Linux distributor Red Hat has issued a critical security update after its servers were hacked last week.
“In connection with the incident, the intruder was able to get a small number of OpenSSH packages relating only to Red Hat Enterprise Linux 4 (i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64 architecture only) signed.
“As a precautionary measure, we are releasing an updated version of these packages and have published a list of the tampered packages and how to detect them. To reiterate, our processes and efforts to date indicate that packages obtained by Red Hat Enterprise Linux subscribers via Red Hat Network are not at risk.”
It seems the hacker or hackers were more intent on getting software signed off than infiltrating Red Hat’s deployment system, which may have allowed them to insert malware into all future deployments if undetected.
The Fedora hack seems more serious, and the organisation has called on system administrators to update their system with new keys.
“While there is no definitive evidence that the Fedora key has been compromised, because Fedora packages are distributed via multiple third-party mirrors and repositories, we have decided to convert to new Fedora signing keys,” it said
“This may require affirmative steps from every Fedora system owner or administrator.”
Red Hat has not disclosed the specific vulnerability that allowed the intrusion onto its systems.
Cotton seedling freezes to death as Chang'e-4 shuts down for the Moon's 14-day lunar night
Fortnite easily out-earns PUBG, Assassin's Creed Odyssey and Red Dead Redemption 2 in 2018
Meteor showers as a service will be visible for about 100 kilometres in all directions
Saturn's rings only formed in the past 100 million years, suggests analysis of Cassini space probe data
New findings contradict conventional belief that Saturn's rings were formed along with the planet about 4.5 billion years ago