Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security researchers have discovered a new self-spreading Golang-based malware that has been actively dropping XMRig cryptocurrency miners on both Windows and Linux servers since early December. . This multi-platform malware also has worm capabilities that allow it to spread to other systems by brute-forcing public-facing services (i.e., MySQL, Tomcat, Jenkins and WebLogic) with weak passwords as revealed by Intezer security researcher Avigayil Mechtinger. The attackers behind this campaign have been actively updating the worm's capabilities through its command-and-control (C2) server since it was first spotted which hints at an actively maintained malware. . A cross-platform malware takes advantage of poor password security to deploy Monero mining software on both Linux and Windows systems.. Monero Miner,Golang Malware,Linux Security Threats,Cryptocurrency Worm,Server Protection. . LinuxSecurity.com Team
The newly discovered Gitpaste-12 worm exploits GitHub and Pastebin to house component code, and harbors 12 different initial attack vectors. . Researchers have uncovered a new worm targeting Linux based x86 servers, as well as Linux internet of things (IoT) devices (that are based on ARM and MIPS CPUs). Of note, the malware utilizes GitHub and Pastebin for housing malicious component code, and has at least 12 different attack modules available – leading researchers to call it “Gitpaste-12.” It was first detected by Juniper Threat Labs in attacks on Oct. 15, 2020. “No malware is good to have, but worms are particularly annoying,” said researchers with Juniper Threat Labs in a Thursday post. “Their ability to spread in an automated fashion can lead to lateral spread within an organization or to your hosts attempting to infect other networks across the internet, resulting in poor reputation for your organization.” . Scientists discovered a novel Gitpaste-12 malware aimed at Linux systems and IoT gadgets, employing various strategies to infiltrate.. Gitpaste-12, Linux Worm, IoT Malware, GitHub Exploits. . LinuxSecurity.com Team
An outbreak of a worm on Tumblr, the microblogging platform, hit many accounts by taking advantage of the platform's reblogging capability. The payload of the worm was the publication of a posting angrily explaining how the worm's authors hated Tumblr users, was analysed by Sophos which noted that the malicious code was embedded mostly as a Base64-encoded string hidden within a data URI. . Once decoded and executed, it would pull code and content from another website. The link for this article located at H Security is no longer available. . Instagram profiles targeted by malware exploiting share function; contents uncovered as Base64-encoded virus for harmful activities.. Tumblr Worm Attack, Malicious Payload, Trojan Code, Microblogging Security. . LinuxSecurity.com Team
It. F-Secure is reporting that the worm is behind a spike in traffic on Port 3389/TCP. Once it The link for this article located at The Register UK is no longer available. . A report from Trend Micro highlights a malware strain generating high volume traffic on Port 80/TCP, suggesting significant risks for web servers.. RDP Threat, Malware Spread, Network Traffic. . LinuxSecurity.com Team
Mogeneration, an Australian software company, has hired the author of the first iPhone worm, Ashley Towns, to develop applications for the iPhone App Store. At the beginning of November, 21 year old Towns circulated the "Ikee" worm via Australian operator Optus's UMTS network. The worm penetrates vulnerable jailbroken iPhones and spreads using open SSH connections. . Once logged into a phone, the worm copies itself onto the device, deletes the SSH service and changes the wallpaper to a photo of Rick Astley with the caption "ikee is never going to give you up". It then starts searching for further iPhones to infect. Towns announced the news of his hiring via his, now no longer public, Twitter account. Graham Cluley, a Senior Technology Consultant for Sophos, complained in a post on his blog that Towns "has not had his collar felt by the long arm of the law", that he was showing "no regret for what he did" and was actually being rewarded for his act. The link for this article located at H Security is no longer available. . Once logged into a phone, the worm copies itself onto the device, deletes the SSH service and change. mogeneration, australian, software, company, hired, author, first, iphone, ashley. . LinuxSecurity.com Team
The Internet prank known as "Rickrolling" has made its way to iPhones in the form of a worm that infects jailbroken versions of the device. The worm is more annoying than harmful -- it even appears to lock the door behind it, preventing similar attacks from slipping in. However, security pros are concerned that a hacker with malicious intentions may exploit the vulnerability the worm highlights.. The Ikee worm exploits the SSH, or secure shell, protocol on jailbroken iPhones. SSH is a network protocol that lets two networked devices exchange data using a secure channel. It is primarily used on Linux- and Unix-based systems to access shell accounts. "The problem is, iPhone users don't think of their devices as being Unix computers," Chester Wisniewski, a senior security adviser at security company Sophos, told MacNewsWorld. "But that's just what it is." The link for this article located at MacNewsWorld is no longer available. . The Xcode malware impacts macOS devices through XcodeGhost, highlighting vulnerabilities even if it appears harmless.. Ikee Worm, SSH Exploit, Jailbroken iPhones, Malware Threat. . LinuxSecurity.com Team
A worm targeting Skype's VoIP application is harvesting e-mail addresses and directing users to a range of sites hosting other malicious software, security vendors said Monday. Once a machine is infected, the worm sends a malicious link via instant messages to other users in person's Skype contact list, according to F-Secure's blog. . The link leads to an executable file that downloads a Trojan horse capable of downloading other malicious software, F-Secure said. It then shows a photo of a "lightly dressed" woman. The link also directs users to at least eight Web sites with information about Africa. It's not clear what type of scam or harm those pages intend, but some of the sites have advertising on them, indicating that it might be a click-fraud scam, said Graham Cluley, senior technology consultant for Sophos. Click fraud refers to the various tricks used to get clicks on advertising banners, which generate revenue for Web page owners. The link for this article located at NetworkWorld is no longer available. . The link leads to an executable file that downloads a Trojan horse capable of downloading other mali. targeting, skype's, application, harvesting, e-mail, addresses, directing, users. . LinuxSecurity.com Team
A worm is targeting MySpace users, compromising their "About me" pages and infecting visitors to them, Symantec has warned. . When a logged-in MySpace user goes to another member's "About me" page affected by the ACTS.Spaceflash worm, they are quietly redirected to a URL that holds a malicious Macromedia Flash file, the security company said in an advisory on Spaceflash Tuesday. That file, in turn, will replace the visitor's own "About me" page with one that is compromised. "It's an annoyance, at this point, for users, but the capability exists where it can lead to malicious actions and steal sensitive information," said Dean Turner, senior manager of Symantec, which currently rates the Spaceflash threat as low. The link for this article located at ZDNet is no longer available. . When a logged-in MySpace user goes to another member's 'About me' page affected by the ACTS.Spacefla. targeting, myspace, users, compromising, their, 'about, pages, infecting, visitors. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.