Tag: linux
-
Red Heron nutzt kritische Gitea-Lücke für internationale Cyberangriffe
Die Acronis Threat Research Unit hat eine internationale Angriffskampagne auf öffentlich erreichbare Gitea-Server aufgedeckt. Die Gruppe Red Heron automatisierte die Ausnutzung einer kritischen Schwachstelle, um Quellcode, Zugangsdaten und interne Konfigurationen zu stehlen. Im Visier standen unter anderem Organisationen aus dem Energie- und Industriesektor sowie Systeme mit Bezug zu Wahlen. Ein neu entdecktes Linux-Rootkit ermöglichte den…
-
RDP, Sound und mehr: Windows-Updates bereiten Nutzern allerhand Probleme
Laut Microsoft lösen die neuen Windows-Updates Probleme mit Linux-VMs, USB-Audio und RDP-Verbindungen aus. Doch da scheint noch mehr kaputt zu sein. First seen on golem.de Jump to article: www.golem.de/news/rdp-sound-und-mehr-windows-updates-bereiten-nutzern-allerhand-probleme-2609-212982.html
-
Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/13/week-in-review-linux-rootkit-deployed-on-f5-big-ip-apm-devices-cisco-fmc-bugs-exploited/
-
Microsoft, Red Hat, Linux und Ajax.NET – Fünf alte Sicherheitslücken werden aktiv ausgenutzt
First seen on security-insider.de Jump to article: www.security-insider.de/cisa-kev-alte-schwachstellen-red-hat-sql-linux-kernel-a-e9e77ee9249d771d100a0f215a073ada/
-
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments…
-
New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed…
-
12 Best Server Security Solutions Compared (2026): Features Pricing
Quick Answer: CrowdStrike and SentinelOne lead server EDR; Trend Micro Deep Security owns virtual patching for unpatchable estates; Microsoft Defender for Servers is the per-resource anchor for Azure/hybrid; Bitdefender and ESET deliver efficacy at value. Server pricing runs per server/workload always confirm Linux feature parity. Servers are where ransomware crews head after the first phish:…
-
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server…
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/
-
Xopero erweitert <> und <> mit Image-basiertes Linux-Backup, FIPS-konforme Verschlüsselung und Active-Directory-Integration
Der Backup-Experte Xopero hat eine neue Version von <> und <> vorgestellt. Ab der Version 2.4.0 ermöglicht Xopero-ONE-vollständige, imagebasierte Backups von Linux-Systemen. Bei Windows-Umgebungen ist die Unterstützung der AES-Verschlüsselung gemäß den strengen US-FIPS-Standards das wichtigste neue Feature. Die Active-Directory-Integration via LDAP erleichtert nun die Aufgaben von Backup-Administratoren, unabhängig von den geschützten Workloads. Die Lösung […]…
-
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
Tags: access, backdoor, cve, cyber, exploit, flaw, linux, malware, remote-code-execution, vulnerabilityA sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation of CVE-2025-53521, an unauthenticated remote code execution flaw affecting BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the vulnerability and links the related compromise activity…
-
Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks
A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash…
-
DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations
A previously undocumented Linux espionage toolkit linked with medium confidence to DPRK-aligned threat actors has been used to compromise South Korean organizations in the automotive and media sectors. The campaign is notable because it does not exploit a flaw in HAProxy itself. Instead, the operators appear to have obtained code execution on targeted edge servers…
-
New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires…
-
Buffer Overflow – Linux patcht Speicherfehler im IPv6-Netzwerk-Stack
Tags: linuxFirst seen on security-insider.de Jump to article: www.security-insider.de/linux-kernel-ipv6-buffer-overflow-udpv6-cve-2026-53362-a-17c813177c5503df28f947c80ec73e7a/
-
Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning
A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct large-scale SEO poisoning and online-gambling fraud. The operation has been active since mid-2025 and represents a notable shift in Brazil’s threat landscape. Rather than deploying the country’s more familiar banking malware, the attackers are…
-
Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection
Security researcher has disclosed a technique used by the Singularity Linux rootkit to evade Elastic Defend by suppressing module-load telemetry to avoid detection across multiple layers. This research highlights how trusted-process exclusions in endpoint eBPF monitoring can become significant targets for advanced kernel-level threats. According to the report, Elastic Defend has monitored Linux kernel module…
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
ey Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor firstdocumentedtargeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, and familiar offensive utilities.…
-
Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled…
-
AI Helps Drive Number of Linux Kernel CVEs to Near 2,000 Per Release
The number of CVEs per Linux kernel release, which for years came in around 500, now is closing in on 2,000 due in large part to AI-armed vulnerability hunters, and that will only get higher, security pros say. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-helps-drive-number-of-linux-kernel-cves-to-near-2000-per-release/
-
Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs
Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remote access trojans: NodeRabbit and PollCat. The campaign uses recruiter impersonation on LinkedIn and other job-search platforms, weaponized Node.js projects, and cloud-hosted ZIP archives to gain covert access to developer endpoints across Windows, Linux, and macOS.…
-
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.Russian cybersecurity company Kaspersky is tracking the First seen…
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks
Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten victim organizations, while deploying a purpose-built Linux encryptor designed to disrupt VMware ESXi environments. The findings show how ransomware affiliates are integrating agentic AI into established post-compromise workflows rather than relying on it as a…
-
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor First seen…
-
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: CVE-2023-49105 (CVSS score of 9.8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality. An unauthenticated attacker who…
-
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, microsoft, sql, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let…
-
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/

