Explore top 10 tips to secure your open-source projects now. Read More
×The TeamTNT threat group has updated Black-T - its crypto-mining worm - with Linux password-stealing capabilities and with an additional network scanner to help facilitate its spread to other vulnerable devices. . While known mostly for actively targeting Docker instances to use compromised systems for unauthorized Monero (XMR) mining, the group now shifted their tactics by upgrading their cryptojacking malware to also collect user credentials. As Unit 42 researchers found TeamTNT is hard at work boosting their malware's capabilities, this time adding memory password scraping capabilities via mimipy (with support for Windows/Linux/macOS) and mimipenguin (Linux support), two open-source Mimikatz equivalents targeting *NIX desktops. . TeamTNT's recent malware advancements include enhanced Linux password harvesting and network reconnaissance, targeting cloud and application servers more effectively. Crypto Mining, Linux Malware, TeamTNT, Password Theft, Cryptojacking. . LinuxSecurity.com Team
A well-known form of malware which has been stealing login credentials and finances from enterprises for over a decade has once again been updated with new tricks to make it more effective at avoiding detection. . Qakbot - also known as Qbot - has been afflicting businesses since 2008, using worm-like capabilities to spread. The information-stealing trojan malware targets Microsoft Windows systems in an effort to create backdoors and make off with the usernames and passwords which can provide access to financial data. The link for this article located at ZDNet is no longer available. . Qakbot - also known as Qbot - has been afflicting businesses since 2008, using worm-like capabilitie. well-known, malware, which, stealing, login, credentials, finances, enterprises. . LinuxSecurity.com Team
Women’s fashion retailer SHEIN has suffered a major security breach that has exposed the personal information and passwords of over six million customers. . In a press statement, SHEIN reveals that it discovered on August 22 2018 that malicious hackers had compromised its computer network, and that between June and early August 2018 customer email addresses and “encrypted password credentials” had been stolen. The link for this article located at Hot for Security is no longer available. . In a press statement, SHEIN reveals that it discovered on August 22 2018 that malicious hackers had . women’s, fashion, retailer, shein, suffered, major, security, breach, exposed, personal. . LinuxSecurity.com Team
Malware writers are interested in Linux after all. Russian security firm Dr Web has reported finding a shadowy Trojan that sets out to steal passwords on the open source platform as well as OS X. . Technical details of Wirenet.1's operation and technique for spreading are sparse for now, but the company reports that the backdoor program targets browser passwords for Opera, Firefox, Chrome, Chromium, and as well as applications such as Thunderbird, SeaMonkey, Pidgin. The link for this article located at IT World is no longer available. . A recent malware threat known as CloudSnare has emerged, discreetly harvesting login credentials from web browsers, constituting a serious risk to user privacy.. Linux Trojan, Malware Attack, Password Theft, Security Threat, Wirenet. . LinuxSecurity.com Team
Malicious hackers exploit vulnerabilities in phpmyadmin to gain access to WineHQ. Add WineHQ to the list of open-source projects struggling to contain a serious security breach. WineHQ, which manages software that The link for this article located at ZDNet Blogs is no longer available. . TechHaven is currently grappling with a major security incident as cybercriminals leverage weaknesses in WordPress, compromising user credentials.. WineHQ Security, PhpMyAdmin Exploitation, Password Theft, Open Source Breach. . LinuxSecurity.com Team
A UK university student has avoided jail over a malware-based scam that allowed him to break into the personal computers and webmail accounts of an estimated 100 victims.. Paul McLouglin, 22, a Salford University student from Liverpool, tricked victims into downloading password-stealing software, called Istealer, which he had disguised as a code-generation key for online games. McLouglin pleaded guilty on 11 April, prior to a sentencing hearing at London's Southwark Crown Court on Monday where he received an eight months sentence The link for this article located at The Register UK is no longer available. . Paul McLouglin, 22, a Salford University student from Liverpool, tricked victims into downloading pa. university, student, avoided, malware-based, allowed, break. . Anthony Pell
A former high school senior from Orange County, California, has pleaded guilty to charges that he installed spyware on school computers in order to boost his grades.. Omar Kahan, of Coto de Caza, California, was one of two Tesoro High School students arrested three years ago in connection with the incident. The other student, Tanvir Singh, pleaded guilty in September 2008. Khan's guilty plea came as his trial was finally set to start this week. Prosecutors say that in his senior year of high school, Khan developed a habit of breaking into school offices to steal tests and mess with the school's computers. He "installed spyware devices on the computers of several teachers and school administrators throughout his senior year," the office of the Orange County District Attorney said in a news release. The link for this article located at Network World is no longer available. . Leo Carter faced charges for embedding malware on university networks to capture credentials and alter academic records.. Spyware Abuse, Educational Fraud, Password Theft, Academic Integrity, High School Crime. . LinuxSecurity.com Team
Gawker Media has admitted passwords were stolen in a hack on its user databases. Whilst the stored passwords were encrypted, Gawker said, simple ones may still be vulnerable to a brute force attack, where constant attempts to crack the key are made until the hackers are successful.. Users have been advised to change their passwords for Gawker websites and for any other site on which they use that same password. The link for this article located at IT Pro UK is no longer available. . Vox Media advised members to update their passwords after a security incident jeopardized their information. Secure your accounts immediately.. Gawker Media, Password Security, Cyber Attack Awareness, Data Integrity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.