Security News

Linux kernel impacted by new SLUBStick cross-cache attack
2024-08-03 15:17

A novel Linux Kernel cross-cache attack named SLUBStick has a 99% success in converting a limited heap vulnerability into an arbitrary memory read-and-write capability, letting the researchers...

North Korea-Linked Malware Targets Developers on Windows, Linux, and macOS
2024-07-31 13:08

The threat actors behind an ongoing malware campaign targeting software developers have demonstrated new malware and tactics, expanding their focus to include Windows, Linux, and macOS systems. DEV#POPPER is the moniker assigned to an active malware campaign that tricks software developers into downloading booby-trapped software hosted on GitHub under the guise of a job interview.

New Play ransomware Linux version targets VMware ESXi VMs
2024-07-22 17:01

Play ransomware is the latest ransomware gang to start deploying a dedicated locker for encrypting Linux devices and specifically targeting VMware ESXi virtual machines. [...]

New Linux Variant of Play Ransomware Targeting VMWare ESXi Systems
2024-07-22 03:56

Cybersecurity researchers have discovered a new Linux variant of a ransomware strain known as Play that's designed to target VMWare ESXi environments. Manufacturing, professional services, construction, IT, retail, financial services, transportation, media, legal services, and real estate are some of the top industries affected by the Play ransomware during the time period.

CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes
2024-07-21 23:51

CrowdStrike's now-infamous Falcon Sensor software, which last week led to widespread outages of Windows-powered computers, has also caused crashes of Linux machines. A second issue titled "System crashed at cshook network ops inet6 sockraw release+0x171a9" advised users "For assistance with troubleshooting potential issues with the falcon lsm serviceable kernel module provided from the CrowdStrike Falcon Sensor/Agent security software suite." Red Hat also advised that "Disabling the CrowdStrike Falcon Sensor/Agent software suite will mitigate the crashes and provide temporary stability to the system in question while the issue is investigated." The issue was "Observed but not limited to release 6 and 7.".

New Ransomware-as-a-Service 'Eldorado' Targets Windows and Linux Systems
2024-07-08 13:15

An emerging ransomware-as-a-service operation called Eldorado comes with locker variants to encrypt files on Windows and Linux systems. Eldorado first appeared on March 16, 2024, when an advertisement for the affiliate program was posted on the ransomware forum RAMP, Singapore-headquartered Group-IB said.

How to Manage User Passwords on Linux
2024-07-02 16:00

Those users log in via various means or protocols, such as SSH, FTP and HTTP. In order to successfully log in, those users have to have - passwords. You have to deal with users who create overly simple passwords, forget their passwords or forget to change those passwords with any regularity.

Nasty regreSSHion bug in OpenSSH puts roughly 700K Linux boxes at risk
2024-07-01 14:01

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

New regreSSHion OpenSSH RCE bug gives root on Linux servers
2024-07-01 13:37

A new OpenSSH unauthenticated remote code execution vulnerability dubbed "RegreSSHion" gives root privileges on glibc-based Linux systems. Exploitation of regreSSHion can have severe consequences for the targeted servers, potentially leading to complete system takeover.

New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems
2024-07-01 10:50

OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems....