While relevant Intel and AMD processors have been mitigated for the recent Retbleed security vulnerability affecting older generations of processors, those mitigations currently just work for x86_64 kernels and will not work if running an x86 (32-bit) kernel on affected hardware. But it's unlikely to get fixed unless some passionate individual steps up as the upstream developers and vendors have long since moved on to just caring about x86_64. . Last week following the flurry of Linux patches for mitigating this newest speculative execution attack, it was pointed out that Linux x86 32-bit kernels are still vulnerable to Retbleed. It turns out Linaro still has a 32-bit Debian box in their functional test farm and they The link for this article located at Phoronix is no longer available. . The latest updates address Retbleed vulnerabilities for x86_64 architectures; however, 32-bit x86 systems still face exposure with no resolution currently available.. Retbleed Vulnerability, x86 32-Bit Vulnerability, Linux Kernel Security. . Brittany Day
A new Linux botnet, B1txor20, that targets Arm and 64-bit x86 systems shows log4j isn't going away any time soon. . We’re months into the disclosure of the log4j vulnerability and new attacks are still popping up. Cybersecurity researchers from Qihoo 360, a Chinese cybersecurity company, have just discovered a new Linux botnet, taking advantage of the flaw to distribute rootkits and steal sensitive data. They named the botnet B1txor20, and claim it uses the log4j vulnerability to target Linux Arm and 64-bit x86 systems. "In addition to traditional backdoor functions, B1txor20 also has functions such as opening a Socket5 proxy and remotely downloading and installing a rootkit," the researchers said. . An emerging Linux botnet, B1texploit21, exploits vulnerabilities in log4j to compromise both Arm and x86 architectures, disseminating malware and exfiltrating sensitive information.. Linux Botnet, Log4j Exploits, Cybersecurity Threats, Rootkit Attack, B1txor20 Malware. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.