Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The alarming discovery of a backdoor in the xz data compression library , which had the potential to compromise Linux systems, has dominated recent security news. While the backdoor did not make its way into production Linux distributions, the incident raises crucial questions about open-source security and the need for vigilance in the face of emerging threats. . How Was This Backdoor Introduced? What Were the Motives Behind It? A Microsoft software engineer, Andres Freund, detected the slow performance of the SSH remote security code in the Debian Linux beta. This discovery led Freund to investigate and identify that Jia Tan, the chief programmer and maintainer of the xz library , had inserted a backdoor to enable attackers to gain control over Linux systems. This incident is notable because, until now, malware has not been successfully concealed within Linux code. Linux managed to evade a potentially catastrophic situation thanks to its open-source nature . Mark Atwood, Amazon's open-source program office principal engineer, highlights that the attack failed precisely because the code was open and accessible to scrutiny. In contrast, closed-source components often present challenges in detecting and mitigating covert attacks. The motives behind the backdoor are unknown, but we can speculate the possibility of crypto miners attempting to infiltrate high-powered Linux systems to capitalize on the surging value of cryptocurrencies. While the exact identity of the attacker remains unknown, their extensive efforts to compromise the xz project in 2021 and push the infected program into Linux distributions are evident. What Are the Implications of This Backdoor? What Can the Community Learn from This Issue? This issue raises critical questions about the security implications of open-source software and the Linux community's underlying responsibility to ensure its code's safety. It underscores the importance of continuous code review, especially within the open-source supply chain , toidentify and address vulnerabilities promptly. The incident with the xz backdoor serves as a wake-up call for Linux admins, infosec professionals, internet security enthusiasts, and sysadmins. The potential consequences of such an attack could have been catastrophic, compromising individual systems and entire infrastructures. It highlights the need for a proactive approach to security and the constant evolution of defensive measures to match emerging threats. This incident also sheds light on the possibility of additional open-source malware programs that have yet to be discovered. This raises questions about the overall security posture of the Linux ecosystem and the measures put in place to detect and prevent future attacks. It prompts security practitioners to reflect on the current defenses and collaborate on strengthening the entire open-source supply chain against persistent threats. Our Final Thought on the XZ Utils Linux Backdoor The close call that Linux encountered with the xz backdoor incident highlights the critical need for continuous code review and an engaged security community. It underscores the importance of maintaining a disciplined and vigilant approach to open-source security rather than relying solely on the assumption that open-source code is inherently secure. Security practitioners, Linux admins, infosec professionals, internet security enthusiasts, and sysadmins play a crucial role in upholding the security and integrity of open-source software. This incident serves as a reminder to stay alert , actively contribute to code review efforts, and collaborate with the broader community to safeguard against potential threats that may have long-term consequences. . The xz utils backdoor incident has highlighted vulnerabilities in open-source software, stressing the need for rigorous code audits, secure supply chains, and a security-first mindset. xz Utils, Open Source Threats, Backdoor Security, Linux Risks. . Brittany Day
"Variants of CL0p were initially only found on Windows systems, but the gang also developed a Linux variant toward the end of 2022, reflecting the diversity of endpoint operating systems used by modern businesses. In an interesting, flawed technical glitch, security researchers noted that the Linux version’s encryption is easily reversible using a simple decryptor." . CL0p is a notorious name on the ransomware scene, and with good reason. The gang’s members have been responsible for a series of high-profile attacks since security researchers first spotted their ransomware strain in the wild back in 2019. Our internal data shows that CL0p continues to cause havoc and will likely supplant LockBit as the top ransomware gang in 2023. Here is a deep dive into the CL0p ransomware and the gang’s attacks. CL0p is the name given to a group of Russian-speaking threat actors who use a ransomware strain that appends the extension .CL0p onto encrypted system files. The gang’s members tweaked a previously used ransomware strain known as CryptoMix to create ransom.CL0p. The group is financially motivated and began its operations by targeting businesses earning at least $5 million in annual revenues. Among the techniques used in traditional CL0p ransomware attacks are local file deletion, evading sandboxes, downloading tools from external URLs and halting system processes. Attacks commonly feature the Truebot tool, which collects and transmits information about the local system in addition to loading malicious shell code and other program modules. The popular adversary simulation tool Cobalt Strike helps CL0p threat actors expand their network access to multiple systems. The link for this article located at Security Boulevard is no longer available. . The LockBit ransomware group broadens its approach by targeting macOS systems, exploiting vulnerabilities and wreaking havoc throughout networks.. CL0p Ransomware, Linux Malware, Threat Actors, Cybercrime, EndpointSecurity. . LinuxSecurity.com Team
After rising and falling since 2021, new Linux malware hit record highs at year-end in 2022, growing by 117% over previous levels. . While Linux malware reached never-before-seen numbers in 2022, the total number of new malware developments among other major computing platforms fell. Linux is regarded as one of the most secure operating systems. But its roller coaster ride of detected incidents since 2021 shows it is not immune to malware. Malware attacks targeting Linux are not new. What is changing, though, is the focus cybercriminals now place on Linux in business and industry. Linux malware has become increasingly prevalent in recent years as more devices and servers run on Linux operating systems. The link for this article located at Linux Insider is no longer available. . As Linux-based threats soar to all-time highs, uncover the evolving terrain of cyber dangers aimed at Linux environments.. Linux Malware Rates,Cyber Threats,Malware Prevalence,Security Incident Reports. . Brittany Day
Attackers are deploying a Linux backdoor on compromised e-commerce servers after injecting a credit card skimmer into online shops' websites. . The PHP-coded web skimmer (a script designed to steal and exfiltrate customers' payment and personal info) is added and camouflaged as a .JPG image file in the /app/design/frontend/ folder. The attackers use this script to download and inject fake payment forms on checkout pages displayed to customers by the hacked online shop. . Cybercriminals implement a sinister JavaScript payload on UNIX-based online retail platforms, aiming to capture buyers' financial details via counterfeit submission forms.. Linux Malware, Web Skimmer, E-Commerce Security, PHP Injection, Online Threats. . LinuxSecurity.com Team
Kubernetes adoption is up - and so is the number of security incidents in container and Kubernetes environments. One of the ways that organizations can tackle this issue is by focusing on securing the container supply chain. . Kubernetes adoption is up, but many organizations are suffering security incidents in their container and Kubernetes environments. In the fall edition of the “State of Container and Kubernetes Security” report, for instance, 91% of respondents told StackRox that they had adopted the container orchestration platform. That’s about the same proportion (90%) of survey participants that admitted to having suffered a security incident in their Kubernetes and container environments over the preceding 12 months. Two-thirds of those security incidents consisted of a misconfiguration issue. Those events were followed by a vulnerability incident (22%), a runtime incident (17%) and a failed audit (16%). Nearly half (44%) of respondents said that they ultimately delayed moving an application into production as a result of their security concerns. . The utilization of cloud-native technologies is growing, yet security breaches within orchestrated systems persist in posing difficulties for enterprises.. Kubernetes Security, Container Incidents, Secure Supply Chain, Dynamic Admission Control. . Brittany Day
OpenWRT has disclosed a data breach that occurred after a malicious hacker gained access to a forum admin account. The OpenWRT wiki, which contains the official download links, was not compromised, the project said.. The maintainers of OpenWRT , an open-source project that provides free and customizable firmware for home routers, have disclosed a security breach that took place over the weekend. According to a message posted on the project's forum and distributed via multiple Linux and FOSS-themed mailing lists , the security breach took place on Saturday, January 16, around 16:00 GMT, after a hacker accessed the account of a forum administrator. . OpenWRT reported a security incident where an intruder gained unauthorized entry to an administrator account on its forum, impacting the community's safety.. OpenWRT Data Breach, Firmware Security, Admin Account Compromise. . LinuxSecurity.com Team
Have you heard that Japanese cryptocurrency exchange Bitpoint has been hacked, resulting in the loss of $32 million worth of various digital currencies? The majority of funds lost (approximately $23 million) belonged to customers, while the rest were owned by the exchange. . Bitpoint has ceased operations and says the funds were stolen from a hot wallet that contained five cryptocurrencies including Bitcoin, Ripple, and Bitcoin Cash. As of yet, the company says it is not aware of any funds taken from cold wallets. The link for this article located at The Next Web is no longer available. . CryptoTrade suffered a breach, losing assets from an online wallet, discontinuing services after a theft that caused a $25 million shortfall.. cryptocurrency loss, Bitpoint hack, digital currency security. . LinuxSecurity.com Team
A new report of the investigation into the $530 million hack that ruined Japanese cryptocurrency exchange Coincheck in January 2018 states that Russian, not North Korean, actors may have been behind the attack. . The Asahi Shimbun, a Japanese newspaper, reported that viruses that were thought to have been used in the hack were found on employees’ computers. According to the Asahi Shimbun, the viruses were linked to Russian hacker groups and named “Mokes” and “Netwire.” These viruses were most likely transferred via email, and allowed the hackers to gain access to private keys. The link for this article located at Security Today is no longer available. . An analysis reveals that a cybercriminal group from Russia orchestrated the $530 million heist of Coincheck's cryptocurrency, utilizing sophisticated malware techniques.. Cryptocurrency Hack, Russian Hackers, Cybersecurity Investigation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.