Sudo Security Update Advisory (CVE-2025-32463)

Sudo Security Update Advisory (CVE-2025-32463)

Overview   we have released a security update that addresses a vulnerability in sudo. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-32463   Sudo Versions: 1.9.14 and above and 1.9.17p1 and below     Resolved Vulnerabilities   Root privilege escalation vulnerability

Analysis of Attacks Targeting Linux SSH Servers for Proxy Installation

Analysis of Attacks Targeting Linux SSH Servers for Proxy Installation

AhnLab SEcurity intelligence Center (ASEC) monitors attacks targeting Linux servers that are inappropriately managed using honeypots. One of the representative honeypots is the SSH service that uses weak credentials, which is targeted by a large number of DDoS and coinminer attackers. ASEC has identified cases where Linux servers were attacked

AhnLab Detection Information on BPFDoor Exploited in Recent Hacking Attacks and KISA Hash Notice

AhnLab Detection Information on BPFDoor Exploited in Recent Hacking Attacks and KISA Hash Notice

BPFDoor is a Linux-based backdoor malware. AhnLab previously published their EDR detection information on this malware through the ASEC blog in October 2024. KISA recently shared threat information and warnings on BPFDoor, which has been exploited in hacking attacks. V3 detection information on the hash values shared by KISA in

Linux Kernel Security Update Advisory (CVE-2025-21756)

Linux Kernel Security Update Advisory (CVE-2025-21756)

Overview   We have released a security update to address a vulnerability in the Linux kernel. Affected product users are advised to update to the latest version.    Affected Products   CVE-2025-21756 Linux Kernel Versions: 6.6.79 and earlierLinux Kernel Versions: 6.12.16 and earlierLinux Kernel Version: 6.13.4 and earlierLinux Kernel Version:

Linux Kernel Security Update Advisory

Linux Kernel Security Update Advisory

Overview   We have released a security update to address a vulnerability in the Linux kernel. Affected product users are advised to update to the latest version.    Affected Products     CVE-2024-53197, CVE-2024-53150   Linux Kernel Versions: 4.19.325 and earlierLinux Kernel Version: 5.4.287 and earlierLinux Kernel Version: 5.10.231 and

cShell DDoS Bot Attack Case Targeting Linux SSH Server (screen and hping3)

cShell DDoS Bot Attack Case Targeting Linux SSH Server (screen and hping3)

AhnLab SEcurity intelligence Center (ASEC) monitors attacks against poorly managed Linux servers using multiple honeypots. Among the prominent honeypots are SSH services using weak credential information, which are targeted by numerous DDoS and CoinMiner threat actors. ASEC recently identified a new DDoS malware strain targeting Linux servers while monitoring numerous

BPFDoor Linux Malware Detected by AhnLab EDR

BPFDoor Linux Malware Detected by AhnLab EDR

BPFDoor is a backdoor using the Berkeley Packet Filter (BPF), first revealed through a threat report by PWC in 2021 [1]. According to the report, the China-based threat actor Red Menshen has been using BPFDoor for several years in attacks targeting the Middle East and Asia regions, with its source

Linux Persistence Techniques Detected by AhnLab EDR (1)

Linux Persistence Techniques Detected by AhnLab EDR (1)

Persistence techniques refer to methods employed by threat actors to maintain a connection to the target system after infiltration. As a single breach may not be enough to achieve all their goals, threat actors look for ways to re-access the system. Persistence can be maintained by configuring the malware to

Linux Kernel Security Update Advisory

Overview An update has been made available to address a vulnerability in the Linux Kernel....

Linux Defense Evasion Techniques Detected by AhnLab EDR (2)

Linux Defense Evasion Techniques Detected by AhnLab EDR (2)

The blog post “Linux Defense Evasion Techniques Detected by AhnLab EDR (1)” [1] covered methods where the threat actors and malware strains attacked Linux servers before incapacitating security services such as firewalls and security modules and then concealing the installed malware. This post will cover additional defense evasion techniques against