FortiGuard Labs is aware of a report that a new malware is designed to run in compromised AWS Lambda environments. Started in 2014, AWS Lambda is a serverless compute service of Amazon Web Services (AWS) and runs code as a response to events, which some refer to as Function as a Service (FaaS). Written in Go, Denonia malware contains and runs a customized version of the XMRig cryptocurrency mining software in memory.Why is this Significant?This is significant as Denonia appears to be the first malware that is crafted to run in AWS Lambda environments. Since AWS Lambda is widely used, another Lambda specific malware can emerge and potentially perform other malicious activities.How was Denonia Malware Deployed in AWS Lambda?The attack vector has not been identified. What is Denonia Malware Designed to Perform in AWS Lambda?Upon infection, Denonia executes XMRig miner in memory, and communicates with the attacker’s Mining pool.What is the Status of Coverage?FortiGuard Labs provide the following coverage against Denonia malware:Adware/MinerRiskware/ApplicationAll network IOCs are blocked by the WebFiltering client.
Category Archives: Advisories
frr-8.2.2-2.fc35
FEDORA-2022-3b86b4a6ef
Packages in this update:
frr-8.2.2-2.fc35
Update description:
Security fix for CVE-2022-26126.
frr-8.0.1-2.fc34
FEDORA-2022-c8c2e42934
Packages in this update:
frr-8.0.1-2.fc34
Update description:
Security fix for CVE-2022-26126.
frr-8.2.2-2.fc36
FEDORA-2022-376cb924bd
Packages in this update:
frr-8.2.2-2.fc36
Update description:
Security fix for CVE-2022-26126.
firefox-99.0-1.fc34 nss-3.77.0-1.fc34
FEDORA-2022-ea66694ce2
Packages in this update:
firefox-99.0-1.fc34
nss-3.77.0-1.fc34
Update description:
Update to latest upsream (Firefox 99.0 & nss 3.77)
firefox-99.0-1.fc35 nss-3.77.0-1.fc35
FEDORA-2022-3781e69ebd
Packages in this update:
firefox-99.0-1.fc35
nss-3.77.0-1.fc35
Update description:
Update to latest upstream (Firefox 99.0 & nss 3.77).
USN-5331-2: tcpdump vulnerabilities
USN-5331-1 fixed several vulnerabilities in tcpdump. This update provides
the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that tcpdump incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2018-16301)
It was discovered that tcpdump incorrectly handled certain captured data.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2020-8037)
CVE-2021-32156
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CVE-2021-32157
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CVE-2021-32158
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.