Security Leftovers

-
Security updates for Monday
Security updates have been issued by Arch Linux (home-assistant, libgcrypt, libvirt, and mutt), Debian (ffmpeg, kernel, libonig, libsdl2, mariadb-10.1, and thunderbird), Fedora (chromium, firefox, jasper, libebml, mingw-python3, netpbm, opensmtpd, thunderbird, and xen), Gentoo (firefox and thunderbird), Mageia (db53, dnsmasq, kernel, kernel-linus, and php-pear), openSUSE (go1.14, go1.15, messagelib, nodejs8, segv_handler, and thunderbird), Oracle (firefox, kernel, and thunderbird), Red Hat (flatpak), SUSE (firefox and rubygem-nokogiri), and Ubuntu (mysql-5.7, mysql-8.0 and python-django).
-
Libgcrypt developers release urgent update to tackle severe vulnerability [Ed: Almost nobody used that version regardless, but the media doesn't mention that]
-
Critical Libgcrypt Crypto Bug Opens Machines to Arbitrary Code
The flaw in the free-source library could have been ported to multiple applications.
The Libgcrypt project has rushed out a fix for a critical bug in version 1.9.0 of the free-source cryptographic library. An exploit would allow an attacker to write arbitrary data to a target machine and execute code.
The security vulnerability is a heap-buffer overflow bug in Libgcrypt 1.9.0 (released on January 19 – previous versions are not affected), which researchers said can be exploited by merely decrypting a block of data. The issue is patched (CVE pending) in Libgcrypt version 1.9.1.
-
New Cryptojacking Malware Targeting Apache, Oracle, Redis Servers
A financially-motivated threat actor notorious for its cryptojacking attacks has leveraged a revised version of their malware to target cloud infrastructures using vulnerabilities in web server technologies, according to new research.
Deployed by the China-based cybercrime group Rocke, the Pro-Ocean cryptojacking malware now comes with improved rootkit and worm capabilities, as well as harbors new evasion tactics to sidestep cybersecurity companies' detection methods, Palo Alto Networks' Unit 42 researchers said in a Thursday write-up.
-
ESET discovers Kobalos: tiny yet complex Linux threat attacking supercomputers – PCR [Ed: With Windows, in order to get it infected, all you need to do it have it installed (NSA backdoors) and connected to the Internet, whereas with BSD a and GNU/Linux you typically need to install the malware]
ESET researchers are reported to have discovered Kobalos, a malware that has been attacking supercomputers – high performance computer (HPC) clusters. ESET has worked with the CERN Computer Security Team and other organisations involved in mitigating attacks on these scientific research networks. Among other targets was a large Asian ISP, a North American endpoint security vendor as well as several privately held servers.
-

- Login or register to post comments
Printer-friendly version- 5169 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

ESET/PCR FUD?
Report: Security Firm Says HPC Clusters under Attack: ‘Level of Sophistication Rarely Seen in Linux Malware’ [Ed: Neglects to say how such malware gets onto systems in the first place and who's to blame for that]
More of ESET
ESET team finds new supply-chain attack targeting gaming community
ZDNet Joins the FUD
This Linux malware is hijacking supercomputers across the globe
Linux Malware Kobalos Backdoors Supercomputers
Linux Malware Kobalos Backdoors Supercomputers [Ed: Does not say how or why this actually gets installed on computers]
More FUD
New Linux malware steals SSH credentials from supercomputers [Ed: Anti-Linux sites like saying "Linux" in "malware" in the same headline without even noting how malware got there in the first place]
Linux malware Kobalos steals credentials using hacked OpenSSH...
Linux malware Kobalos steals credentials using hacked OpenSSH software
The stigma
High-performance computing malware targeting Linux, Solaris and possibly Microsoft | SC Media
Original FUD
Kobalos – A complex Linux threat to high performance computing infrastructure [Ed: It is not at all a "Linux" thing and they don't say what gets it there]
A New Linux Malware Targeting High-Performance Computing Cluster
A New Linux Malware Targeting High-Performance Computing Clusters [Ed: It is not "Linux malware" but some malware that somehow finds its way into systems that only sometimes happen to run GNU/Linux (because it dominates this space completely)]
More of this FUD
New Linux Malware Targets Supercomputers' SSH Credentials from North America, Asia, and Europe!
'Kobalos' Linux Malware Targets Supercomputers Worldwide
This devious Linux malware is targeting supercomputers
This devious Linux malware is targeting supercomputers