#linux-security — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #linux-security, aggregated by home.social.
-
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
CTRL-OS 26.05 is out: a downstream NixOS/Nixpkgs distro with 5 years of commercial support.
We stay aligned with upstream and contribute security work back to nixpkgs. Fixes for packages like glibc trigger mass rebuilds, which the community batches to preserve CI capacity. For security-sensitive deployments we backport ahead of that in our own public repo, to meet our SLAs.
-
If people are given option then which distro they pick up the most.
#linux #linuxmint #ubuntu #debian #linuxcommunity #linuxdistro #linuxdistros #linuxgaming #linuxkernel #linuxaudio #linuxsecurity #linuxnews #9to5Linux #itsfoss #opensource #linuxmobile #linux_gaming #linuxdesktop #linuxmemes #linuxlaptops -
A critical Bad Epoll vulnerability (CVE-2026-46242) allows local users to gain root access on Linux and Android devices. Patch your systems immediately.
#LinuxSecurity #BadEpoll #CyberSecurity #ZeroDay #CVE202646242
https://meterpreter.org/bad-epoll-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
La sicurezza del tuo clipboard è fondamentale. Scopri come la nuova funzione Paste Protect di Opera One blocca automaticamente le iniezioni di codice pericoloso mentre navighi. #OperaBrowser #CyberSecurity #LinuxSecurity #Privacy #WebSafety
-
La sicurezza del tuo clipboard è fondamentale. Scopri come la nuova funzione Paste Protect di Opera One blocca automaticamente le iniezioni di codice pericoloso mentre navighi. #OperaBrowser #CyberSecurity #LinuxSecurity #Privacy #WebSafety
-
🐞🌐 Ladybird Browser face pași uriași: Adaugă gestionarea descărcărilor, istoric extins și Sandboxing nativ pe Linux 🚀🛡️
Proiectul Ladybird, browserul web independent care a captat atenția întregii lumi tech prin refuzul de a folosi motoare existente (precum Chromium/Blink sau Firefox/Gecko), continuă să se transforme într-un produs de zi cu zi extrem de capabil. În cea mai recentă actualizare, echipa de dezvoltare a anunțat adăugarea unor funcții vitale de utilizare: un panou de Downloads, o pagină dedicată pentru Istoric (History) și, cel mai important din punct de vedere tehnic, o arhitectură de Sandboxing nativă pentru Linux.
Născut inițial ca un simplu vizualizator HTML pentru sistemul de operare retro SerenityOS, Ladybird este acum un proiect cross-platform matur, scris de la zero în C++, care pune un accent obsesiv pe performanță, standarde web curate și confidențialitate.
Iată principalele noutăți implementate în această versiune:
🔹 Securitate de top prin Sandboxing pe Linux:
Până acum, mecanismele avansate de izolare a proceselor din Ladybird funcționau excelent pe macOS (folosind sandbox_init). Noua actualizare aduce în sfârșit paritatea de securitate și pentru utilizatorii de Linux.Browserul utilizează acum tehnologiile native din kernelul Linux, precum Namespaces (izolarea rețelei și a proceselor) și Landlock (un modul de securitate LSM modern care restricționează drastic accesul la sistemul de fișiere).
Ce înseamnă asta? Dacă o pagină web malițioasă reușește să exploateze o breșă în motorul de randare, atacul va fi complet izolat în interiorul acelui tab și nu va putea accesa fișierele tale personale de pe computer.
🔹 Gestionar de descărcări (Downloads Manager):
O funcție de bază, dar absolut esențială pentru un browser modern. Ladybird include acum o interfață dedicată pentru monitorizarea descărcărilor de fișiere. Utilizatorii pot vedea progresul în timp real, viteza de download, pot pune pe pauză sau anula procesul și pot deschide direct folderul destinație dintr-un simplu click.🔹 Istoric de navigare complet (History View):
A fost implementată componenta de management a istoricului. Pagina îți permite acum să cauți rapid prin site-urile vizitate anterior, să le sortezi în funcție de dată și să ștergi selectiv anumite intrări sau întregul istoric de navigare, sporind controlul asupra urmelor digitale.🔹 Rafinarea motorului de randare propriu (LibWeb & LibJS):
Dezvoltatorii continuă să bifeze procente uriașe în testele de compatibilitate cu standardele web oficiale (W3C). Au fost corectate bug-uri legate de interpretarea codului JavaScript complex și au fost aduse îmbunătățiri în randarea layout-urilor CSS moderne (Flexbox și Grid), făcând ca din ce în ce mai multe site-uri complexe să se încarce impecabil.💡 De ce contează Ladybird? Într-o industrie web dominată aproape în totalitate de monopolul Google Chromium (pe care se bazează Chrome, Edge, Brave, Opera și Vivaldi), Ladybird reprezintă una dintre puținele speranțe pentru un web liber și diversificat, demonstrând că o comunitate pasionată poate construi o alternativă reală de la zero.
Proiectul este complet open-source, nu include reclame, nu colectează telemetrie și este finanțat exclusiv din donații și sponsorizări (inclusiv un suport masiv din partea unor figuri proeminente din tech).
#LadybirdBrowser #Ladybird #WebBrowser #LinuxSecurity #Sandboxing #Landlock #OpenSource #BrowserIndependent #TechNews
-
🐞🌐 Ladybird Browser face pași uriași: Adaugă gestionarea descărcărilor, istoric extins și Sandboxing nativ pe Linux 🚀🛡️
Proiectul Ladybird, browserul web independent care a captat atenția întregii lumi tech prin refuzul de a folosi motoare existente (precum Chromium/Blink sau Firefox/Gecko), continuă să se transforme într-un produs de zi cu zi extrem de capabil. În cea mai recentă actualizare, echipa de dezvoltare a anunțat adăugarea unor funcții vitale de utilizare: un panou de Downloads, o pagină dedicată pentru Istoric (History) și, cel mai important din punct de vedere tehnic, o arhitectură de Sandboxing nativă pentru Linux.
Născut inițial ca un simplu vizualizator HTML pentru sistemul de operare retro SerenityOS, Ladybird este acum un proiect cross-platform matur, scris de la zero în C++, care pune un accent obsesiv pe performanță, standarde web curate și confidențialitate.
Iată principalele noutăți implementate în această versiune:
🔹 Securitate de top prin Sandboxing pe Linux:
Până acum, mecanismele avansate de izolare a proceselor din Ladybird funcționau excelent pe macOS (folosind sandbox_init). Noua actualizare aduce în sfârșit paritatea de securitate și pentru utilizatorii de Linux.Browserul utilizează acum tehnologiile native din kernelul Linux, precum Namespaces (izolarea rețelei și a proceselor) și Landlock (un modul de securitate LSM modern care restricționează drastic accesul la sistemul de fișiere).
Ce înseamnă asta? Dacă o pagină web malițioasă reușește să exploateze o breșă în motorul de randare, atacul va fi complet izolat în interiorul acelui tab și nu va putea accesa fișierele tale personale de pe computer.
🔹 Gestionar de descărcări (Downloads Manager):
O funcție de bază, dar absolut esențială pentru un browser modern. Ladybird include acum o interfață dedicată pentru monitorizarea descărcărilor de fișiere. Utilizatorii pot vedea progresul în timp real, viteza de download, pot pune pe pauză sau anula procesul și pot deschide direct folderul destinație dintr-un simplu click.🔹 Istoric de navigare complet (History View):
A fost implementată componenta de management a istoricului. Pagina îți permite acum să cauți rapid prin site-urile vizitate anterior, să le sortezi în funcție de dată și să ștergi selectiv anumite intrări sau întregul istoric de navigare, sporind controlul asupra urmelor digitale.🔹 Rafinarea motorului de randare propriu (LibWeb & LibJS):
Dezvoltatorii continuă să bifeze procente uriașe în testele de compatibilitate cu standardele web oficiale (W3C). Au fost corectate bug-uri legate de interpretarea codului JavaScript complex și au fost aduse îmbunătățiri în randarea layout-urilor CSS moderne (Flexbox și Grid), făcând ca din ce în ce mai multe site-uri complexe să se încarce impecabil.💡 De ce contează Ladybird? Într-o industrie web dominată aproape în totalitate de monopolul Google Chromium (pe care se bazează Chrome, Edge, Brave, Opera și Vivaldi), Ladybird reprezintă una dintre puținele speranțe pentru un web liber și diversificat, demonstrând că o comunitate pasionată poate construi o alternativă reală de la zero.
Proiectul este complet open-source, nu include reclame, nu colectează telemetrie și este finanțat exclusiv din donații și sponsorizări (inclusiv un suport masiv din partea unor figuri proeminente din tech).
#LadybirdBrowser #Ladybird #WebBrowser #LinuxSecurity #Sandboxing #Landlock #OpenSource #BrowserIndependent #TechNews
-
Unlocking Fully Encrypted Servers over Tor
Remote servers should not have to choose between security and availability.
For years, the common compromise has been to expose SSH to the public Internet or to rely on VPNs and provider-specific KVM consoles whenever a LUKS-encrypted server reboots.
I believe there is a better approach.
By combining LUKS, Tor Onion Services, and a lightweight SSH server running directly inside the initramfs, it is possible to build servers that remain fully encrypted at rest, yet can always be unlocked remotely without exposing any public management interface.
This article describes the concept and how it could evolve into a reusable feature for Infinito.Nexus.
The Problem
Full disk encryption protects data when a server is powered off.
However, after every reboot someone must enter the LUKS passphrase.
For remote dedicated servers this usually means one of the following:
- opening SSH to the Internet
- connecting through a VPN
- using a provider’s KVM/IPMI console
- booting into a rescue system
While remote unlocking via Dropbear inside the initramfs is already a well-known solution, it still typically relies on a publicly reachable IP address.
The Idea
Instead of exposing SSH publicly, start Tor directly inside the initramfs.
The boot sequence would look like this:
Server boots
│
▼
Kernel + initramfs
│
▼
Network initialization
│
▼
Tor starts
│
▼
Temporary Onion Service appears
unlock-xxxxxxxx.onion
│
▼
SSH via Tor
│
▼
cryptsetup luksOpen
│
▼
Root filesystem unlocked
│
▼
Operating system boots
│
▼
Temporary Onion Service disappearsThe administrator simply connects through Tor:
torsocks ssh [email protected]After entering the LUKS passphrase, the operating system continues booting normally.
Separate Identities for Boot and Runtime
One of the strongest aspects of this design is that boot-time and runtime use different Onion identities.
Boot environment
- dedicated Ed25519 key
- dedicated Onion address
- only SSH
- exists only during boot
Example:
unlock-xxxxxxxx.onionRuntime environment
Once the operating system has booted:
- the initramfs exits
- Tor inside initramfs stops
- a new Tor instance starts
- completely different Onion addresses become available
For example:
ssh-xxxxxxxx.onion
cloud-xxxxxxxx.onion
matrix-xxxxxxxx.onion
mail-xxxxxxxx.onionThe unlock address simply disappears.
This cleanly separates the trust boundaries between the bootloader environment and the running operating system.
Why Tor?
Using Tor instead of exposing SSH directly provides several advantages:
- no public IP address required
- no exposed SSH port
- no VPN infrastructure
- works behind NAT or Carrier-Grade NAT
- management interface is only reachable through the Tor network
- additional network privacy
- ideal for self-hosted infrastructure
This is particularly attractive for servers hosted in data centers where administrators rarely have physical access.
What Happens After a Crash?
Whenever the server reboots:
- the initramfs starts
- networking is initialized
- Tor publishes the temporary Onion Service
- you connect via SSH
- you unlock LUKS
- the server continues booting
No KVM console.
No VPN.
No public SSH endpoint.
Only Tor.
Of course, catastrophic failures such as a broken initramfs or missing network drivers still require traditional recovery methods such as a rescue system or KVM.
Existing Building Blocks
Most of the required components already exist today.
My repository hetzner-arch-luks demonstrates how to deploy Arch Linux with full disk encryption on Hetzner servers and configure remote unlocking via SSH during the initramfs stage.
Repository:
https://github.com/kevinveenbirkenbach/hetzner-arch-luks
Another project, linux-image-manager, automates the creation and customization of Linux images and could serve as the foundation for embedding Tor, Dropbear/TinySSH, and the required initramfs configuration into reusable images.
Repository:
https://github.com/kevinveenbirkenbach/linux-image-manager
Together, these repositories provide much of the groundwork required for a fully automated implementation.
Future Integration into Infinito.Nexus
I envision this becoming a native feature of Infinito.Nexus.
Provisioning a server could automatically:
- install Arch Linux
- configure LUKS full disk encryption
- generate an initramfs containing:
- Tor
- Dropbear or TinySSH
- cryptsetup
- create a dedicated boot-time Onion Service
- automatically switch to permanent runtime Onion Services after successful boot
From the administrator’s perspective, recovering a rebooted server would be as simple as:
torsocks ssh root@unlock-<hostname>.onionEnter the passphrase.
The server continues booting.
Nothing is ever exposed to the public Internet.
Looking Ahead
This concept combines three mature technologies:
- LUKS
- Tor Onion Services
- Remote initramfs unlocking
While each technology already exists independently, integrating them into a seamless provisioning workflow could significantly improve the security and usability of encrypted self-hosted infrastructure.
For projects focused on digital sovereignty and privacy, removing the need for publicly exposed management interfaces is a natural next step.
#ArchLinux #cryptsetup #Cybersecurity #DevOps #DigitalSovereignty #DiskEncryption #Dropbear #FullDiskEncryption #Hetzner #InfinitoNexus #InfrastructureAsCode #initramfs #Linux #LinuxSecurity #LUKS #OnionServices #OpenSource #Privacy #RemoteLUKSUnlock #RemoteServerManagement #RemoteUnlock #SecureBoot #SelfHostedInfrastructure #SelfHosting #ServerSecurity #SSHOverTor #TinySSH #Tor #TorHiddenServices -
🛡️🦠 ClamAV 1.5.3 a fost lansat de urgență! Antivirusul open-source repară multiple vulnerabilități de securitate 🚀💻
Echipa de dezvoltare din spatele ClamAV, cel mai popular și utilizat motor antivirus open-source din lume — integrat masiv pe serverele de mail, în gateway-urile web și pe sistemele Linux din întreaga lume — a anunțat lansarea oficială a versiunii 1.5.3. Aceasta este o actualizare critică de mentenanță și securitate, menită să corecteze mai multe vulnerabilități descoperite în modulele sale de scanare.
Dacă folosești ClamAV pentru a-ți proteja infrastructura împotriva programelor malițioase (malware), această actualizare ar trebui aplicată fără întârziere pentru a preveni posibile atacuri.
Iată principalele detalii ale patch-urilor aduse în versiunea 1.5.3:
🔹 Remedierea vulnerabilităților din motoarele de parsare:
Miezul ClamAV se bazează pe capacitatea de a deschide, decompresa și analiza o varietate uriașă de formate de fișiere. Versiunea 1.5.3 rezolvă breșe de securitate descoperite tocmai în aceste componente logice. Atacatorii puteau crea fișiere modificate special (cum ar fi arhive sau documente PDF corupte) care, în momentul în care erau analizate de antivirus, puteau provoca prăbușirea serviciului (Denial of Service) sau erori de tip buffer overflow.🔹 Prevenirea blocării serverelor (Infinite Loops):
Au fost corectate bug-uri care puteau bloca procesul de scanare într-o buclă infinită în timpul procesării anumitor structuri de date imbricate. În medii de producție (cum ar fi scanarea e-mailurilor în timp real), acest lucru ducea la un consum de 100% din resursele procesorului și la blocarea completă a cozilor de mesaje.🔹 Optimizări generale și stabilitate:
Pe lângă patch-urile stricte de securitate, ClamAV 1.5.3 aduce îmbunătățiri de performanță pentru motorul de scanare de text și actualizează bibliotecile interne pentru o mai bună compatibilitate cu formatele de fișiere de ultimă generație.⚠️ Recomandare pentru administratori: Deoarece ClamAV rulează adesea ca un serviciu de fundal automat (demonul clamd), este esențial să actualizați pachetul imediat pentru a vă asigura că serverele nu sunt expuse unor vectori de atac ce vizează chiar instrumentul de protecție.
Noile pachete sunt deja trimise către managerii de depozite ai marilor distribuții Linux și pot fi descărcate sau compilate din surse de pe site-ul oficial ClamAV.
#ClamAV #Antivirus #OpenSource #Cybersecurity #LinuxSecurity #PatchUpdate #SysAdmin #TechNews
-
🛡️🦠 ClamAV 1.5.3 a fost lansat de urgență! Antivirusul open-source repară multiple vulnerabilități de securitate 🚀💻
Echipa de dezvoltare din spatele ClamAV, cel mai popular și utilizat motor antivirus open-source din lume — integrat masiv pe serverele de mail, în gateway-urile web și pe sistemele Linux din întreaga lume — a anunțat lansarea oficială a versiunii 1.5.3. Aceasta este o actualizare critică de mentenanță și securitate, menită să corecteze mai multe vulnerabilități descoperite în modulele sale de scanare.
Dacă folosești ClamAV pentru a-ți proteja infrastructura împotriva programelor malițioase (malware), această actualizare ar trebui aplicată fără întârziere pentru a preveni posibile atacuri.
Iată principalele detalii ale patch-urilor aduse în versiunea 1.5.3:
🔹 Remedierea vulnerabilităților din motoarele de parsare:
Miezul ClamAV se bazează pe capacitatea de a deschide, decompresa și analiza o varietate uriașă de formate de fișiere. Versiunea 1.5.3 rezolvă breșe de securitate descoperite tocmai în aceste componente logice. Atacatorii puteau crea fișiere modificate special (cum ar fi arhive sau documente PDF corupte) care, în momentul în care erau analizate de antivirus, puteau provoca prăbușirea serviciului (Denial of Service) sau erori de tip buffer overflow.🔹 Prevenirea blocării serverelor (Infinite Loops):
Au fost corectate bug-uri care puteau bloca procesul de scanare într-o buclă infinită în timpul procesării anumitor structuri de date imbricate. În medii de producție (cum ar fi scanarea e-mailurilor în timp real), acest lucru ducea la un consum de 100% din resursele procesorului și la blocarea completă a cozilor de mesaje.🔹 Optimizări generale și stabilitate:
Pe lângă patch-urile stricte de securitate, ClamAV 1.5.3 aduce îmbunătățiri de performanță pentru motorul de scanare de text și actualizează bibliotecile interne pentru o mai bună compatibilitate cu formatele de fișiere de ultimă generație.⚠️ Recomandare pentru administratori: Deoarece ClamAV rulează adesea ca un serviciu de fundal automat (demonul clamd), este esențial să actualizați pachetul imediat pentru a vă asigura că serverele nu sunt expuse unor vectori de atac ce vizează chiar instrumentul de protecție.
Noile pachete sunt deja trimise către managerii de depozite ai marilor distribuții Linux și pot fi descărcate sau compilate din surse de pe site-ul oficial ClamAV.
#ClamAV #Antivirus #OpenSource #Cybersecurity #LinuxSecurity #PatchUpdate #SysAdmin #TechNews
-
CVE-2026-14544: CRITICAL integer overflow in HPLIP (RHEL 10) enables remote code execution or privilege escalation via crafted print data 🖨️. Patch status not confirmed. Stay updated: https://radar.offseq.com/threat/cve-2026-14544-integer-overflow-or-wraparound-in-r-d57463ec7bf8b710 #OffSeq #CVE202614544 #LinuxSecurity
-
🔎 CISOfy’s Lynis delivers battle-tested security auditing for Linux, macOS, and Unix-based systems—scanning host health to support hardening and compliance testing. Modular, flexible, and open-source (GPL), it runs as a lightweight audit tool and powers Lynis Enterprise. Try it: https://cisofy.com/lynis/ #LinuxSecurity #SecurityAuditing #Compliance
-
🔎 CISOfy’s Lynis delivers battle-tested security auditing for Linux, macOS, and Unix-based systems—scanning host health to support hardening and compliance testing. Modular, flexible, and open-source (GPL), it runs as a lightweight audit tool and powers Lynis Enterprise. Try it: https://cisofy.com/lynis/ #LinuxSecurity #SecurityAuditing #Compliance
-
Haha, my #foss tool Lynis got covered in a song.
(I guess it is AI generated, but bonus points for promoting open source software)
-
Haha, my #foss tool Lynis got covered in a song.
(I guess it is AI generated, but bonus points for promoting open source software)
-
Lockpicker è un app open source per DE GNOME che consente di usare Hashcat in modo semplice e formativo su Linux. #Lockpicker #Hashcat #LinuxSecurity #GNOME #CyberTraining
-
Lockpicker è un app open source per DE GNOME che consente di usare Hashcat in modo semplice e formativo su Linux. #Lockpicker #Hashcat #LinuxSecurity #GNOME #CyberTraining
-
⚠️ Arch Linux AUR hit by major ongoing malware campaign
Since around June 11, attackers have been systematically adopting orphaned packages and injecting malicious code into 1,500+ AUR packages across several waves.
The malware often sneaks in via suspicious dependencies (npm / bun packages like atomic-lockfile or js-digest) that download a Rust-based infostealer targeting SSH keys, GitHub tokens, browser data, and more. Some attempts are now using code obfuscation to hide what they’re doing. In a few cases it even tries to deploy an eBPF rootkit if run as root.
Arch developers have been actively reverting the malicious changes, banning compromised accounts, and pausing new package adoptions while they clean it up. Official Arch repos remain safe this is isolated to the user-maintained AUR.
If you use AUR packages:Carefully review PKGBUILDs before building anything new
Check your installed AUR packages (pacman -Qm) and be extra cautious with anything updated recently
Consider rotating SSH keys and tokens if you’ve built any suspicious packages
Community tools and detection scripts are helping spot the bad onesClassic reminder that the AUR is powerful but community-driven always review before you build.
Stay safe, Linux friends.
-
PSA for anyone auditing Linux fleets: getent passwd is NOT the same as cat /etc/passwd when LDAP or SSSD is configured. Your audit scripts will miss every centrally-managed account if you only parse the local file.
Also, useradd's default shell comes from /etc/default/useradd -- on many distros that's /bin/bash. If you're creating service accounts without --shell /usr/sbin/nologin, you're handing out interactive shells.
#LinuxSecurity #SysAdmin #BashScripting #Security #DevSecOps #InfoSec
-
PSA for anyone auditing Linux fleets: getent passwd is NOT the same as cat /etc/passwd when LDAP or SSSD is configured. Your audit scripts will miss every centrally-managed account if you only parse the local file.
Also, useradd's default shell comes from /etc/default/useradd -- on many distros that's /bin/bash. If you're creating service accounts without --shell /usr/sbin/nologin, you're handing out interactive shells.
#LinuxSecurity #SysAdmin #BashScripting #Security #DevSecOps #InfoSec
-
Patches for CVE-2026-46243 (CIFSwitch), a local privilege escalation vulnerability in the Linux kernel's CIFS subsystem, have been built for Rocky Linux 8, 9, and 10. Our hot fix security repository has been updated.
If you're running any supported Rocky Linux release, update now:
sudo dnf --enablerepo=security update#RockyLinux #OpenSource #Linux #LinuxSecurity #CVE #EnterpriseLinux
-
Patches for CVE-2026-46243 (CIFSwitch), a local privilege escalation vulnerability in the Linux kernel's CIFS subsystem, have been built for Rocky Linux 8, 9, and 10. Our hot fix security repository has been updated.
If you're running any supported Rocky Linux release, update now:
sudo dnf --enablerepo=security update#RockyLinux #OpenSource #Linux #LinuxSecurity #CVE #EnterpriseLinux
-
⚠️ تحذير لمستخدمي لينكس: ثغرة CVE‑2024‑XXXXX في مكتبة libc تسمح بسرقة مفاتيح SSH والوصول الكامل إلى الخوادم.
🔑 أهم ما يجب فعله الآن
- حدّث جميع التوزيعات إلى الإصدار المصحّح.
- فعّل المصادقة الثنائية وقلل أذونات ملفات المفاتيح.
- راقب سجلات الدخول للأنشطة غير العادية. -
Learn why Linux Kernel developers want to deprecate AF_ALG features, and the security concerns driving the decision.
Full story here: https://ostechnix.com/linux-kernel-7-2-deprecates-af_alg/
#AF_ALG #LinuxCryptoSubsystem #Linuxkernel #Linuxsecurity #EricBiggers #LinuxkernelHardening #Opensource
-
Learn why Linux Kernel developers want to deprecate AF_ALG features, and the security concerns driving the decision.
Full story here: https://ostechnix.com/linux-kernel-7-2-deprecates-af_alg/
#AF_ALG #LinuxCryptoSubsystem #Linuxkernel #Linuxsecurity #EricBiggers #LinuxkernelHardening #Opensource
-
Infosecurity Europe
Aggregated from www.darkreading.com.Read the full article →
http://sudoaptchat.com/infosecurity-europe/
#LinuxSecurity -
KDE Linux rimuove Zen Kernel, AUR e moduli non sicuri, rafforzando sicurezza e coerenza del suo sistema immutabile basato su Flatpak.
#KDELinux #KDE #LinuxSecurity #ImmutableOS #Flatpak #Linuxhttps://www.linuxeasy.org/kde-linux-zen-kernel-aur/?utm_source=mastodon&utm_medium=jetpack_social
-
KDE Linux rimuove Zen Kernel, AUR e moduli non sicuri, rafforzando sicurezza e coerenza del suo sistema immutabile basato su Flatpak.
#KDELinux #KDE #LinuxSecurity #ImmutableOS #Flatpak #Linuxhttps://www.linuxeasy.org/kde-linux-zen-kernel-aur/?utm_source=mastodon&utm_medium=jetpack_social
-
Rocky Linux 10.2 introduce crittografia post‑quantum, nuovi strumenti per installazione e gestione, aggiornamenti dei componenti e miglioramenti per utenti Linux.
#RockyLinux #PostQuantum #LinuxSecurity #OpenSource #SysadminLife -
Rocky Linux 10.2 introduce crittografia post‑quantum, nuovi strumenti per installazione e gestione, aggiornamenti dei componenti e miglioramenti per utenti Linux.
#RockyLinux #PostQuantum #LinuxSecurity #OpenSource #SysadminLife -
AI-Discovered Bugs Expose Linux Security Trend
Linux is facing a surge in security vulnerabilities, with two high-risk kernel-level flaws uncovered just days apart - a trend that's expected to continue, potentially forcing companies to reboot servers on a weekly basis. These recently publicized issues, including Dirty Frag, Copy Fail, and Fragnesia, are linked by a common weakness in the…
#LinuxSecurity #LinuxPrivilegeEscalation #PageCache #KernelVulnerabilities #Lpe
-
Linux Mint speeds up Nemo, redesigns screenshots, and warns users about fake Linux app websites
https://fed.brid.gy/r/https://nerds.xyz/2026/05/linux-mint-may-2026-news/
-
AI-Driven Linux Bugs Expose Growing Security Trend
Linux is facing a surge in high-risk security vulnerabilities, with multiple kernel-level flaws emerging in rapid succession - a trend that's likely to continue, forcing companies to take frequent server reboots to stay safe. Recent bugs like Dirty Frag, Copy Fail, and Fragnesia are more than just isolated incidents,…
#LinuxSecurity #LinuxPrivilegeEscalation #KernelVulnerabilities #AidrivenBugs #EmergingThreats
-
🚀 Linus Torvalds throws a digital tantrum because his inbox can't handle AI bug hunters 🤖. Apparently, managing the Linux security mailing list is harder than fixing the bugs themselves! 📬💥
https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633 #LinusTorvalds #AIbughunters #LinuxSecurity #DigitalTantrum #InboxManagement #HackerNews #ngated -
🚀 Linus Torvalds throws a digital tantrum because his inbox can't handle AI bug hunters 🤖. Apparently, managing the Linux security mailing list is harder than fixing the bugs themselves! 📬💥
https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633 #LinusTorvalds #AIbughunters #LinuxSecurity #DigitalTantrum #InboxManagement #HackerNews #ngated -
The Boring Stuff is Dangerous Now
Aggregated from www.darkreading.com.AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly.
Read the full article →
http://sudoaptchat.com/the-boring-stuff-is-dangerous-now/
#LinuxSecurity -
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
🔗 https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
🔗 https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
I'm considering moving from Arch to Debian for my daily driver, thinking it may be more secure and less of a hassle than Arch's rolling release model. I'm not sure whether it makes much sense if I then have to install newer versions of things (development stuff, mostly?) anyway... But for the system itself? Maybe worth it? 🤔
#linux #LinuxSecurity -
I'm considering moving from Arch to Debian for my daily driver, thinking it may be more secure and less of a hassle than Arch's rolling release model. I'm not sure whether it makes much sense if I then have to install newer versions of things (development stuff, mostly?) anyway... But for the system itself? Maybe worth it? 🤔
#linux #LinuxSecurity -
Copy Fail (CVE-2026-31431) is a 4-byte write into the Linux page cache that hands root to any local user in seconds. No race, no ASLR bypass, a 2017 "in-place is faster" optimization in algif_aead, exploitable in 2026 with 732 bytes of Python.
The boundaries that hold are the ones that don't share a kernel: Firecracker, V8 isolates, gVisor. Shared-kernel containers, you have homework.
#LinuxSecurity #KernelSecurity #DevOps -
Copy Fail Linux Privilege
Copy Fail is a Linux kernel privilege escalation flaw. Learn who may be affected, why it matters, and how to update safely. -
CopyFail (CVE-2026-31431) is a high-severity Linux kernel vulnerability -- patches are out now for Rocky Linux 8.10, 9.8, and 10.1.
Any unprivileged local user can escalate to root in seconds. Multi-tenant hosts, containers, and CI runners should prioritize this one.
Fix it with:
sudo dnf --refresh update 'kernel*'Full write-up on the blog:
https://forums.rockylinux.org/t/copyfail-cve-2026-31431-patches-now-available-for-rocky-linux/20422
#RockyLinux #Linux #OpenSource #LinuxSecurity #CopyFail -
Heads up: CVE-2026-31431 (Copy Fail) is a kernel crypto vulnerability affecting Rocky Linux. Our community is on it: tracking patches and sharing Rocky-specific guidance as it develops.
If you're running Rocky in production, check the forum thread for the latest:
https://forums.rockylinux.org/t/cve-2026-31431-copy-fail-linux-kernel-crypto-vulnerability/20375/8
#RockyLinux #LinuxSecurity #OpenSource