#ssh — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ssh, aggregated by home.social.
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Спутник как VPS: честная история про космический SSH, TinySat и TriSat
Космический аппарат не обязательно должен весить сотни килограммов и стоить как небольшой завод. Иногда достаточно платы размером с ладонь, Raspberry Pi, радиоканала и команды, которая готова несколько месяцев отлаживать термостабилизацию, прошивку и связь с орбиты. В июле прошлого года я рассказывал , что мы готовим к запуску спутник с бортовым компьютером, к которому можно будет подключаться по SSH. Прямо как к нашему VPS, только он летит над головой со скоростью 7,8 км/с. Звучало как фантастика, но мы это сделали. Сейчас расскажу, что из этого вышло на самом деле, почему мы ушли от предыдущего форм-фактора и что такое TriSat — платформа, которую мы выбрали для нашего космического эксперимента.
https://habr.com/ru/companies/ruvds/articles/1069366/
#ruvds_статьи #спутники #linux #радиосвязь #ssh #трисат #vps
-
SSH Tunnels tonight at @PLUG
Description: SSH is a secure networking multitool. Tunnel backwards and forwards, double-tunnel, throw a tunnel, tunnel for proxies and applications. Learn important configuration options and command line convienience tips as well.
tonight @ 19:00 AZ ( UTC - 7 )
1702 E Highland, Phoenix
@FLOSS_Stammtisch is next Tuesday on the 18th also starting at 19:00
#LocalGroup #Phoenix #Arizona #FLOSSgroup #LUG #PLUG #Stammtisch #FLOSS_Stammtisch #SSH #OpenSSH
-
SSH Tunnels tonight at @PLUG
Description: SSH is a secure networking multitool. Tunnel backwards and forwards, double-tunnel, throw a tunnel, tunnel for proxies and applications. Learn important configuration options and command line convienience tips as well.
tonight @ 19:00 AZ ( UTC - 7 )
1702 E Highland, Phoenix
@FLOSS_Stammtisch is next Tuesday on the 18th also starting at 19:00
#LocalGroup #Phoenix #Arizona #FLOSSgroup #LUG #PLUG #Stammtisch #FLOSS_Stammtisch #SSH #OpenSSH
-
SSHBool punta a semplificare la gestione delle infrastrutture remote riunendo terminale, SFTP, editor, database e monitoraggio in un'unica applicazione desktop. 🚀 #Linux #SSH #Rust #Tauri #SysAdmin #OpenSource #LinuxEasy https://www.linuxeasy.org/sshbool-la-nuova-workspace-desktop-per-gestire-infrastrutture-remote/
-
SSHBool punta a semplificare la gestione delle infrastrutture remote riunendo terminale, SFTP, editor, database e monitoraggio in un'unica applicazione desktop. 🚀 #Linux #SSH #Rust #Tauri #SysAdmin #OpenSource #LinuxEasy https://www.linuxeasy.org/sshbool-la-nuova-workspace-desktop-per-gestire-infrastrutture-remote/
-
Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.
The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.
This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.
#ai #security #SupplyChainAttack #hack
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
Companies exposed: https://exposure.cloudsek.com/ai-supply-chain-incident
ArsTecnica overview: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
-
Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.
The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.
This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.
#ai #security #SupplyChainAttack #hack
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
Companies exposed: https://exposure.cloudsek.com/ai-supply-chain-incident
ArsTecnica overview: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
-
Quel boulet.
J'étais entrain de mettre en place un backup hors-site de mon serveur. Devant faire une pause, j'éteins mon ordi :
$ sudo shutdown -h nowJ'étais dans ma session SSH 😬
Je suis en vacances, et je viens d'éteindre mon serveur sur lequel j'héberge mes photos, mes films, mes musiques, mon nextcloud, une instance writefreely, ainsi que tous mes mots de passe sur Vaultwarden. Le seul moyen de l'allumer c'est d'être sur place.Je suis un boulet.
-
Quel boulet.
J'étais entrain de mettre en place un backup hors-site de mon serveur. Devant faire une pause, j'éteins mon ordi :
$ sudo shutdown -h nowJ'avais oublié de fermer ma session SSH 😬
Je suis en vacances, et je viens d'éteindre mon serveur sur lequel j'héberge mes photos, mes films, mes musiques, mon nextcloud, une instance writefreely, ainsi que tous mes mots de passe sur Vaultwarden. Le seul moyen de l'allumer c'est d'être sur place.Je suis un boulet.
-
'90s, come back in this time. This is all we need.
- Provides a simple, no-frills terminal with everything you need, using Linux GTK3.
- Supports local terminals, SSH, and SFTP as well as serial and TELNET connections, bringing that familiar terminal experience into the present.
- Transfers files to and from the host of an SSH connection over SFTP.And many other features.
-
'90s, come back in this time. This is all we need.
- Provides a simple, no-frills terminal with everything you need, using Linux GTK3.
- Supports local terminals, SSH, and SFTP as well as serial and TELNET connections, bringing that familiar terminal experience into the present.
- Transfers files to and from the host of an SSH connection over SFTP.And many other features.
-
RE: https://fosstodon.org/@CenterforOpenScience/117076822166523045
🔔 News from OSF, important especially to those who are used to publishing their research data using the platform.
#openscience #openaccess #academia #science #psychology #ssh
-
SSHardening – Karol Szafrański – P.I.W.O. 2026
-
OpenSSH 10.5 ships with several security fixes, as developers say growing AI-assisted vulnerability research is prompting more frequent releases.
https://linuxiac.com/openssh-10-5-fixes-security-flaws-as-project-responds-to-ai-assisted-bug-discovery/ -
OpenSSH 10.5 ships with several security fixes, as developers say growing AI-assisted vulnerability research is prompting more frequent releases.
https://linuxiac.com/openssh-10-5-fixes-security-flaws-as-project-responds-to-ai-assisted-bug-discovery/ -
unissh – современный, опенсорсный SSH клиент с selfhosted zero-knowledge сервером для синхронизации данных
Доброго времени суток, читатели! Хочу представить вам unissh – современный, простой опенсорсный SSH клиент с selfhosted zero-knowledge сервером для синхронизации данных.
https://habr.com/ru/articles/1068896/
#ssh #rust #terminal #crossplatform #selfhosted #sshclient #sftp
-
Headless Raspberry Pi für SSH vorkonfigurieren
Am Wochenende hatte ich da mal wieder so eine Situation, dass ich einen Raspberry Pi headless deployen wollte. Er sollte einen Strauß von USB-serial Adaptern in einem tmux zusammenmuxen. Also nichts, wofür man ein grafische Oberfläche, geschweige denn einen Monitor braucht. Dementsprechend wollte ich nicht mit (noch mehr) Kabeln und Hardware herumjonglieren. Das muss doch auch ohne gehen. Einfach eine vorbereitete SD-Karte reinstopfen und sofort loslegen. Ja. geht. Und damit ich das nicht […]https://www.commander1024.de/wordpress/2026/08/headless-raspberry-pi-fuer-ssh-vorkonfigurieren/
-
Headless Raspberry Pi für SSH vorkonfigurieren
Am Wochenende hatte ich da mal wieder so eine Situation, dass ich einen Raspberry Pi headless deployen wollte. Er sollte einen Strauß von USB-serial Adaptern in einem tmux zusammenmuxen. Also nichts, wofür man ein grafische Oberfläche, geschweige denn einen Monitor braucht. Dementsprechend wollte ich nicht mit (noch mehr) Kabeln und Hardware herumjonglieren. Das muss doch auch ohne gehen. Einfach eine vorbereitete SD-Karte reinstopfen und sofort loslegen. Ja. geht. Und damit ich das nicht […]https://www.commander1024.de/wordpress/2026/08/headless-raspberry-pi-fuer-ssh-vorkonfigurieren/
-
Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram
Indicators extracted from public reporting. Source: https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram
Pulse ID: 6a79ca73d5b9065ceacb44eb
Pulse Link: https://otx.alienvault.com/pulse/6a79ca73d5b9065ceacb44eb
Pulse Author: CyberHunter_NL
Created: 2026-08-10 12:56:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SSH #Telegram #bot #CyberHunter_NL
-
Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram
Indicators extracted from public reporting. Source: https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram
Pulse ID: 6a79ca73d5b9065ceacb44eb
Pulse Link: https://otx.alienvault.com/pulse/6a79ca73d5b9065ceacb44eb
Pulse Author: CyberHunter_NL
Created: 2026-08-10 12:56:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SSH #Telegram #bot #CyberHunter_NL
-
OpenClaw и Hermes на одном VPS: чего стоит связать двух агентов безопасно
Поставил OpenClaw и Hermes на один VPS и связал их между собой: первый принимает задачи из Telegram, второй исполняет их в своей песочнице. Через час после установки обнаружил, что панель управления агентом открыта в интернет, а ещё через полчаса — что фаервола на сервере нет вообще. Хроника нескольких вечеров про то, чем ИИ-агент опасен на своём сервере и сколько стоит поставить его по-человечески. Читать, что сломалось
https://habr.com/ru/articles/1068762/
#OpenClaw #hermes #ииагенты #acp #vps #docker #ssh #ufw #openrouter #безопасность_сервера
-
Reviving a four year old reMarkable 2
https://oskrim.github.io/hardware/2026/08/09/remarkable-over-ssh.html
Comments: https://news.ycombinator.com/item?id=49230514
#HackerNews #reMarkable2 #techrevival #DIY #electronics #SSH #hacking
-
Reviving a four year old reMarkable 2
https://oskrim.github.io/hardware/2026/08/09/remarkable-over-ssh.html
Comments: https://news.ycombinator.com/item?id=49230514
#HackerNews #reMarkable2 #techrevival #DIY #electronics #SSH #hacking
-
Hab da mal was gebastelt... man hat am Wochenende ja nichts Besseres zu tun:
Secure Your Server
Zwei praktische Checks. Ein seriöser Sicherheitsbericht.
Prüfe eine Domain auf die Härtungsdetails, auf die Angreifer und Audits zuerst schauen. Teste danach, ob deine echten E-Mails sauber authentifiziert und zugestellt werden. Kein Konto, kein Tracking, keine Bezahlschranke.
Domain-Sicherheitsscan
Vollständige externe Sicht auf TLS/SSL, SSH, offene Ports, DNS, SPF, DKIM, DMARC, MTA-STS, HTTP-Security-Header, WHOIS und PGP/WKD.
Mail-Zustellungstest
Erzeuge eine einmalige Testadresse, schick eine Mail aus deinem Postfach und sieh SPF, DKIM, DMARC, TLS, rDNS, Spam-Signale und Zustellungsdetails.
Bugs, Verbesserungswünsche bitte an "hallo [at] chrislo.de"
Mehr Infos:
https://www.sichere-deinen-server.de/#chrislo #sys #secureyourserver #sicheredeinenserver #sicherheit #security #server #domain #tls #ssh
-
Hab da mal was gebastelt... man hat am Wochenende ja nichts Besseres zu tun:
Secure Your Server
Zwei praktische Checks. Ein seriöser Sicherheitsbericht.
Prüfe eine Domain auf die Härtungsdetails, auf die Angreifer und Audits zuerst schauen. Teste danach, ob deine echten E-Mails sauber authentifiziert und zugestellt werden. Kein Konto, kein Tracking, keine Bezahlschranke.
Domain-Sicherheitsscan
Vollständige externe Sicht auf TLS/SSL, SSH, offene Ports, DNS, SPF, DKIM, DMARC, MTA-STS, HTTP-Security-Header, WHOIS und PGP/WKD.
Mail-Zustellungstest
Erzeuge eine einmalige Testadresse, schick eine Mail aus deinem Postfach und sieh SPF, DKIM, DMARC, TLS, rDNS, Spam-Signale und Zustellungsdetails.
Bugs, Verbesserungswünsche bitte an "hallo [at] chrislo.de"
Mehr Infos:
https://www.sichere-deinen-server.de/#chrislo #sys #secureyourserver #sicheredeinenserver #sicherheit #security #server #domain #tls #ssh
-
Win of the day
I am currently thousands of kilometers from my homelab, and one of my nodes crashed. This cascaded into several services going down, including my auth provider (PocketID), so I couldn't log in from new devices
I recently installed a network enabled PDU into the rack, so I could log into its web interface by tunneling through various SSH hoops, but I never mapped which outlet goes to what host
I eventually could correspond the last node event in my k3s cluster with the consumption on one outlet, sent a reboot instruction, and the node came back up
Is it what I'm supposed to cross arms and say "Hackerman" ?
#homelab #selfhost #selfhosted #selfhosting #hackerman #ssh #outage #pocketid #k3s #kubernetes #pdu #remote #network #reboot
-
Win of the day
I am currently thousands of kilometers from my homelab, and one of my nodes crashed. This cascaded into several services going down, including my auth provider (PocketID), so I couldn't log in from new devices
I recently installed a network enabled PDU into the rack, so I could log into its web interface by tunneling through various SSH hoops, but I never mapped which outlet goes to what host
I eventually could correspond the last node event in my k3s cluster with the consumption on one outlet, sent a reboot instruction, and the node came back up
Is it what I'm supposed to cross arms and say "Hackerman" ?
#homelab #selfhost #selfhosted #selfhosting #hackerman #ssh #outage #pocketid #k3s #kubernetes #pdu #remote #network #reboot
-
Started looking for alternative tunneling methods for locally hosted services and found this list to be super helpful
#tunnel #https #ssh #selfhosting
https://github.com/anderspitman/awesome-tunneling -
Inside a Self-Propagating npm Worm
A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
Pulse ID: 6a75b2f415506d0a2374398b
Pulse Link: https://otx.alienvault.com/pulse/6a75b2f415506d0a2374398b
Pulse Author: AlienVault
Created: 2026-08-07 10:27:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #Encryption #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #RAT #SSH #Worm #bot #AlienVault
-
ChainDrop npm Attack Compromises Hundreds of Packages
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
Pulse ID: 6a7484b807f5882281629fae
Pulse Link: https://otx.alienvault.com/pulse/6a7484b807f5882281629fae
Pulse Author: AlienVault
Created: 2026-08-06 12:57:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Worm #bot #AlienVault
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.
Pulse ID: 6a72f4367f010bc9d645f5d1
Pulse Link: https://otx.alienvault.com/pulse/6a72f4367f010bc9d645f5d1
Pulse Author: AlienVault
Created: 2026-08-05 08:28:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault
-
Fake AI Tool Campaign Turns Developer Interest Into Enterprise Initial Access
Indicators extracted from public reporting. Source: https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer
Pulse ID: 6a71b783e18524e9a67a3110
Pulse Link: https://otx.alienvault.com/pulse/6a71b783e18524e9a67a3110
Pulse Author: CyberHunter_NL
Created: 2026-08-04 09:57:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #NET #Netskope #OTX #OpenThreatExchange #RCE #SSH #bot #developers #CyberHunter_NL
-
New Malware Wave: Arch Linux Blocks AUR Updates
Malware is once again spreading via Arch User Repositories. Therefore, there are no updates for AUR for the time being.