Security News > 2021

PHP Infiltrated with Backdoor Malware
2021-03-29 15:42

The PHP project on Sunday announced that attackers were able to gain access to its main Git server, uploading two malicious commits, including a backdoor. "Had it not been detected, the code could have ultimately poisoned the binary package repositories which countless organizations rely upon and trust. Open-source projects which are self-hosting their code repositories may be at increased risk of this type of supply-chain attack and must have robust processes in place to detect and reject suspicious commits."

Linux 101: How to give users sudo privileges on Ubuntu and Red Hat-based Linux distributions
2021-03-29 14:49

New Linux admins need to know how to give and take sudo privileges from users. You might come into a situation when you need to "Promote" one of those users to admin and give them sudo privileges.

More Ransomware Gangs Targeting Vulnerable Exchange Servers
2021-03-29 14:48

The Black Kingdom/Pydomer ransomware operators have joined the ranks of threat actors targeting the Exchange Server vulnerabilities that Microsoft disclosed in early March. "As of today, we have seen a significant decrease in the number of still-vulnerable servers - more than 92% of known worldwide Exchange IPs are now patched or mitigated. We continue to work with our customers and partners to mitigate the vulnerabilities," Microsoft noted in a March 25 blog post.

'Hades' Ransomware Hits Big Firms, but Operators Slow to Respond to Victims
2021-03-29 14:03

Researchers from CrowdStrike, Accenture, and Awake Security have dissected some of the attacks involving the Hades ransomware and published information on both the malware itself and the tactics, techniques and procedures employed by its operators. The Hades ransomware operators targeted a few industries only, including transportation and logistics, consumer products, and manufacturing and distribution - a logistics provider and organizations in the automotive supply chain and manufacturing of insulation products are known victims.

UK terror law reviewer calls for expanded police powers to imprison people who refuse to hand over passwords
2021-03-29 14:01

The UK's Government Reviewer of Terrorism Laws is again advising the removal of legal safeguards around a controversial law that allows people to be jailed if they refuse police demands for forced decryption of their devices. In what appears to be a recurring theme, Jonathan Hall QC said police should be able to threaten people arrested under terror laws with five years in prison if they don't hand over passwords on demand.

UK terror law reviewer calls for prison sentences if suspects refuse to hand passwords over to investigators
2021-03-29 14:01

The UK's Government Reviewer of Terrorism Laws is again advising the removal of legal safeguards around a controversial law that allows people to be jailed if they refuse police demands for forced decryption of their devices. In what appears to be a recurring theme, Jonathan Hall QC said police should be able to threaten people arrested under terror laws with five years in prison if they don't hand over passwords on demand.

Backdoor Disguised as Typo Fix Added to PHP Source Code
2021-03-29 13:05

The developers of the PHP scripting language revealed on Sunday that they had identified what appeared to be malicious code in the php-src repository hosted on the git. The unauthorized code was disguised as two typo fix-related commits apparently pushed by Rasmus Lerdorf, author of the PHP language, and Nikita Popov, an important PHP contributor.

AP Sources: SolarWinds Hack Got Emails of Top DHS Officials
2021-03-29 12:41

"The SolarWinds hack was a victory for our foreign adversaries, and a failure for DHS," said Sen. Rob Portman of Ohio, top Republican on the Senate's Homeland Security and Governmental Affairs Committee. An inquiry by the AP found new details about the breach at DHS and other agencies, including the Energy Department, where hackers accessed top officials' private schedules.

Scottish National Party members found among list of names signed up to rival Alba Party after website whoopsie
2021-03-29 12:32

Alex Salmond's Alba Party has got off to a rocky start after a coding error on its website appeared to expose the names of those signed up. First reported by Scotland's The Herald On Sunday, the names of more than 4,000 people who had signed up to attend events were inadvertently made public.

PHP repository moved to GitHub after malicious code inserted under creator Rasmus Lerdorf's name
2021-03-29 11:46

The main code repository for PHP, which powers nearly 80 per cent of the internet, was breached to add malicious code and is now being moved to GitHub as a precaution. "Yesterday two malicious commits were pushed to the php-src repo from the names of Rasmus Lerdorf and myself. We don't yet know how exactly this happened, but everything points towards a compromise of the git.php.net server," said PHP maintainer Nikita Popov, who works with the PHP team at JetBrains.