Thousands of machines running Linux have been infected by a malware strain that’s notable for its stealth, the number of misconfigurations it can exploit, and the breadth of malicious activities it can perform, researchers reported Thursday.

The malware has been circulating since at least 2021. It gets installed by exploiting more than 20,000 common misconfigurations, a capability that may make millions of machines connected to the internet potential targets, researchers from Aqua Security said. It can also exploit CVE-2023-33426, a vulnerability with a severity rating of 10 out of 10 that was patched last year in Apache RocketMQ, a messaging and streaming platform that’s found on many Linux machines.

  • Asidonhopo@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    edit-2
    27 days ago

    I was reading about this a couple days ago. With the wider adoption of Linux these days, is there an easy solution to scan for a way to eliminate this for the less experienced end user?