ssh

Back Open Paginator
27.02.2026 10:32
techbot (@techbot@social.raytec.co)

Malicious Go 'crypto' Module Steals Passwords and Deploys Rekoobe Backdoor

A malicious Go module impersonating the legitimate golang.org/x/crypto has been discovered, containing a backdoor in ssh/terminal/terminal.go. This module captures passwords, exfiltrates them, and executes remote commands. The attack chain includes a Linux stager that installs an SSH key for persistence, weakens firewall settings, and deploys a Rekoobe backdoor. The campaign targets high-trust cryptography libraries and likely aims at cloud environments. The threat actor uses GitHub for staging and disguises payloads as media files. This sophisticated supply chain attack highlights the need for careful scrutiny of Go module changes and implementation of robust security measures in development workflows.

Pulse ID: 69a1276fbef301b2eb97cd94
Pulse Link: otx.alienvault.com/pulse/69a12
Pulse Author: AlienVault
Created: 2026-02-27 05:11:11

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Cloud #CyberSecurity #GitHub #Golang #InfoSec #Linux #OTX #OpenThreatExchange #Password #Passwords #RAT #Rust #SSH #SupplyChain #Word #bot #AlienVault




Show Original Post


27.02.2026 05:21
kkarhan (@kkarhan@infosec.space)

@iron_bug @torproject @ooni @limping Okay, I've looked into this...

I guess the only working option is to basically look like Russian Cybercrime [hacking foreign corpos for ransom] and setup your own custom #SSH tunnels and #TorBridges

en.wikipedia.org/wiki/Toosheh
netfreedompioneers.org/toosheh
netfreedompioneers.org/knapsac




Show Original Post


26.02.2026 23:15
forumuu (@forumuu@nerdculture.de)

Serverdienste und Dateifreigaben im Netzwerk

Nextcloud Client
forum.ubuntuusers.de/topic/nex
26.02.2026 um 23:06 Uhr

#ubuntuusers #forumuu #linux #opensource #fragenistmenschlich #netzwerk #network #server #webserver #ssh #mysql #nfs #samba #vnc #vpn




Show Original Post


26.02.2026 23:11
jbz (@jbz@indieweb.social)

snakes.run: rendering 100M pixels a second over ssh · eieio.games

eieio.games/blog/secure-massiv

#gamedev #tui #ssh




Show Original Post


26.02.2026 18:50
brunobord (@brunobord@dice.camp)

oh my god this is so cool

$ ssh snakes.run

#ssh #game #snakes




Show Original Post


26.02.2026 16:24
royalapps (@royalapps@dotnet.social)

Tired of Managing Multiple Remote Sessions manually? Here’s the Fix 💡 Read more under: royalapps.com/go/help-ts-win-v

#devops #itadmin #terminalservices #RDP #remotedesktop #ssh





Show Original Post


26.02.2026 13:43
Karcsesz (@Karcsesz@equestria.social)

Today on "How is this the state of the art!?": ssh-agent

I just learned that you may get locked out of your server due to too many authentication requests because the ssh-agent protocol has zero provisions for prefiltering keys and just blindly tries everything in your database until one of them goes through.

Is there a security reason why ssh can't send the host's hash to the agent to tell it what server it should return the key for?

#sshAgent #ssh




Show Original Post


26.02.2026 09:30
greve (@greve@floss.social)

#Veritasium did a video on how #SSH almost became compromised by #XZ, and along the way in a really easy to understand yet precise way explains so many things about the software freedom community that I am truly impressed.

Deserves to be shared widely:

youtube.com/watch?v=aoag03mSuXQ




Show Original Post


25.02.2026 17:56
pitrh (@pitrh@mastodon.social)

Friends,

It feels like it was in a different century, but at the beginning of the -#ukraine full scale war I speculated that you could predict development in conflict based on the intensity of attempted , see nxdomain.no/~peter/Predicting_. The data now covers four years.

I ponder whether it's worth using the data (linked in the article) to see how these things correlate.

I'd love to hear your thoughts.




Show Original Post


25.02.2026 11:44
Radio_Azureus (@Radio_Azureus@ioc.exchange)

Thirty years of curl

Curl is for me part of the critical tools in any POSIX OS. Even in closed source OS like win64 curl is vital.

My gratitude is infinite

curl --verbose wttr.in/palmentuin|lolcat

...gets me such nice formatted output to (ba cs k z)sh

100% pure shell output, no browser needs to be spawned for that!

Curl usage

curl is used in command lines or scripts to transfer data. curl is also libcurl, used in cars, television sets, routers, printers, audio equipment, mobile phones, tablets, medical devices, settop boxes, computer games, media players and is the Internet transfer engine for countless software applications in over twenty billion installations.

curl is used daily by virtually every Internet-using human on the globe!

sources:

curl.se/
ioc.exchange/@bagder@mastodon.

#curl #critical #program #birthday #congratulations #30years #fun #jokes #OpenSource #POSIX #programming #networking #protocols #TCP #SSH




Show Original Post


25.02.2026 00:51
ricci (@ricci@discuss.systems)

My student Ghazal gave a talk at the PRISM workshop (attached to #NDSS) yesterday! She has done some really nice work on classifying #ssh brute-force attackers using clustering techniques. The full paper and slides are up at: flux.utah.edu/paper/abdollahi-




Show Original Post


25.02.2026 00:23
kkarhan (@kkarhan@infosec.space)

@iuvi this seems like a good way to do it at first glance.

I'd still recommend to use @torproject / #TorBrowser through that #SSHtunnel for added #privacy.

Still #Russia fighting against #VPN useage whilst also being reliant on #CyberCrime & #CyberWarfare from russian soil makes it basically impossible to ban #SSH.




Show Original Post


1 ...15 16 17 18 19 20 21 22 23 24 25 ...55
UP