Tux Machines

FUD and Security

Posted by Roy Schestowitz on Jul 13, 2023

=> Programming Leftovers | Kernel Articles in LWN: NFSD, 6.5 Release, and More

Hackers use Rekoobe Backdoor to Attack Linux Systems [Ed: The issue here is bad configurations, not Linux, and they focus too much on what's done to already-compromised systems, not the means or cause of compromise]

=> ↺ Hackers use Rekoobe Backdoor to Attack Linux Systems

Rekoobe is a notorious backdoor that primarily targets Linux environments, and it’s actively exploited by the threat actors, mainly a Chinese threat group, APT31.
This notorious backdoor was discovered in 2015 for the first time, while an updated version of it resurfaced in 2018 that was exploited by the threat actors in several attacks.

Security updates for Wednesday [LWN.net]

=> ↺ Security updates for Wednesday [LWN.net]

Security updates have been issued by Debian (erlang, symfony, thunderbird, and yajl), Fedora (cutter-re, kernel, rizin, and yt-dlp), Red Hat (grafana), SUSE (kernel and python-Django), and Ubuntu (dotnet6, dotnet7 and firefox).

Two Teens Accused of Masterminding Hacks on Grand Theft Auto and Uber

=> ↺ Two Teens Accused of Masterminding Hacks on Grand Theft Auto and Uber

Two UK teenagers were accused of being key members of the notorious hacking group Lapsus$, with prosecutors alleging that the pair were involved in hacks on companies including Nvidia Corp., Rockstar Games Inc., and Uber Technologies Inc.
Arion Kurtaj, 18, and a 17-year-old boy, who can’t be named for legal reasons, were hit with joint charges including serious computer misuse, blackmail and fraud against BT Group Plc, and Nvidia.

Russian hackers lured embassy workers in Ukraine with ad for a cheap BMW

=> ↺ Russian hackers lured embassy workers in Ukraine with ad for a cheap BMW

Hackers suspected of working for Russia’s foreign intelligence agency targeted dozens of diplomats at embassies in Ukraine with a fake used car advert in a bid to break into their computers, according to a cybersecurity firm report published on Wednesday.
The wide-reaching espionage activity targeted diplomats working in at least 22 of the roughly 80 foreign missions in Ukraine’s capital, Kyiv, analysts at Palo Alto Networks’ Unit 42 research division said in the report.

UK: Man jailed for more than three years for attempting to extort money from the company he worked for [Ed: British police can hold people accountable when it punishes not a corporation but an individual.]

=> ↺ UK: Man jailed for more than three years for attempting to extort money from the company he worked for | ↺ punishes not a corporation but an individual

A 28-year-old man who tried to extort money from the company he worked for has been jailed for three years and seven months.
At Reading Crown Court today (11/7) Ashley Liles, of Fleetwood, Letchworth Garden City, Hertfordshire, was sentenced for blackmail and unauthorised access to a computer with intent to commit other offences.

Former Security Engineer For International Technology Company Arrested For Defrauding Decentralized Cryptocurrency Exchange

=> ↺ Former Security Engineer For International Technology Company Arrested For Defrauding Decentralized Cryptocurrency Exchange

Damian Williams, the United States Attorney for the Southern District of New York, Chad Plantz, the Special Agent in Charge of the San Diego Field Office of Homeland Security Investigations (“HSI”), and Tyler Hatcher, the Special Agent in Charge of the Los Angeles Field Office of the Internal Revenue Service – Criminal Investigation (“IRS-CI”), announced the unsealing of an Indictment charging SHAKEEB AHMED with wire fraud and money laundering in connection with his attack on a decentralized cryptocurrency exchange (the “Crypto Exchange”). AHMED was arrested this morning in New York, New York, and will be presented this afternoon before U.S. Magistrate Judge Robert W. Lehrburger.

Australian infrastructure company Ventia hit with cyberattack

=> ↺ Australian infrastructure company Ventia hit with cyberattack

The Australian infrastructure services provider Ventia is dealing with a cyberattack that began this weekend.
On Saturday, the company said it identified a cyber intrusion and took some “key systems” offline to contain the incident. It did not respond to requests for comment about whether it is a ransomware attack, but taking systems offline is an action typically taken in response to such an incident.

=> gemini.tuxmachines.org

Proxy Information
Original URL
gemini://gemini.tuxmachines.org/n/2023/07/13/FUD_and_Security.gmi
Status Code
Success (20)
Meta
text/gemini;lang=en-GB
Capsule Response Time
139.426944 milliseconds
Gemini-to-HTML Time
1.136405 milliseconds

This content has been proxied by September (ba2dc).