Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
83

MUT-1244 Advisory: Credential Theft Risks and Protection Steps

In recent months, Linux security administrators and WordPress site owners have encountered a formidable adversary: MUT-1244 . This threat actor has been unleashing havoc by targeting academics, penetration testers, red teamers, security researchers, and other threat actors. MUT-1244's primary goal is to acquire sensitive data, including AWS access keys and WordPress account credentials. . Their campaign leverages trojanized GitHub repositories designed to fool even the most diligent users. By disguising malicious code as legitimate tools and repositories, MUT-1244 has managed to steal over 390,000 credentials. This article will delve into how MUT-1244 operates, highlighting the infection vectors, the extent of credential exfiltration, and the critical indicators of compromise you need to watch out for. We'll break down the practical steps Linux security admins can take to safeguard their systems and data, from verifying software sources to implementing robust credential management practices. By understanding and recognizing the tactics employed by MUT-1244, you can better protect your environment against this persistent and evolving threat. Infection Vectors: Trojanized GitHub Repositories One of the primary ways MUT-1244 has managed to infiltrate systems is through trojanized GitHub repositories. Many security professionals, including penetration testers and red teamers, rely on various open-source tools on GitHub to perform their tasks. MUT-1244 has exploited this trust by creating repositories that appear legitimate but are laden with malicious code. When unsuspecting users clone and execute these repositories, they inadvertently run malicious scripts that compromise their systems. These scripts swiftly harvest credentials and other sensitive data, relaying the information to the attackers. MUT-1244 has been particularly cunning in ensuring that the malicious repositories are well-crafted and the malicious code is deeply embedded, making it difficult for users to immediately detectanything amiss. Exfiltration: The Scope of the Breach The exfiltration of credentials is the core objective of MUT-1244's campaign. By specifically targeting tools that offensive security professionals would use, the threat actor has gathered a vast trove of sensitive data, including AWS access keys and WordPress account credentials. These credentials are critical, as they can provide attackers direct access to various services and platforms, potentially leading to further exploitation and data breaches. The trojanized tools used in these attacks are designed to look like legitimate credentials checkers, which security professionals use to audit and manage passwords and keys. But instead of merely checking the credentials, these tools are configured to capture and exfiltrate them. Sometimes, the compromised tools even provide normal feedback, making it harder for users to realize they have been duped. Indicators of Compromise: What to Watch Out For Understanding the indicators of compromise (IoCs) associated with MUT-1244 can help in early detection and remediation. Some of the most important IoCs to be aware of include phishing email tactics and known malicious GitHub users and repositories. One common phishing tactic involves sending emails with subjects like "Notification: Important CPU Microcode Update for High-Performance Computing (HPC) Users" from senders such as This email address is being protected from spambots. You need JavaScript enabled to view it.. These emails trick recipients into downloading compromised tools or clicking malicious links. Furthermore, several malicious GitHub users and repositories have been identified as part of this campaign. Users with names like 0x3ngine, 0xget, and 0zzzer, and repositories such as 0x3ngine/xmrdropper and 0xget/cve-2001-1473 are known to distribute compromised code. Practical Steps for Protecting Your Systems Given the persistent and evolving nature of threats like MUT-1244, Linux admins should implement a multifaceted approach to securing their systems and credentials. Here are severalpractical steps to safeguard systems and data effectively: Audit Third-Party Tools & Repositories: Thoroughly audit any third-party tools and repositories before integrating them into your workflow. This means verifying the source's legitimacy, assessing the code's integrity, and performing internal security checks before deployment. Where possible, use repositories from well-known and reputable sources or official channels. Practice Secure Credential Management: Implement stringent credential management practices. Regularly rotate credentials, enforce strong password policies, and use multi-factor authentication (MFA) whenever feasible. These practices can help limit the risk of credential theft and ensure that compromised credentials are quickly rendered useless. Educate Users: Educate your team about common phishing tactics and the specific methods used by MUT-1244. Awareness training can significantly reduce the likelihood of falling prey to phishing schemes. Ensuring that users can recognize suspicious emails and understand how to respond appropriately can make a big difference in preventing initial compromises. Use Strong Access Controls: Leverage robust access controls and comprehensive logging mechanisms. By setting up fine-grained access controls and monitoring user activity closely, you can quickly detect and respond to anomalous behavior. Logs can provide critical insights into potential security incidents, allowing for faster remediation and investigation. Stay Current & Proactive: Stay informed about the latest threat intelligence and updates relating to your security tools. Subscribing to industry newsletters, attending security conferences, and participating in professional forums can help you stay ahead of emerging threats and keep up with best practices. Keeping your security tools and threat databases up to date is crucial for maintaining an effective defense against adversaries like MUT-1244. Our Final Thoughts: Vigilance and Proactive SecurityAdministration are Key MUT-1244 poses an immense threat to Linux security administrators, particularly those working in offensive security. By compromising over 390,000 credentials using trojanized GitHub repositories and sophisticated phishing tactics, this threat actor has highlighted the necessity for stringent measures and constant vigilance against attacks of this nature. To protect against these threats, it's essential to regularly assess third-party tools, implement strong credential management practices, and stay abreast of IoCs and threat intelligence updates. Involving your team members in understanding potential attack vectors while maintaining strong access controls can also significantly strengthen your security posture. By taking proactive measures and staying vigilant, Linux admins can protect their systems and data against evolving threats posed by actors like MUT-1244. The key is staying informed, implementing best practices, monitoring security measures regularly for new challenges as they emerge, and adapting accordingly. . Uncover the methods by which MAL-5678 exploits vulnerable credentials via compromised code bases and deceptive emails. Explore defensive strategies.. credential security,trojanized tools,phishing attacks,Linux security threats,repository audit. . Brittany Day

Calendar 2 Dec 19, 2024 User Avatar Brittany Day Hacks/Cracks
83

Dropbox Security Breach: GitHub Code Theft via Phishing Attack

Dropbox has revealed details of a phishing attack to which it fell victim. In the attack, a threat actor was able to steal code from the company after gathering employee credentials to GitHub repositories.. The security breach took place in the middle of last month, with GitHub notifying Dropbox of suspicious account activity on October 14. The cloud storage company says that the code that was accessed "contained some credentials -- primarily, API keys -- used by Dropbox developers" but insists that "no one's content, passwords, or payment information was accessed", and that its core apps and infrastructure were unaffected. In a blog post that goes into some detail about the incident, Dropbox says: "In today's evolving threat landscape, people are inundated with messages and notifications, making phishing lures hard to detect. Threat actors have moved beyond simply harvesting usernames and passwords, to harvesting multi-factor authentication codes as well. In September, GitHub detailed one such phishing campaign, in which a threat actor accessed GitHub accounts by impersonating the code integration and delivery platform CircleCI. We recently learned that Dropbox was targeted by a similar campaign. . Dropbox encountered a serious cybersecurity incident, in which source code was compromised from GitHub through phishing tactics; however, essential systems remain intact.. Dropbox Security, GitHub Phishing Attack, Code Theft Risk, API Key Protection. . LinuxSecurity.com Team

Calendar 2 Nov 02, 2022 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Privacy Compromised: Smart Speaker Apps Eavesdrop and Phish Users

Privacy is a hot topic in the realm of smart speakers, fromemployees listening in on recordingsand auditorsaccessing user locations. Now, another issue regarding speakers has been raised, after security researchers revealed that apps accepted by the Amazon Alexa and Google Home platforms could be used to phish users and to eavesdrop on them. Learn more in an interesting Engadget article: . Researchers from the firm Security Research Labs created the apps, known as Skills for Alexa and Actions for Google Home, which exploited security vulnerabilities to hack devices, as reported by Ars Technica . SRL created several apps for each platform which appeared to be legitimate skills like a horoscope app, but which actually hid malicious code. The apps were able to collect personal data including passwords, and also to eavesdrop on users even after they thought that the speaker was no longer listening. This worked by the app giving a fake error message which sounded as if it had closed, while it actually it continued operating and taking down a transcript of everything the user said after that point. The link for this article located at Engadget is no longer available. . Studies indicate that Smart Assistant applications are capable of enabling unauthorized listening and fraudulent schemes, thereby jeopardizing user confidentiality.. Smart Speakers, Security Vulnerability, Eavesdropping App, User Data Theft. . LinuxSecurity.com Team

Calendar 2 Oct 21, 2019 User Avatar LinuxSecurity.com Team Privacy
83

FIFA Data Breach: Phishing Attack Exposes Sensitive Data

FIFA President Gianni Infantino said in a statement to the press that the world football governing body's computer systems suffered a data breach for the second time this year. Moreover, both the Fédération Internationale de Football Association (FIFA) and Union of European Football Associations (UEFA) are both suspected of having suffered data breaches.. Hackers might have stolen sensitive data after compromising FIFA's computer systems via a phishing campaign targeting multiple officials of the football global governing entity. The link for this article located at Softpedia News is no longer available. . Hackers might have stolen sensitive data after compromising FIFA's computer systems via a phishing c. president, gianni, infantino, statement, press, world, football, governing. . LinuxSecurity.com Team

Calendar 2 Nov 04, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

George Garofano: 8 Months for iCloud Phishing Crime and Celebrity Breach

What does it cost to gain unauthorized access to roughly 240 Apple iCloud accounts? For George Garofano, 26, the price is eight months in federal prison followed by three years of supervised release and 60 hours of community service.. Garofano used a phishing attack, claiming to be from Apple security, to get account holders to send him their login credentials. He used the information from victims, which included a number of people in the entertainment industry, to steal personal information, including photos and videos. He also traded the credentials and personal information with others. The FBI investigation began when personal photos of female celebrities, including actress Jennifer Lawrence, began to be leaked online in 2014. The link for this article located at DarkReading is no longer available. . DiMarco's hacking operation resulted in illegal intrusions into Google Drive accounts and a lengthy prison term.. Phishing Attack, Data Breach, Cybercrime, Apple iCloud, User Privacy. . LinuxSecurity.com Team

Calendar 2 Aug 30, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Augusta University Health Data Breach Affects 417,000 Patients

A leading US healthcare organization (HCO) has admitted that a phishing attack last September may have led to the compromise of highly sensitive data on nearly half a million patients. . Georgia-based Augusta University Health claimed it was notified by investigators on July 31 that a September 2017 phishing attack on hospital staff may have given the hackers access to data on around 417,000 patients. The link for this article located at InfoSecurity is no longer available. . Georgia-based Augusta University Health claimed it was notified by investigators on July 31 that a S. leading, healthcare, organization, (hco), admitted, phishing, attack, september. . LinuxSecurity.com Team

Calendar 2 Aug 21, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

MyFitnessPal: 150 Million Accounts Compromised - Change Your Password Now

MyfitnessPal has been hacked! Because email addresses were among the information stolen, criminals have been able to send MyfitnessPal spear phishing emails for the past month. These spear phishing attacks are especially dangerous because stolen personal information that users had logged in the app can be used to make phishing emails very convincing and difficult to detect. . Under Armour’s hugely popular fitness tracker, MyFitnessPal, has been hacked. If you’re one of the 150 million or so users of the app or website don’t panic, but do change your password. If you use Facebook to log in to MyFitnessPal you do not need to change your Facebook password. If you use your MyFitnessPal password on any other websites, change your password on those websites – choose a different, strong password for each one (consider using a password manager if that sounds too difficult).. Strava experienced a data breach impacting 100 million users. Update your credentials to safeguard against potential scams.. MyFitnessPal Accounts, Password Change, Phishing Risks, Account Security. . LinuxSecurity.com Team

Calendar 2 Apr 02, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Google Targets Phishing Campaigns Ahead Of Iran Presidential Elections

Google has detected large-scale phishing attacks targeting users in Iran, ahead of presidential elections in the country. . The company has detected and disrupted for almost three weeks email-based phishing campaigns that are aimed at compromising the accounts of tens of thousands of Iranian users, Eric Grosse, Google's vice president for security engineering wrote in a blog post Wednesday. The link for this article located at TechWorld is no longer available. . Google disclosed its successful efforts to thwart email phishing schemes targeting numerous Iranian individuals ahead of the presidential elections.. Google Phishing, Cybersecurity Threats, Email Security, Iran Cyber Attacks, Presidential Election Security. . LinuxSecurity.com Team

Calendar 2 Jun 14, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here