A new covert Linux kernel rootkit named Syslogk has been spotted under development in the wild and cloaking a malicious payload that can be remotely commandeered by an adversary using a magic network traffic packet . . "The Syslogk rootkit is heavily based on Adore-Ng but incorporates new functionalities making the user-mode application and the kernel rootkit hard to detect," Avast security researchers David Álvarez and Jan Neduchal said in a report published Monday. Adore-Ng, an open-source rootkit available since 2004, equips the attacker with full control over a compromised system. It also facilitates hiding processes as well as custom malicious artifacts, files, and even the kernel module, making it harder to detect. The link for this article located at The Hacker News is no longer available. . A recently uncovered Linux kernel exploit enables threat actors to manipulate devices from a distance via specially crafted packets.. Syslogk Rootkit, Remote Control, Linux Kernel Threat. . LinuxSecurity.com Team
A security flaw in Google Chrome allows an attacker to eventually take control a vulnerable host, and Google recommends users to deploy a patch as soon as possible. All versions of the browser are affected, including Google Chrome for Linux. Learn more: . The bug was discovered by the Center for Internet Security, who writes that governments might be the primary target of any potential attack. The vulnerability requires users to visit a malicious website, at which point an attacker could attempt to run arbitrary code with the final goal of taking control of the device. The link for this article located at Softpedia News is no longer available. . An urgent vulnerability in Mozilla Firefox has been discovered, which could permit external manipulation through infected webpages. Please upgrade at once to protect your system.. Google Chrome Security, Remote Code Execution, Browser Vulnerability. . Brittany Day
Siri may be your personal assistant. But your voice is not the only one she listens to. As a group of French researchers have discovered, Siri also helpfully obeys the orders of any hacker who talks to her . A pair of researchers at ANSSI, a French government agency devoted to information security, have shown that they can use radio waves to silently trigger voice commands on any Android phone or iPhone that has Google Now or Siri enabled, if it also has a pair of headphones with a microphone plugged into its jack. . Scientists demonstrate the potential for cybercriminals to activate Siri and Google Assistant functionalities using radio signals from afar.. Voice Assistant Security, Radio Wave Attacks, Siri Vulnerabilities. . LinuxSecurity.com Team
Macs older than a year are vulnerable to exploits that remotely overwrite the firmware that boots up the machine, a feat that allows attackers to control vulnerable devices from the very first instruction. . The attack, according to a blog post published Friday by well-known OS X security researcher Pedro Vilaca, affects Macs shipped prior to the middle of 2014 that are allowed to go into sleep mode. He found a way to reflash a Mac's BIOS using functionality contained in userland, which is the part of an operating system where installed applications and drivers are executed. By exploiting vulnerabilities such as those regularly found in Safari and other Web browsers, attackers can install malicious firmware that survives hard drive reformatting and reinstallation of the operating system.. Older Mac models face increased risks from firmware exploits due to outdated software and lack of updates, enabling remote attacks and data breaches. Mac Security,Firmware Exploits,Remote Control Attacks,OS X Vulnerabilities. . LinuxSecurity.com Team
At the DEFCON hacking conference, which ended yesterday, IT security researchers Nicholas Percoco and Christian Papathanasiou demonstrated what they claim is the first rootkit for Android. Their aim was to show how slight the obstacles to the development of a such a rootkit are and how powerful the result can be. Android is Linux-based and desktop Linux rootkits are nothing out of the ordinary.. The demo rootkit, dubbed "Mindtrick", is a Loadable Kernel Module (LKM) and can conceal itself from other processes. The demo was included in a DVD given to DEFCON delegates. The rootkit can gain access to Android devices, either through using unpatched vulnerabilities, or by pretending to be a legitimate app. Two other researchers recently showed that it's possible to spread infected apps to thousands of devices. Once installed, the rootkit is activated by calling the infected mobile from a specific number. It then establishes a connection to the attacker's computer, which allows the phone to be controlled remotely. As the researchers demonstrated in their talk, this gives the attacker access to the Android phone's SQLite database, allowing them to view, for example, a victim's texts or contacts. It's also possible to remotely read the device's current GPS coordinates and to make outgoing calls without this being shown on the display. Criminals could make use of the latter by running up costs for expensive sex lines which they in turn operate. According to the researchers, current anti-virus software for Android does not (yet) detect the rootkit. The link for this article located at H Security is no longer available. . The demo rootkit, dubbed 'Mindtrick', is a Loadable Kernel Module (LKM) and can conceal itself from . defcon, hacking, conference, which, ended, yesterday, security, researchers, nicholas, percoco. . LinuxSecurity.com Team
Remote-controlled "zombie" networks operated by bottom-feeding spammers have become a serious problem that requires more industry action, the Federal Trade Commission is expected to announce on Tuesday. . The FTC and more than 30 of its counterparts abroad are planning to contact Internet service providers and urge them to pay more attention to what their customers are doing online. Among the requests: identifying customers with suspicious e-mailing patterns, quarantining those computers and offering help in cleaning the zombie code off the hapless PCs. To be sure, computers infected by zombie programs and used to churn out spam are a real threat to the future of e-mail. One report by security firm Sophos found that compromised PCs are responsible for 40 percent of the world's spam--and that number seems to be heading up, not down. But government pressure--even well-intentioned--on Internet providers to monitor their users raises some important questions. Will ISPs merely count the number of outbound e-mail messages, or actually peruse the content of e-mail correspondence? E-mail eavesdropping is limited by the Electronic Communications Privacy Act in the United States, but what about other countries without such laws? If these steps don't stop zombie-bots, will the government come back with formal requirements instead of mere suggestions the next time around?. Regulatory bodies are addressing fraudulent networks and highlighting the vital position of internet service providers in protecting consumers.. Spam Network Management, Botnet Defense, FTC Guidelines. . Brittany Day
Networks of computers that are exploited by spammers and hackers to forward junk e-mail and viruses without the knowledge of the PC user, known as bot networks, are on the increase, according to anti-virus firm Symantec. . . .. Networks of computers that are exploited by spammers and hackers to forward junk e-mail and viruses without the knowledge of the PC user, known as bot networks, are on the increase, according to anti-virus firm Symantec. A bot (short for 'robot') is a program that is covertly installed on a targeted system, allowing an unauthorised user to remotely control the computer for a wide variety of purposes. Co-ordinating a group of bot-controlled systems makes a bot network, used to increase the speed and breadth of attacks. The link for this article located at Out-law.com is no longer available. . Networks of computers that are exploited by spammers and hackers to forward junk e-mail and viruses . networks, computers, exploited, spammers, hackers, forward, e-mail, viruses. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.