400
Never-before-seen Linux malware gets installed using 1-day exploits
(arstechnica.com)
This is a most excellent place for technology news and articles.
Did I miss the bit where they said how it was delivered?
Seems it's exploiting vulnerabilities in some software called "Ivanti Connect Secure VPN", so unless you're running that, you're safe I guess. Says in the past they used vulnerabilities in "Qlik Sense" and Adobe "Magento". Never heard of any of those, but I guess maybe some businesses use them?
My university has us use Ivanti to connect to our network from offsite...
These vpns seem to be quite a good target since at least the one my university uses is run as a setuid executable, so if there is a vulnerability in there, you can execute code as root that wasn't intended to be executed as root.
Hmmm... Nice, nice, that's nice,
Which university??