Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Hackers have developed a Linux port of the Cobalt Strike penetration testing toolkit dubbed Vermilion Strike to evade malware detection. . Cyber criminals have developed a Linux port of the Cobalt Strike penetration testing tool that has been dubbed Vermilion Strike, security researchers have discovered. The tool has been developed from scratch to avoid detection from malware scanners. According to a report published by cloud security firm Intezer Labs, researchers last month discovered a fully undetected ELF implementation of Cobalt Strike’s beacon . The malware used Cobalt Strike’s Command and Control (C2) protocol when communicating to its C2 server and has remote access capabilities such as uploading files, running shell commands, and writing to files. . Hackers have developed a Linux variant of Cobalt Strike, upgrading their malware avoidance strategies with additional features.. Linux Port Cobalt Strike, Vermilion Strike, Malware Evasion, Penetration Testing Toolkit, Cyber Crime. . LinuxSecurity.com Team
The rise of malware designed to infect Linux servers' distributed denial-of-service attacks has earned greater attention from VirusTotal, the Google-owned go-to tool for malware hunters. For security researchers that need to stay on top of emerging malware threats, the VirusTotal malware database has become an integral tool.. Anyone can upload a suspicious file to the web tool to check whether the dozen or so antivirus engines, such as Kaspersky, McAfee, Symantec, and other equivalents, detect it as malware. The tool is meant for good guys, but as one researcher found last year, black hat hackers were also using the service to test their malware against antivirus products prior to releasing it in the wild - despite the tool's shortcomings for comparative analysis. The link for this article located at ZDNet Blogs is no longer available. . Explore the ways in which ThreatTracker supports analysts in tackling new Linux malware challenges and scrutinizing server infiltration pathways.. Linux Malware, VirusTotal Detection, Server Security Insights. . LinuxSecurity.com Team
Most Linux distributions have a significant focus on security. This does not mean they are necessarily ready for production out of the box. Tools like SELinux, excellent firewall options, and robust access controls can make Linux exceptionally secure. . Despite this, actually deploying a Linux system into production still requires that the systems administrator have some idea what they are doing. Let's use my favourite distribution, CentOS, as an example. (CentOS is a near-identical repackaging of Red Hat Enterprise Linux.) By default, SELinux is turned on. In most situations, this is a great thing; SELinux provides a layer of sandboxing so that applications of a certain class can't impinge upon files belonging to applications or users of another class. The link for this article located at The Register UK is no longer available. . Despite this, actually deploying a Linux system into production still requires that the systems admi. linux, distributions, significant, focus, security, necessari. . LinuxSecurity.com Team
Researchers at North Carolina State University and Microsoft Research have come up with a way to combat rootkits by using the machine's own hardware-based memory protection: the so-called HookSafe tool basically protects the operating system kernel from rootkits.. Rootkits are the most difficult of malware to detect and remove: they often evade detection by anti-malware software, and even if they are discovered, they can still be difficult to completely eradicate. A rootkit typically hijacks "hooks" in the operating system -- basically the control data in the kernel used to augment or extend the features of an OS -- in order to hide out in the OS. This in turn lets the rootkit intercept and manipulate the system's data, remain invisible to the user and anti-malware tools, and to install other malware aimed at stealing data from the system. "Then the rootkit can hijack and manipulate the results seen by the user applications ... only allowing a user to see what it wants them to see," says Xuxian Jiang, assistant professor of computer science at NC State and a member of the research team. The link for this article located at Dark Reading is no longer available. . Uncover the innovative approach taken by scientists to create a solution employing hardware memory safeguards aimed at counteracting rootkit threats.. Rootkit Protection Tools, Hardware Memory Defense, Malware Detection System. . LinuxSecurity.com Team
A new tool too dangerous to give away can turn any PC. After silently inserting itself to run inside any browser The link for this article located at eWeek is no longer available. . An application surfaces that can stealthily transform any web browser with JavaScript support into a harmful agent, presenting considerable dangers.. JavaScript Threat, Malware Tool, Browser Security Issue, Cyber Attack Software. . LinuxSecurity.com Team
London . The link for this article located at SourceWire is no longer available. . Delve into an innovative solution that adeptly fights off malware dangers with accuracy and effectiveness.. Robot Code Cracker, Malware Defense, Cybersecurity Tool. . Bill Locke
Get the latest Linux and open source security news straight to your inbox.