Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The infamous FinSpy spyware has returned - and is now targeting Linux and macOS users. FinSpy is being used in new campaigns targeting dissident organizations in Egypt. . The FinSpy commercial spyware is back in recently observed campaigns against organizations and activists in Egypt. While the spyware previously targeted Windows, iOS and Android users, researchers have discovered these campaigns using new variants that target macOS and Linux users. FinSpy is a full-fledged surveillance software suite, which has the ability to intercept victims’ communications, access private data, and record audio and video, according to Amnesty International, which uncovered the recent new variants. It’s been in use by law-enforcement and government agencies around the world since 2011. The link for this article located at ThreatPost is no longer available. . The sophisticated malware known as FinSpy is particularly aimed at individuals using Linux and macOS, focusing on campaigns against both activist groups and various organizations.. FinSpy, Linux Security Threats, Malware Attacks, macOS Surveillance. . LinuxSecurity.com Team
Have you heard that spyware based on two-year-old AhMyth RAT has made it past Play Store's scans, despite not being anything special? Learn more in this interesting ZDNet article: . You know Play Store security scans are really bad when spyware based on open source code manages to slip past Google's defenses, not once, but twice. The Android app that did this is called Radio Balouch, also RB Music, an app for streaming Balouchi music, specific to a geographical region and population that spreads across Iran, Afghanistan, and Pakistan. The link for this article located at ZDNet is no longer available. . App Marketplace inspections falter as community-driven malware evades safeguards, revealing critical vulnerabilities in data protection.. Open Source Spyware, Play Store Security, Android Security Risks. . LinuxSecurity.com Team
Chinese authorities are secretly installing surveillance apps on smartphones of foreigners at border crossings in the Xinjiang region who are entering from neighboring Kyrgyzstan, an international investigation revealed. . Xinjiang (XUAR) is an autonomous territory and home to many Muslim ethnic minority groups where China is known to be conducting massive surveillance operations, especially on the activities of Uighurs, a Muslim Turkic minority group of about 8 million people. The Chinese government has blamed the Muslim Turkic minority group for Islamic extremism and deadly attacks on Chinese targets. The link for this article located at The Hacker News is no longer available. . Xinjiang authorities are reportedly installing spyware on foreign smartphones at border crossings, revealing alarming surveillance tactics.. chinese, authorities, secretly, installing, surveillance, smartphones, foreigners, border. . LinuxSecurity.com Team
On Monday 13 May, Facebook revealed that an “advanced cyber actor” has been spying on some users of its ridiculously popular WhatsApp messaging app, thanks to a zero-day vulnerability that allowed hackers to install spyware, silently, just by calling a victim’s phone. . The vulnerability is now fixed, which means that if you’re one of WhatsApp’s 1,500,000,000 users you need to go to the well and drink up the latest version. There’s a good chance your app’s already updated itself, but this is a serious vulnerability so we advise you to check all the same. The link for this article located at NakedSecurity is no longer available. . The issue has been resolved. For the 1,500,000,000 users of WhatsApp, make sure to update immediately to ensure your device's protection.. WhatsApp Update, zero-day exploit, cyber security threat, spyware risk. . LinuxSecurity.com Team
Amnesty International has been spearphished by a WhatsApp message bearing links to what the organization believes to be malicious, powerful spyware: specifically, Pegasus, which has been called History’s Most Sophisticated Tracker Program. . On Wednesday, the human rights-focused NGO said in a post that a staffer received the link to the malware in June. It was baited with a message written in Arabic that implored the group to cover a protest for “your brothers detained in Saudi Arabia in front of the Saudi embassy in Washington.” The link for this article located at Naked Security/Sophos is no longer available. . Human Rights Watch disclosed that malware was transmitted via Facebook Messenger, targeting an employee masquerading as news article distribution.. Amnesty International, WhatsApp Phishing, Cybersecurity Threats. . LinuxSecurity.com Team
The cyberattacker who stole 400GB in corporate data belonging to spyware firm Hacking Team has come forward. Hacking Team has not had a good week. The Milan, Italy-based company, known for selling surveillance and spyware tools to government agencies and private companies, experienced a data breach over the weekend which led to the alleged theft of 400GB of corporate data.. The file, which has spread like wildfire through torrent sharing, magnets and mirrors, contains information including customer lists, financial statements and allegedly the source code of tools supplied by the company. The link for this article located at ZDNet Security is no longer available. . Significant leak of corporate information by CyberOps, revealing customer databases and accounting details. Discover more here.. Data Breach, Spyware Tools, Cybersecurity Incident, Corporate Intelligence. . LinuxSecurity.com Team
A special hacking unit of the U.S. National Security Agency intercepts deliveries of new computer equipment en route to plant spyware, according to a report on Sunday from Der Spiegel, a German publication.. The method, called "interdiction," is one of the most successful operations conducted by the NSA's Office of Tailored Access Operations (TAO), which specializes in infiltrating computers, wrote the publication, citing a top-secret document. The link for this article located at Network World is no longer available. . CIA's elite team adeptly executes network surveillance to introduce malware, exposing critical data vulnerabilities.. NSA Operations, Cyber Surveillance, Computer Security, Spyware Interception. . LinuxSecurity.com Team
Backdoored versions of a widely used privacy tool have surfaced in Iran, raising fears that its government is using the Trojanised software to spy on its citizens. . A free encrypted proxy tool called Simurgh The link for this article located at The Register UK is no longer available. . Compromised iterations of the Simurgh application highlight alarm over the Iranian state surveilling individuals via malware.. Trojan Software, Iranian Surveillance, Encrypted Proxy Tools. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.