home.social

#linux-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #linux-security, aggregated by home.social.

fetched live
  1. How to Stay Protected

    XMRig Malware Campaigns Target Businesses

    Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.

    In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.

    What Is XMRig?

    XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.

    By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.

    Why Are Businesses Being Targeted?

    Corporate environments provide an attractive opportunity for attackers because they often contain:

    • High-performance desktop computers
    • Powerful servers
    • Multiple workstations
    • Cloud infrastructure
    • Continuous internet connectivity

    Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.

    The result is free cryptocurrency mining at the company’s expense.

    How XMRig Malware Gets Installed

    Most unauthorised XMRig installations begin after another security weakness has already been exploited.

    Common infection methods include:

    • Phishing emails containing malicious attachments
    • Fake software downloads
    • Exploitation of unpatched vulnerabilities
    • Weak Remote Desktop Protocol (RDP) passwords
    • Stolen administrator credentials
    • Trojan malware that downloads additional payloads

    Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.

    Warning Signs of an XMRig Infection

    Many organisations discover mining malware only after performance problems become noticeable.

    Common symptoms include:

    • Constantly high CPU usage
    • Increased electricity consumption
    • Slow computers
    • Loud cooling fans
    • Servers running hotter than normal
    • Unknown scheduled tasks
    • Unexpected outbound network traffic
    • Security software being disabled

    Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.

    Business Impact

    Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.

    Potential consequences include:

    Reduced Productivity

    Employees experience slower computers, affecting daily work.

    Higher Operating Costs

    Mining consumes CPU resources and electricity around the clock.

    Hardware Wear

    Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.

    Security Risks

    An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.

    How Organisations Can Protect Themselves

    Preventing cryptojacking requires multiple layers of security.

    Keep Systems Updated

    Install security updates for Windows, Linux, browsers, and all business software as soon as practical.

    Use Endpoint Protection

    Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.

    Enable Multi-Factor Authentication

    Protect administrator accounts and remote access services with MFA wherever possible.

    Monitor CPU Usage

    Investigate unexplained spikes in processor utilisation, especially outside business hours.

    Restrict Administrative Privileges

    Limit local administrator permissions to reduce the impact of compromised accounts.

    Educate Employees

    Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.

    Is XMRig Dangerous?

    The software itself is completely legitimate.

    The danger comes from unauthorised installation and misuse by attackers.

    Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.

    Best Practices for IT Teams

    Organisations should adopt a proactive security strategy by:

    • Regularly auditing endpoints
    • Monitoring unusual network connections
    • Reviewing scheduled tasks and startup entries
    • Enforcing least-privilege access
    • Conducting vulnerability scans
    • Backing up critical business data
    • Implementing continuous security monitoring

    Early detection significantly reduces the financial and operational impact of mining malware.

    Final Thoughts

    Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.

    Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.

    By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.

    Frequently Asked Questions

    Is XMRig malware?

    No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.

    What cryptocurrency does XMRig mine?

    It is primarily designed to mine Monero (XMR) using the RandomX algorithm.

    Can antivirus detect XMRig?

    Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.

    How can I tell if my computer is mining cryptocurrency?

    Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.

    #Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner
  2. How to Stay Protected

    XMRig Malware Campaigns Target Businesses

    Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.

    In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.

    What Is XMRig?

    XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.

    By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.

    Why Are Businesses Being Targeted?

    Corporate environments provide an attractive opportunity for attackers because they often contain:

    • High-performance desktop computers
    • Powerful servers
    • Multiple workstations
    • Cloud infrastructure
    • Continuous internet connectivity

    Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.

    The result is free cryptocurrency mining at the company’s expense.

    How XMRig Malware Gets Installed

    Most unauthorised XMRig installations begin after another security weakness has already been exploited.

    Common infection methods include:

    • Phishing emails containing malicious attachments
    • Fake software downloads
    • Exploitation of unpatched vulnerabilities
    • Weak Remote Desktop Protocol (RDP) passwords
    • Stolen administrator credentials
    • Trojan malware that downloads additional payloads

    Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.

    Warning Signs of an XMRig Infection

    Many organisations discover mining malware only after performance problems become noticeable.

    Common symptoms include:

    • Constantly high CPU usage
    • Increased electricity consumption
    • Slow computers
    • Loud cooling fans
    • Servers running hotter than normal
    • Unknown scheduled tasks
    • Unexpected outbound network traffic
    • Security software being disabled

    Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.

    Business Impact

    Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.

    Potential consequences include:

    Reduced Productivity

    Employees experience slower computers, affecting daily work.

    Higher Operating Costs

    Mining consumes CPU resources and electricity around the clock.

    Hardware Wear

    Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.

    Security Risks

    An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.

    How Organisations Can Protect Themselves

    Preventing cryptojacking requires multiple layers of security.

    Keep Systems Updated

    Install security updates for Windows, Linux, browsers, and all business software as soon as practical.

    Use Endpoint Protection

    Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.

    Enable Multi-Factor Authentication

    Protect administrator accounts and remote access services with MFA wherever possible.

    Monitor CPU Usage

    Investigate unexplained spikes in processor utilisation, especially outside business hours.

    Restrict Administrative Privileges

    Limit local administrator permissions to reduce the impact of compromised accounts.

    Educate Employees

    Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.

    Is XMRig Dangerous?

    The software itself is completely legitimate.

    The danger comes from unauthorised installation and misuse by attackers.

    Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.

    Best Practices for IT Teams

    Organisations should adopt a proactive security strategy by:

    • Regularly auditing endpoints
    • Monitoring unusual network connections
    • Reviewing scheduled tasks and startup entries
    • Enforcing least-privilege access
    • Conducting vulnerability scans
    • Backing up critical business data
    • Implementing continuous security monitoring

    Early detection significantly reduces the financial and operational impact of mining malware.

    Final Thoughts

    Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.

    Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.

    By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.

    Frequently Asked Questions

    Is XMRig malware?

    No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.

    What cryptocurrency does XMRig mine?

    It is primarily designed to mine Monero (XMR) using the RandomX algorithm.

    Can antivirus detect XMRig?

    Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.

    How can I tell if my computer is mining cryptocurrency?

    Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.

    #Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner
  3. CTRL-OS 26.05 is out: a downstream NixOS/Nixpkgs distro with 5 years of commercial support.

    We stay aligned with upstream and contribute security work back to nixpkgs. Fixes for packages like glibc trigger mass rebuilds, which the community batches to preserve CI capacity. For security-sensitive deployments we backport ahead of that in our own public repo, to meet our SLAs.

    cyberus-technology.de/post/ann

    #NixOS #LinuxSecurity

  4. La sicurezza del tuo clipboard è fondamentale. Scopri come la nuova funzione Paste Protect di Opera One blocca automaticamente le iniezioni di codice pericoloso mentre navighi. #OperaBrowser #CyberSecurity #LinuxSecurity #Privacy #WebSafety

    linuxeasy.org/opera-presenta-p

  5. La sicurezza del tuo clipboard è fondamentale. Scopri come la nuova funzione Paste Protect di Opera One blocca automaticamente le iniezioni di codice pericoloso mentre navighi. #OperaBrowser #CyberSecurity #LinuxSecurity #Privacy #WebSafety

    linuxeasy.org/opera-presenta-p

  6. 🐞🌐 Ladybird Browser face pași uriași: Adaugă gestionarea descărcărilor, istoric extins și Sandboxing nativ pe Linux 🚀🛡️

    Proiectul Ladybird, browserul web independent care a captat atenția întregii lumi tech prin refuzul de a folosi motoare existente (precum Chromium/Blink sau Firefox/Gecko), continuă să se transforme într-un produs de zi cu zi extrem de capabil. În cea mai recentă actualizare, echipa de dezvoltare a anunțat adăugarea unor funcții vitale de utilizare: un panou de Downloads, o pagină dedicată pentru Istoric (History) și, cel mai important din punct de vedere tehnic, o arhitectură de Sandboxing nativă pentru Linux.

    Născut inițial ca un simplu vizualizator HTML pentru sistemul de operare retro SerenityOS, Ladybird este acum un proiect cross-platform matur, scris de la zero în C++, care pune un accent obsesiv pe performanță, standarde web curate și confidențialitate.

    Iată principalele noutăți implementate în această versiune:

    🔹 Securitate de top prin Sandboxing pe Linux:
    Până acum, mecanismele avansate de izolare a proceselor din Ladybird funcționau excelent pe macOS (folosind sandbox_init). Noua actualizare aduce în sfârșit paritatea de securitate și pentru utilizatorii de Linux.

    Browserul utilizează acum tehnologiile native din kernelul Linux, precum Namespaces (izolarea rețelei și a proceselor) și Landlock (un modul de securitate LSM modern care restricționează drastic accesul la sistemul de fișiere).

    Ce înseamnă asta? Dacă o pagină web malițioasă reușește să exploateze o breșă în motorul de randare, atacul va fi complet izolat în interiorul acelui tab și nu va putea accesa fișierele tale personale de pe computer.

    🔹 Gestionar de descărcări (Downloads Manager):
    O funcție de bază, dar absolut esențială pentru un browser modern. Ladybird include acum o interfață dedicată pentru monitorizarea descărcărilor de fișiere. Utilizatorii pot vedea progresul în timp real, viteza de download, pot pune pe pauză sau anula procesul și pot deschide direct folderul destinație dintr-un simplu click.

    🔹 Istoric de navigare complet (History View):
    A fost implementată componenta de management a istoricului. Pagina îți permite acum să cauți rapid prin site-urile vizitate anterior, să le sortezi în funcție de dată și să ștergi selectiv anumite intrări sau întregul istoric de navigare, sporind controlul asupra urmelor digitale.

    🔹 Rafinarea motorului de randare propriu (LibWeb & LibJS):
    Dezvoltatorii continuă să bifeze procente uriașe în testele de compatibilitate cu standardele web oficiale (W3C). Au fost corectate bug-uri legate de interpretarea codului JavaScript complex și au fost aduse îmbunătățiri în randarea layout-urilor CSS moderne (Flexbox și Grid), făcând ca din ce în ce mai multe site-uri complexe să se încarce impecabil.

    💡 De ce contează Ladybird? Într-o industrie web dominată aproape în totalitate de monopolul Google Chromium (pe care se bazează Chrome, Edge, Brave, Opera și Vivaldi), Ladybird reprezintă una dintre puținele speranțe pentru un web liber și diversificat, demonstrând că o comunitate pasionată poate construi o alternativă reală de la zero.

    Proiectul este complet open-source, nu include reclame, nu colectează telemetrie și este finanțat exclusiv din donații și sponsorizări (inclusiv un suport masiv din partea unor figuri proeminente din tech).

    #LadybirdBrowser #Ladybird #WebBrowser #LinuxSecurity #Sandboxing #Landlock #OpenSource #BrowserIndependent #TechNews

  7. 🐞🌐 Ladybird Browser face pași uriași: Adaugă gestionarea descărcărilor, istoric extins și Sandboxing nativ pe Linux 🚀🛡️

    Proiectul Ladybird, browserul web independent care a captat atenția întregii lumi tech prin refuzul de a folosi motoare existente (precum Chromium/Blink sau Firefox/Gecko), continuă să se transforme într-un produs de zi cu zi extrem de capabil. În cea mai recentă actualizare, echipa de dezvoltare a anunțat adăugarea unor funcții vitale de utilizare: un panou de Downloads, o pagină dedicată pentru Istoric (History) și, cel mai important din punct de vedere tehnic, o arhitectură de Sandboxing nativă pentru Linux.

    Născut inițial ca un simplu vizualizator HTML pentru sistemul de operare retro SerenityOS, Ladybird este acum un proiect cross-platform matur, scris de la zero în C++, care pune un accent obsesiv pe performanță, standarde web curate și confidențialitate.

    Iată principalele noutăți implementate în această versiune:

    🔹 Securitate de top prin Sandboxing pe Linux:
    Până acum, mecanismele avansate de izolare a proceselor din Ladybird funcționau excelent pe macOS (folosind sandbox_init). Noua actualizare aduce în sfârșit paritatea de securitate și pentru utilizatorii de Linux.

    Browserul utilizează acum tehnologiile native din kernelul Linux, precum Namespaces (izolarea rețelei și a proceselor) și Landlock (un modul de securitate LSM modern care restricționează drastic accesul la sistemul de fișiere).

    Ce înseamnă asta? Dacă o pagină web malițioasă reușește să exploateze o breșă în motorul de randare, atacul va fi complet izolat în interiorul acelui tab și nu va putea accesa fișierele tale personale de pe computer.

    🔹 Gestionar de descărcări (Downloads Manager):
    O funcție de bază, dar absolut esențială pentru un browser modern. Ladybird include acum o interfață dedicată pentru monitorizarea descărcărilor de fișiere. Utilizatorii pot vedea progresul în timp real, viteza de download, pot pune pe pauză sau anula procesul și pot deschide direct folderul destinație dintr-un simplu click.

    🔹 Istoric de navigare complet (History View):
    A fost implementată componenta de management a istoricului. Pagina îți permite acum să cauți rapid prin site-urile vizitate anterior, să le sortezi în funcție de dată și să ștergi selectiv anumite intrări sau întregul istoric de navigare, sporind controlul asupra urmelor digitale.

    🔹 Rafinarea motorului de randare propriu (LibWeb & LibJS):
    Dezvoltatorii continuă să bifeze procente uriașe în testele de compatibilitate cu standardele web oficiale (W3C). Au fost corectate bug-uri legate de interpretarea codului JavaScript complex și au fost aduse îmbunătățiri în randarea layout-urilor CSS moderne (Flexbox și Grid), făcând ca din ce în ce mai multe site-uri complexe să se încarce impecabil.

    💡 De ce contează Ladybird? Într-o industrie web dominată aproape în totalitate de monopolul Google Chromium (pe care se bazează Chrome, Edge, Brave, Opera și Vivaldi), Ladybird reprezintă una dintre puținele speranțe pentru un web liber și diversificat, demonstrând că o comunitate pasionată poate construi o alternativă reală de la zero.

    Proiectul este complet open-source, nu include reclame, nu colectează telemetrie și este finanțat exclusiv din donații și sponsorizări (inclusiv un suport masiv din partea unor figuri proeminente din tech).

    #LadybirdBrowser #Ladybird #WebBrowser #LinuxSecurity #Sandboxing #Landlock #OpenSource #BrowserIndependent #TechNews

  8. Unlocking Fully Encrypted Servers over Tor

    Remote servers should not have to choose between security and availability.

    For years, the common compromise has been to expose SSH to the public Internet or to rely on VPNs and provider-specific KVM consoles whenever a LUKS-encrypted server reboots.

    I believe there is a better approach.

    By combining LUKS, Tor Onion Services, and a lightweight SSH server running directly inside the initramfs, it is possible to build servers that remain fully encrypted at rest, yet can always be unlocked remotely without exposing any public management interface.

    This article describes the concept and how it could evolve into a reusable feature for Infinito.Nexus.

    The Problem

    Full disk encryption protects data when a server is powered off.

    However, after every reboot someone must enter the LUKS passphrase.

    For remote dedicated servers this usually means one of the following:

    • opening SSH to the Internet
    • connecting through a VPN
    • using a provider’s KVM/IPMI console
    • booting into a rescue system

    While remote unlocking via Dropbear inside the initramfs is already a well-known solution, it still typically relies on a publicly reachable IP address.

    The Idea

    Instead of exposing SSH publicly, start Tor directly inside the initramfs.

    The boot sequence would look like this:

    Server boots


    Kernel + initramfs


    Network initialization


    Tor starts


    Temporary Onion Service appears

    unlock-xxxxxxxx.onion


    SSH via Tor


    cryptsetup luksOpen


    Root filesystem unlocked


    Operating system boots


    Temporary Onion Service disappears

    The administrator simply connects through Tor:

    torsocks ssh [email protected]

    After entering the LUKS passphrase, the operating system continues booting normally.

    Separate Identities for Boot and Runtime

    One of the strongest aspects of this design is that boot-time and runtime use different Onion identities.

    Boot environment

    • dedicated Ed25519 key
    • dedicated Onion address
    • only SSH
    • exists only during boot

    Example:

    unlock-xxxxxxxx.onion

    Runtime environment

    Once the operating system has booted:

    • the initramfs exits
    • Tor inside initramfs stops
    • a new Tor instance starts
    • completely different Onion addresses become available

    For example:

    ssh-xxxxxxxx.onion
    cloud-xxxxxxxx.onion
    matrix-xxxxxxxx.onion
    mail-xxxxxxxx.onion

    The unlock address simply disappears.

    This cleanly separates the trust boundaries between the bootloader environment and the running operating system.

    Why Tor?

    Using Tor instead of exposing SSH directly provides several advantages:

    • no public IP address required
    • no exposed SSH port
    • no VPN infrastructure
    • works behind NAT or Carrier-Grade NAT
    • management interface is only reachable through the Tor network
    • additional network privacy
    • ideal for self-hosted infrastructure

    This is particularly attractive for servers hosted in data centers where administrators rarely have physical access.

    What Happens After a Crash?

    Whenever the server reboots:

    1. the initramfs starts
    2. networking is initialized
    3. Tor publishes the temporary Onion Service
    4. you connect via SSH
    5. you unlock LUKS
    6. the server continues booting

    No KVM console.

    No VPN.

    No public SSH endpoint.

    Only Tor.

    Of course, catastrophic failures such as a broken initramfs or missing network drivers still require traditional recovery methods such as a rescue system or KVM.

    Existing Building Blocks

    Most of the required components already exist today.

    My repository hetzner-arch-luks demonstrates how to deploy Arch Linux with full disk encryption on Hetzner servers and configure remote unlocking via SSH during the initramfs stage.

    Repository:

    https://github.com/kevinveenbirkenbach/hetzner-arch-luks

    Another project, linux-image-manager, automates the creation and customization of Linux images and could serve as the foundation for embedding Tor, Dropbear/TinySSH, and the required initramfs configuration into reusable images.

    Repository:

    https://github.com/kevinveenbirkenbach/linux-image-manager

    Together, these repositories provide much of the groundwork required for a fully automated implementation.

    Future Integration into Infinito.Nexus

    I envision this becoming a native feature of Infinito.Nexus.

    Provisioning a server could automatically:

    • install Arch Linux
    • configure LUKS full disk encryption
    • generate an initramfs containing:
      • Tor
      • Dropbear or TinySSH
      • cryptsetup
    • create a dedicated boot-time Onion Service
    • automatically switch to permanent runtime Onion Services after successful boot

    From the administrator’s perspective, recovering a rebooted server would be as simple as:

    torsocks ssh root@unlock-<hostname>.onion

    Enter the passphrase.

    The server continues booting.

    Nothing is ever exposed to the public Internet.

    Looking Ahead

    This concept combines three mature technologies:

    • LUKS
    • Tor Onion Services
    • Remote initramfs unlocking

    While each technology already exists independently, integrating them into a seamless provisioning workflow could significantly improve the security and usability of encrypted self-hosted infrastructure.

    For projects focused on digital sovereignty and privacy, removing the need for publicly exposed management interfaces is a natural next step.

    #ArchLinux #cryptsetup #Cybersecurity #DevOps #DigitalSovereignty #DiskEncryption #Dropbear #FullDiskEncryption #Hetzner #InfinitoNexus #InfrastructureAsCode #initramfs #Linux #LinuxSecurity #LUKS #OnionServices #OpenSource #Privacy #RemoteLUKSUnlock #RemoteServerManagement #RemoteUnlock #SecureBoot #SelfHostedInfrastructure #SelfHosting #ServerSecurity #SSHOverTor #TinySSH #Tor #TorHiddenServices
  9. 🛡️🦠 ClamAV 1.5.3 a fost lansat de urgență! Antivirusul open-source repară multiple vulnerabilități de securitate 🚀💻

    Echipa de dezvoltare din spatele ClamAV, cel mai popular și utilizat motor antivirus open-source din lume — integrat masiv pe serverele de mail, în gateway-urile web și pe sistemele Linux din întreaga lume — a anunțat lansarea oficială a versiunii 1.5.3. Aceasta este o actualizare critică de mentenanță și securitate, menită să corecteze mai multe vulnerabilități descoperite în modulele sale de scanare.

    Dacă folosești ClamAV pentru a-ți proteja infrastructura împotriva programelor malițioase (malware), această actualizare ar trebui aplicată fără întârziere pentru a preveni posibile atacuri.

    Iată principalele detalii ale patch-urilor aduse în versiunea 1.5.3:

    🔹 Remedierea vulnerabilităților din motoarele de parsare:
    Miezul ClamAV se bazează pe capacitatea de a deschide, decompresa și analiza o varietate uriașă de formate de fișiere. Versiunea 1.5.3 rezolvă breșe de securitate descoperite tocmai în aceste componente logice. Atacatorii puteau crea fișiere modificate special (cum ar fi arhive sau documente PDF corupte) care, în momentul în care erau analizate de antivirus, puteau provoca prăbușirea serviciului (Denial of Service) sau erori de tip buffer overflow.

    🔹 Prevenirea blocării serverelor (Infinite Loops):
    Au fost corectate bug-uri care puteau bloca procesul de scanare într-o buclă infinită în timpul procesării anumitor structuri de date imbricate. În medii de producție (cum ar fi scanarea e-mailurilor în timp real), acest lucru ducea la un consum de 100% din resursele procesorului și la blocarea completă a cozilor de mesaje.

    🔹 Optimizări generale și stabilitate:
    Pe lângă patch-urile stricte de securitate, ClamAV 1.5.3 aduce îmbunătățiri de performanță pentru motorul de scanare de text și actualizează bibliotecile interne pentru o mai bună compatibilitate cu formatele de fișiere de ultimă generație.

    ⚠️ Recomandare pentru administratori: Deoarece ClamAV rulează adesea ca un serviciu de fundal automat (demonul clamd), este esențial să actualizați pachetul imediat pentru a vă asigura că serverele nu sunt expuse unor vectori de atac ce vizează chiar instrumentul de protecție.

    Noile pachete sunt deja trimise către managerii de depozite ai marilor distribuții Linux și pot fi descărcate sau compilate din surse de pe site-ul oficial ClamAV.

    #ClamAV #Antivirus #OpenSource #Cybersecurity #LinuxSecurity #PatchUpdate #SysAdmin #TechNews

  10. 🛡️🦠 ClamAV 1.5.3 a fost lansat de urgență! Antivirusul open-source repară multiple vulnerabilități de securitate 🚀💻

    Echipa de dezvoltare din spatele ClamAV, cel mai popular și utilizat motor antivirus open-source din lume — integrat masiv pe serverele de mail, în gateway-urile web și pe sistemele Linux din întreaga lume — a anunțat lansarea oficială a versiunii 1.5.3. Aceasta este o actualizare critică de mentenanță și securitate, menită să corecteze mai multe vulnerabilități descoperite în modulele sale de scanare.

    Dacă folosești ClamAV pentru a-ți proteja infrastructura împotriva programelor malițioase (malware), această actualizare ar trebui aplicată fără întârziere pentru a preveni posibile atacuri.

    Iată principalele detalii ale patch-urilor aduse în versiunea 1.5.3:

    🔹 Remedierea vulnerabilităților din motoarele de parsare:
    Miezul ClamAV se bazează pe capacitatea de a deschide, decompresa și analiza o varietate uriașă de formate de fișiere. Versiunea 1.5.3 rezolvă breșe de securitate descoperite tocmai în aceste componente logice. Atacatorii puteau crea fișiere modificate special (cum ar fi arhive sau documente PDF corupte) care, în momentul în care erau analizate de antivirus, puteau provoca prăbușirea serviciului (Denial of Service) sau erori de tip buffer overflow.

    🔹 Prevenirea blocării serverelor (Infinite Loops):
    Au fost corectate bug-uri care puteau bloca procesul de scanare într-o buclă infinită în timpul procesării anumitor structuri de date imbricate. În medii de producție (cum ar fi scanarea e-mailurilor în timp real), acest lucru ducea la un consum de 100% din resursele procesorului și la blocarea completă a cozilor de mesaje.

    🔹 Optimizări generale și stabilitate:
    Pe lângă patch-urile stricte de securitate, ClamAV 1.5.3 aduce îmbunătățiri de performanță pentru motorul de scanare de text și actualizează bibliotecile interne pentru o mai bună compatibilitate cu formatele de fișiere de ultimă generație.

    ⚠️ Recomandare pentru administratori: Deoarece ClamAV rulează adesea ca un serviciu de fundal automat (demonul clamd), este esențial să actualizați pachetul imediat pentru a vă asigura că serverele nu sunt expuse unor vectori de atac ce vizează chiar instrumentul de protecție.

    Noile pachete sunt deja trimise către managerii de depozite ai marilor distribuții Linux și pot fi descărcate sau compilate din surse de pe site-ul oficial ClamAV.

    #ClamAV #Antivirus #OpenSource #Cybersecurity #LinuxSecurity #PatchUpdate #SysAdmin #TechNews

  11. CVE-2026-14544: CRITICAL integer overflow in HPLIP (RHEL 10) enables remote code execution or privilege escalation via crafted print data 🖨️. Patch status not confirmed. Stay updated: radar.offseq.com/threat/cve-20 #OffSeq #CVE202614544 #LinuxSecurity

  12. 🔎 CISOfy’s Lynis delivers battle-tested security auditing for Linux, macOS, and Unix-based systems—scanning host health to support hardening and compliance testing. Modular, flexible, and open-source (GPL), it runs as a lightweight audit tool and powers Lynis Enterprise. Try it: cisofy.com/lynis/ #LinuxSecurity #SecurityAuditing #Compliance

  13. 🔎 CISOfy’s Lynis delivers battle-tested security auditing for Linux, macOS, and Unix-based systems—scanning host health to support hardening and compliance testing. Modular, flexible, and open-source (GPL), it runs as a lightweight audit tool and powers Lynis Enterprise. Try it: cisofy.com/lynis/ #LinuxSecurity #SecurityAuditing #Compliance

  14. Haha, my #foss tool Lynis got covered in a song.

    youtu.be/Qx0DR_PQoWA

    (I guess it is AI generated, but bonus points for promoting open source software)

    #OpenSource #LinuxSecurity

  15. Haha, my #foss tool Lynis got covered in a song.

    youtu.be/Qx0DR_PQoWA

    (I guess it is AI generated, but bonus points for promoting open source software)

    #OpenSource #LinuxSecurity

  16. ⚠️ Arch Linux AUR hit by major ongoing malware campaign

    Since around June 11, attackers have been systematically adopting orphaned packages and injecting malicious code into 1,500+ AUR packages across several waves.

    The malware often sneaks in via suspicious dependencies (npm / bun packages like atomic-lockfile or js-digest) that download a Rust-based infostealer targeting SSH keys, GitHub tokens, browser data, and more. Some attempts are now using code obfuscation to hide what they’re doing. In a few cases it even tries to deploy an eBPF rootkit if run as root.

    Arch developers have been actively reverting the malicious changes, banning compromised accounts, and pausing new package adoptions while they clean it up. Official Arch repos remain safe this is isolated to the user-maintained AUR.
    If you use AUR packages:

    Carefully review PKGBUILDs before building anything new
    Check your installed AUR packages (pacman -Qm) and be extra cautious with anything updated recently
    Consider rotating SSH keys and tokens if you’ve built any suspicious packages
    Community tools and detection scripts are helping spot the bad ones

    Classic reminder that the AUR is powerful but community-driven always review before you build.

    Stay safe, Linux friends.

    #ArchLinux #AUR #LinuxSecurity #Malware #OpenSource

  17. PSA for anyone auditing Linux fleets: getent passwd is NOT the same as cat /etc/passwd when LDAP or SSSD is configured. Your audit scripts will miss every centrally-managed account if you only parse the local file.

    Also, useradd's default shell comes from /etc/default/useradd -- on many distros that's /bin/bash. If you're creating service accounts without --shell /usr/sbin/nologin, you're handing out interactive shells.

    #LinuxSecurity #SysAdmin #BashScripting #Security #DevSecOps #InfoSec

  18. PSA for anyone auditing Linux fleets: getent passwd is NOT the same as cat /etc/passwd when LDAP or SSSD is configured. Your audit scripts will miss every centrally-managed account if you only parse the local file.

    Also, useradd's default shell comes from /etc/default/useradd -- on many distros that's /bin/bash. If you're creating service accounts without --shell /usr/sbin/nologin, you're handing out interactive shells.

    #LinuxSecurity #SysAdmin #BashScripting #Security #DevSecOps #InfoSec

  19. Patches for CVE-2026-46243 (CIFSwitch), a local privilege escalation vulnerability in the Linux kernel's CIFS subsystem, have been built for Rocky Linux 8, 9, and 10. Our hot fix security repository has been updated.

    If you're running any supported Rocky Linux release, update now:
    sudo dnf --enablerepo=security update

  20. Patches for CVE-2026-46243 (CIFSwitch), a local privilege escalation vulnerability in the Linux kernel's CIFS subsystem, have been built for Rocky Linux 8, 9, and 10. Our hot fix security repository has been updated.

    If you're running any supported Rocky Linux release, update now:
    sudo dnf --enablerepo=security update

    #RockyLinux #OpenSource #Linux #LinuxSecurity #CVE #EnterpriseLinux

  21. ⚠️ تحذير لمستخدمي لينكس: ثغرة CVE‑2024‑XXXXX في مكتبة libc تسمح بسرقة مفاتيح SSH والوصول الكامل إلى الخوادم.

    🔑 أهم ما يجب فعله الآن
    - حدّث جميع التوزيعات إلى الإصدار المصحّح.
    - فعّل المصادقة الثنائية وقلل أذونات ملفات المفاتيح.
    - راقب سجلات الدخول للأنشطة غير العادية.

    #LinuxSecurity #SSH #CVE2024 #OpenSource #Privacy

    🔗 news.google.com/rss/articles/C

  22. Infosecurity Europe
    Aggregated from www.darkreading.com.Read the full article →
    sudoaptchat.com/infosecurity-e
    #LinuxSecurity

  23. AI-Discovered Bugs Expose Linux Security Trend

    Linux is facing a surge in security vulnerabilities, with two high-risk kernel-level flaws uncovered just days apart - a trend that's expected to continue, potentially forcing companies to reboot servers on a weekly basis. These recently publicized issues, including Dirty Frag, Copy Fail, and Fragnesia, are linked by a common weakness in the…

    osintsights.com/ai-discovered-

    #LinuxSecurity #LinuxPrivilegeEscalation #PageCache #KernelVulnerabilities #Lpe

  24. AI-Driven Linux Bugs Expose Growing Security Trend

    Linux is facing a surge in high-risk security vulnerabilities, with multiple kernel-level flaws emerging in rapid succession - a trend that's likely to continue, forcing companies to take frequent server reboots to stay safe. Recent bugs like Dirty Frag, Copy Fail, and Fragnesia are more than just isolated incidents,…

    osintsights.com/ai-driven-linu

    #LinuxSecurity #LinuxPrivilegeEscalation #KernelVulnerabilities #AidrivenBugs #EmergingThreats

  25. The Boring Stuff is Dangerous Now
    Aggregated from www.darkreading.com.AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly.
    Read the full article →
    sudoaptchat.com/the-boring-stu
    #LinuxSecurity

  26. I'm considering moving from Arch to Debian for my daily driver, thinking it may be more secure and less of a hassle than Arch's rolling release model. I'm not sure whether it makes much sense if I then have to install newer versions of things (development stuff, mostly?) anyway... But for the system itself? Maybe worth it? 🤔
    #linux #LinuxSecurity

  27. I'm considering moving from Arch to Debian for my daily driver, thinking it may be more secure and less of a hassle than Arch's rolling release model. I'm not sure whether it makes much sense if I then have to install newer versions of things (development stuff, mostly?) anyway... But for the system itself? Maybe worth it? 🤔
    #linux #LinuxSecurity

  28. Copy Fail (CVE-2026-31431) is a 4-byte write into the Linux page cache that hands root to any local user in seconds. No race, no ASLR bypass, a 2017 "in-place is faster" optimization in algif_aead, exploitable in 2026 with 732 bytes of Python.
    The boundaries that hold are the ones that don't share a kernel: Firecracker, V8 isolates, gVisor. Shared-kernel containers, you have homework.
    #LinuxSecurity #KernelSecurity #DevOps

    open.substack.com/pub/doriandi

  29. Copy Fail Linux Privilege

    Copy Fail is a Linux kernel privilege escalation flaw. Learn who may be affected, why it matters, and how to update safely.

    beitmenotyou.online/copy-fail-

  30. CopyFail (CVE-2026-31431) is a high-severity Linux kernel vulnerability -- patches are out now for Rocky Linux 8.10, 9.8, and 10.1.

    Any unprivileged local user can escalate to root in seconds. Multi-tenant hosts, containers, and CI runners should prioritize this one.

    Fix it with:
    sudo dnf --refresh update 'kernel*'

    Full write-up on the blog:
    forums.rockylinux.org/t/copyfa

  31. Heads up: CVE-2026-31431 (Copy Fail) is a kernel crypto vulnerability affecting Rocky Linux. Our community is on it: tracking patches and sharing Rocky-specific guidance as it develops.

    If you're running Rocky in production, check the forum thread for the latest:

    forums.rockylinux.org/t/cve-20