Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
83

BlackCat Ransomware Munchkin: Evolving Threats On Linux Systems

The BlackCat ransomware operators have demonstrated ongoing adaptation and innovation in their malicious activities, making mitigating their threats challenging for security experts. . BlackCat operators, like Munchkin, revealed updates for propagating their payload across victim networks. They’ve been consistently evolving their ransomware tooling over the past two years. Cybersecurity researchers at Unit 42 of Palo Alto Networks, BlackCat operators recently revealed updates, like Munchkin, for propagating their payload across victim networks. They have been consistently evolving their ransomware tooling over the past two years. Unit 42 researchers obtained a unique instance of Munchkin loaded in a customized Alpine VM, highlighting a growing trend among ransomware threat actors to use VMs for evading security solutions in malware deployment. BlackCat’s evolution over time involved obfuscating configurations and employing command-line parameters for added security. Their latest tool, ‘Munchkin,’ uses a Linux-based OS to run BlackCat on remote machines and encrypt SMB/CIFS shares. The link for this article located at CyberSecurity News is no longer available. . The BlackCat ransomware continues to advance with the introduction of its latest Munchkin tool, designed to enhance its ability to propagate threats within various network environments.. BlackCat Ransomware, Munchkin Tool, Cybersecurity Threats, Malware Propagation. . LinuxSecurity.com Team

Calendar 2 Oct 20, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
209

Linux Growth Sparks Cyber Threat Targeting in Cloud Infrastructure

With the growth of Linux in cloud environments, critical infrastructure, and even mobile platforms, hackers are increasingly targeting the open source system for higher returns. . Growing at close to 20% year-over-year, the Linux operating system market is expected to touch $22.15 billion in 2029 from a mere $6.27 billion in 2022, according to Fortune Business Insights. However, with growth, comes opportunities, and sometimes these are opportunities for threat actors. Linux has gained significant popularity and broader adoption in various domains, including servers, cloud infrastructure, Internet of Things (IoT) devices, and mobile platforms. The increased adoption of DevOps and modern applications is making Linux the platform of choice for servers and hence developers are increasingly developing it. . Expanding at nearly 18% annually, the Android platform segment is projected to reach $30.5 billion by 2028.. Linux Adoption, Open Source Risks, Cyber Threats. . Brittany Day

Calendar 2 Jul 04, 2023 User Avatar Brittany Day Security Trends
77

Tsunami Botnet Targets Linux SSH Servers: Malicious Brute Force Attacks

An unknown threat actor is brute-forcing Linux SSH servers to install a wide range of malware, including the Tsunami DDoS (distributed denial of service) bot, ShellBot, log cleaners, privilege escalation tools, and an XMRig (Monero) coin miner. . SSH (Secure Socket Shell) is an encrypted network communication protocol for logging into remote machines, supporting tunneling, TCP port forwarding, file transfers, etc. Network administrators typically use SSH to manage Linux devices remotely, performing tasks such as running commands, changing the configuration, updating software, and troubleshooting problems. However, if those servers are poorly secured, they might be vulnerable to brute force attacks , allowing threat actors to try out many potential username-password combinations until a match is found. . The Tsunami botnet malware specifically aims at inadequately protected Linux SSH servers, leveraging numerous vulnerabilities.. Linux Malware, SSH Security, Brute Force Attacks, Tsunami Botnet, Remote Server Management. . LinuxSecurity.com Team

Calendar 2 Jun 26, 2023 User Avatar LinuxSecurity.com Team Server Security
83

Adoption of Sliver C2 Increases Among Cyber Threat Actors Today

An increasing number of threat actors have started relying on the command-and-control (C2) framework Sliver as an open-source alternative to tools such as Metasploit and Cobalt Strike. . Security researchers at Cybereason described the new phenomenon in an advisory published last Thursday, adding that Sliver is gaining popularity due to its modular capabilities (via Armory), cross-platform support and vast number of features. “Sliver C2 is getting more and more traction since its release in 2020,” reads the report. “As of today, the number of threat intelligence reports is still low, and the main reports describe the use of the Russian SVR leveraging Sliver C2.” In particular, the team said it already noticed Sliver with known threat actors and malware families such as BumbleBee and APT29 (also known as Cozy Bear). . Experts at Security Inc. have highlighted the growing popularity of the Sliver command and control (C2) framework among cybercriminals.. Sliver C2, Cybersecurity Framework, Open Source Tools. . LinuxSecurity.com Team

Calendar 2 Jan 24, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Kinsing Malware Targets Oracle WebLogic And Docker APIs For Crypto Mining

Malicious actors such as Kinsing are taking advantage of both recently disclosed and older security flaws in Oracle WebLogic Server to deliver cryptocurrency-mining malware. . Cybersecurity company Trend Micro said it found the financially-motivated group leveraging the vulnerability to drop Python scripts with capabilities to disable operating system (OS) security features such as Security-Enhanced Linux ( SELinux ), and others. The operators behind the Kinsing malware have a history of scanning for vulnerable servers to co-opt them into a botnet, including that of Redis , SaltStack , Log4Shell, Spring4Shell, and the Atlassian Confluence flaw (CVE-2022-26134). The link for this article located at The Hacker News is no longer available. . Fortinet uncovers BlackMatter ransomware targeting VMware and Microsoft SQL Server for data encryption.. WebLogic Exploit, Cyber Threats, Cryptocurrency Mining, Kinsing Malware, Docker API Security. . LinuxSecurity.com Team

Calendar 2 Sep 19, 2022 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Evasive Techniques Used By Malicious Shell Scripts And Detection Methods

Learn about common defense evasion techniques used in malicious shell scripts and how Uptycs detects them. . Attackers use malicious shell scripts as an initial vector to download malicious payloads to the victim system. In the earlier days, base64 and other common encoding schemes were used to evade defensive parameters. But nowadays, threat actors are adopting newer techniques that include commands to disable firewalls, monitoring agents etc. The link for this article located at Uptycs Blog is no longer available. . Threat actors leverage command-line scripts to undermine security measures, gaining insights into novel evasion strategies and Uptycs monitoring capabilities.. Malicious Shell Scripts, Evasion Techniques, Uptycs Detection. . LinuxSecurity.com Team

Calendar 2 Jul 07, 2021 User Avatar LinuxSecurity.com Team Hacks/Cracks
210

Aviatrix VPN: Critical Risk of Escalation Privileges in Linux Settings

Aviatrix, a supplier of open source enterprisevirtual private networks(VPNs) to customers including BT, Nasa and Shell, has patched a serious vulnerability in its client that could have given an attacker escalation privileges on a machine to which they already had access. Learn more about this vulnerability and its implications for Linux users in an informative Computer Weekly article: . The vulnerability was uncovered byImmersive Labsresearcher and content engineer Alex Seymour, after noticing that the VPN client was unusually verbose when booting on a Linux machine. Its disclosure comes hot on the heels of government warnings about the possibility of state-sponsored threat actors targeting high-profile organisations through VPN vulnerabilities in products from the likes of Pulse Secure, Palo Alto Networks and Fortinet. The link for this article located at Computer Weekly is no longer available. . An alarming vulnerability in Aviatrix VPN presents a critical risk of privilege escalation, jeopardizing the safety of users operating within Linux ecosystems. Discover further details.. Aviatrix, VPN, escalation privileges, Linux security, threat actors. . Brittany Day

Calendar 2 Dec 05, 2019 User Avatar Brittany Day Security Vulnerabilities
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here