Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A Chinese-speaking hacking group tracked as ‘DragonSpark’ was observed employing Golang source code interpretation to evade detection while launching espionage attacks against organizations in East Asia. . The attacks are tracked by SentinelLabs , whose researchers report that DragonSpark relies on a little-known open-source tool called SparkRAT to steal sensitive data from compromised systems, execute commands, perform lateral network movement, and more. The threat actors leverage compromised infrastructure in China, Taiwan, and Singapore to launch their attacks, while the intrusion vector observed by SentinelLabs is vulnerable MySQL database servers exposed online. . PhantomStrike employs Python code obfuscation to remain undetected during surveillance missions aimed at Southeast Asian organizations.. DragonSpark Espionage, Golang Interpretation, East Asia Cyber Attacks, Open Source Malware. . LinuxSecurity.com Team
Apache OpenOffice (AOO) is currently vulnerable to a remote code execution vulnerability (CVE-2021-33035) recently discovered by security researcher Eugene Lim, and while the app's source code has been patched, the fix has only been made available as beta software and awaits an official release. . That means that most people running the open source office suite, which has been downloaded hundreds of millions of times and was last updated in May, probably have vulnerable versions of the software. On Saturday, September 18, security researcher Eugene Lim revealed details about the vulnerability (CVE-2021-33035) at HackerOne's Hacktivity online conference after an August 30 public disclosure date came and went without the fix being fully deployed. . A security flaw in Apache OpenOffice permits remote code execution; a preliminary patch has been developed, though it has not been officially launched yet.. Remote Code Execution, Apache OpenOffice, Security Risk. . Brittany Day
RIPS is a tool written in PHP to find vulnerabilities using static source code analysis for PHP web applications. By tokenizing and parsing all source code files RIPS is able to transform PHP source code into a program model and to detect sensitive sinks (potentially vulnerable functions) that can be tainted by user input (influenced by a malicious user) during the program flow. . Besides the structured output of found vulnerabilities RIPS also offers an integrated code audit framework for further manual analysis. The link for this article located at Darknet is no longer available. . Besides the structured output of found vulnerabilities RIPS also offers an integrated code audit fra. written, vulnerabilities, using, static, source, analysis. . LinuxSecurity.com Team
The indicted founder of digital currency Liberty Reserve says the U.S. government began targeting him only after he refused to turn over the source code for his proprietary system to the FBI.. Arthur Budovsky, who is fighting extradition to the U.S. from Spain, told a Madrid court that the FBI approached him in 2011 to obtain the source code for what he says was the purpose of undermining the service. The link for this article located at Wired is no longer available. . Arthur Budovsky, who is fighting extradition to the U.S. from Spain, told a Madrid court that the FB. indicted, founder, digital, currency, liberty, reserve, government, began, targeting. . LinuxSecurity.com Team
SOFTWARE titan Adobe Systems has warned that hackers breached its defences and stole source code along with credit card numbers and other information relating to nearly three million customers.. "Very recently, Adobe's security team discovered sophisticated attacks on our network, involving illegal access of customer information as well as source code for numerous Adobe products," Adobe chief security officer Brad Arkin said in a blog post. The link for this article located at The Australian is no longer available. The link for this article located at The Australian is no longer available. . 'Very recently, Adobe's security team discovered sophisticated attacks on our network, involving ill. software, titan, adobe, systems, warned, hackers, breached, defences, stole, source. . LinuxSecurity.com Team
Trend Micro has published the source code of its free anti-malware tool, HijackThis (HJT), on Sourceforge under a GPLv2 licence. Trend Micro says it will be maintaining the original source code but also incorporating modifications from the community.. HijackThis creator, Merijn Bellekom, said that "this means that other people can build on a solid base to create or improve their own anti-malware tools". Bellekom's anti-spyware tool was acquired by Trend Micro in 2007 and is used by many anti-spyware communities. The link for this article located at H Security is no longer available. . HijackThis creator, Merijn Bellekom, said that 'this means that other people can build on a solid ba. source, trend, micro, published, anti-malware, hijackthis, (hjt). . LinuxSecurity.com Team
A hacker released the source code for antivirus firm Symantec's pcAnywhere utility on Tuesday, raising fears that others could find security holes in the product and attempt takeovers of customer computers. . The release followed failed email negotiations over a $50,000 payout to the hacker calling himself YamaTough to destroy the code. The email thread was published on Monday, but the hacker and the company said their participation had been a ruse. YamaTough said he was always going to publish the code, while Symantec said law enforcement had been directing its side of the talks. The link for this article located at Reuters is no longer available. . The release followed failed email negotiations over a $50,000 payout to the hacker calling himself Y. hacker, released, source, antivirus, symantec's, pcanywhere, utility, tuesday, raisi. . LinuxSecurity.com Team
Chris Evans, aka Scary Beasts, has confirmed that version 2.3.4 of vsftpd's downloadable source code was compromised and a backdoor added to the code. Evans, the author of vsftpd . The bad tarball included a backdoor in the code which would respond to a user logging in with a user name ":)" by listening on port 6200 for a connection and launching a shell when someone connects. The link for this article located at H Security is no longer available. . The bad tarball included a backdoor in the code which would respond to a user logging in with a user. chris, evans, scary, beasts, confirmed, version, vsftpd's, downloadable, source. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.