As much as I loathe m$, the one thing they got right was forcing casual users (windows home) to install security updates as top priority, whether they like it or not. I know we all hate on windows, and rightly so, but that policy does nullify this particular vector and that is great for the consumer-level users.
(... for the sake of argument lets just pretend windows doesnt have 10,000 other vulns the malware devs can just exploit instead)
Also keep in mind that the main reason Windows is targeted for so many exploits is because of the consumer market share. If Linux consumer market share goes up, so will general malware targeting it. We already saw it happen when OSX share increased and Apple had to abandon the whole "Macs don't get viruses" schtick.
We already saw it happen when OSX share increased and Apple had to abandon the whole "Macs don't get viruses" schtick.
It's kinda crazy that Apple got away with spinning "Our products don't sell well enough for this to be a problem" into a marketing point for as long as they did.
Linux has had a long history of worms and viruses, fortunately (sorta) thanks to its server legacy. Dumb and lazy server admins have given it pretty good 'secure by default' behaviours and cultures.
Desktop users though: whole different set of challenges.
I mean, I don't think I would mind forced updates if they didn't take so damned long and fail half the time. And then, just when you think you've finished installing all updates, you reboot and there's more updates! Why can't they just install it all at once?
Plus, after each major update, Microsoft wastes your time by advertising to you about Edge, Office 365, and OneDrive before they even let you get back into the desktop.
Forced security updates is addressing a symptom but not addressing the root cause, which is that the Windows update process is just painful for a myriad of reasons. In Linux, I run one command, wait 5 minutes, reboot, and I am back to work.
Linux has good security updates too. Fedora installs pending updates on restart, and I believe flatpaks are updated automatically in the background.
The virus discussed in the article doesn't affect Linux PCs, only servers. Windows-style forced reboots wouldn't make sense in a server environment, and it's up to the server administrators to implement good update policies for their nodes and containers.
I am aware, it's just a relevant and closely related observation about consumer OSes. You make good points. A professional server admin > automstic updates (most of the time...)
Seems it's exploiting vulnerabilities in some software called "Ivanti Connect Secure VPN", so unless you're running that, you're safe I guess. Says in the past they used vulnerabilities in "Qlik Sense" and Adobe "Magento". Never heard of any of those, but I guess maybe some businesses use them?
So its spreading via a closed source VPN software. Why should you even use that when there is great VPN software available on Linux which works reliable for decades?
Well of course you miss zero trust connections, multi-cloud readiness, award‑winning security and proven secure corporate access ...
Researchers have unearthed Linux malware that circulated in the wild for at least two years before being identified as a credential stealer that’s installed by the exploitation of recently patched vulnerabilities.
Last Friday, Checkpoint Research revealed that the Linux version has existed since at least the same year, when it was uploaded to the VirusTotal malware identification site.
Checkpoint went on to conclude that Magnet Goblin—the name the security firm uses to track the financially motivated threat actor using the malware—has installed it by exploiting “1-days,” which are recently patched vulnerabilities.
“Magnet Goblin, whose campaigns appear to be financially motivated, has been quick to adopt 1-day vulnerabilities to deliver their custom Linux malware, NerbianRAT and MiniNerbian,” Checkpoint researchers wrote.
In the past, Magnet Goblin has installed the malware by exploiting one-day vulnerabilities in Magento, Qlink Sense, and possibly Apache ActiveMQ.
In the course of its investigation into the Ivanti exploitation, Checkpoint found the Linux version of NerbianRAT on compromised servers that were under the control of Magnet Goblin.
The original article contains 453 words, the summary contains 168 words. Saved 63%. I'm a bot and I'm open source!
Actually, that's pretty much it. According to the article, it attacks a specific piece of ecommerce software (Magento), and I get the impression the attack isn't viable if the software has all the latest fixes. So it's dangerous only to a subset of servers.