 23, 2023 User Avatar Brittany Day Firewalls
210

Lenovo: Major Vulnerabilities Found In Multiple Laptop Models

Hundreds of Lenovo models are vulnerable to three major flaws. . Cybersecurity experts from ESET have found three security flaws in hundreds of different Lenovo laptop models which could put millions of users at risk. ESET said exploiting these vulnerabilities would allow attackers to deploy and successfully execute UEFI malware either in the form of SPI flash implants like LoJax or ESP implants like ESPecter. In total, three vulnerabilities have been discovered, which are now tracked as CVE-2021-3970, CVE-2021-3971 (also known as SecureBackDoor and SecureBackDoorPreim), and CVE-3972 (SMM memory corruption inside the SW SMI handler function). . Kaspersky discovers multiple severe vulnerabilities in HP computers, endangering countless users by enabling possible UEFI malware intrusions.. Lenovo Laptop Flaws, UEFI Malware Risks, Cybersecurity Vulnerabilities. . Brittany Day

Calendar%202 Apr 21, 2022 User Avatar Brittany Day Security Vulnerabilities
67

Preventing Cryptojacking: Strategies To Safeguard Your Systems

Criminals are using ransomware-like tactics and poisoned websites to get your employees’ computers to mine cryptocurrencies. Here’s what you can do to stop it. . Cryptojacking is the unauthorized use of someone else’s computer to mine cryptocurrency. Hackers do this by either getting the victim to click on a malicious link in an email that loads cryptomining code on the computer, or by infecting a website or online ad with JavaScript code that auto-executes once loaded in the victim’s browser. Either way, the cryptomining code then works in the background as unsuspecting victims use their computers normally. The only sign they might notice is slower performance or lags in execution. . Uncover the mechanisms behind cryptojacking, its impact on system efficiency, and vital strategies for defense and recovery from such intrusions.. Cryptojacking Prevention, Malware Protection, Cybersecurity Techniques. . LinuxSecurity.com Team

Calendar%202 Aug 02, 2019 User Avatar LinuxSecurity.com Team Cryptography
77

Increased Cyber Threats To Unsecured Elasticsearch Servers

Unsecured Elasticsearch clusters are being targeted in a fresh wave of attacks designed to drop both malware and cryptocurrency mining software. . This week, cybersecurity researchers from Cisco Talos warned of a spike in recent strikes against these systems, with six separate cyberattack groups believed to be involved. The link for this article located at ZDNet is no longer available. . Security analysts highlight an alarming increase in focused malware assaults on vulnerable MongoDB instances.. malware attacks, Elasticsearch security, cyber threat landscape, targeted attacks. . LinuxSecurity.com Team

Calendar%202 Feb 28, 2019 User Avatar LinuxSecurity.com Team Server Security
77

AV-Test Reveals Linux Security Solutions At Risk From Attacks

The recent tests on Linux security solutions by AV-Test Lab indicate a worrisome situation . A successful attack normally does not infect the system or the kernel. Rather, it focuses on the applications running on the Linux PC or Web server. They can be more easily hijacked or harnessed as a means to replicate. Major hacker attacks have already been carried out on Web servers via SQL injection or cross-site scripting. But desktop PCs with Linux are also an attractive target. After all, running applications with security gaps are found there as well, e.g. the Firefox browser or tools such as the Adobe Reader. . Assessment findings reveal that Linux protection mechanisms are encountering notable difficulties due to software assaults and various cyber hazards.. Linux Security Tests, AV-Test Solutions, Application Vulnerabilities, Malware Attacks. . LinuxSecurity.com Team

Calendar%202 Mar 14, 2017 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200