SHARE
Facebook X Pinterest WhatsApp

Linux.com, Linux Foundation Hit by Hackers

A week after uncovering malware on several key kernel.org servers, the Linux Foundation has taken other key Websites, including Linux.com, offline for a complete reinstall. Linux.com, LinuxFoundation.org and all sub-domains associated with these sites were taken offline after administrators discovered “a security breach” on Sept. 8, according to an email sent to all registered members […]

Sep 13, 2011
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A week after uncovering malware on several key kernel.org servers, the Linux Foundation has taken other key Websites, including Linux.com, offline for a complete reinstall.

Linux.com, LinuxFoundation.org and all sub-domains associated with these sites were taken offline after administrators discovered “a security breach” on Sept. 8, according to an email sent to all registered members of the sites on Sept. 11. The servers will be completely reinstalled and will be back online “as they become available,” Linux Foundation wrote.

This information was also posted on a holding page on all the affected sites.

The username, password, email address and “other information” provided by users registered with the sites may have been stolen, according to the disclosure email. Any passwords or SSH keys used on those sites should be considered compromised, and the foundation recommended that if any of the passwords had been reused elsewhere, that users should change them immediately.

“We believe this breach was connected to the intrusion on kernel.org,” Linux Foundation said in the email.

Linux Organization officials discovered on Aug. 28 that attackers had installed a Trojan and opened a backdoor into kernel.org servers on Aug. 12. The attackers had logged user activity and modified the OpenSSH client and server software installed on the compromised server, but had not gained access to the Linux kernel source code or other applications. The Trojan discovered on kernel.org was based on an “off-the-shelf” rootkit called Phalanx.

The security breach is not just about information theft as it involves a malware compromise, Paul Ducklin, head of technology for the Asia Pacific group at Sophos, wrote on the Naked Security blog. “If a server is ‘owned’ by malware, even the login process should be considered untrustworthy,” Ducklin wrote, noting that malware could steal passwords directly from memory at the time of the actual login by a user.

The pattern of activity by the intruders on kernel.org led observers to speculate that the attackers did not really understand the significance of the servers they’d breached and were unable to capitalize on the attack. If the latest breaches are related to kernel.org and had occurred around the same time, the attacks appear to be even more widespread than originally thought. 

These breaches have no impact on the Linux kernel or any other projects’ source codes as none of the compromised sites are related to software development. The Linux Foundation is a not-for-profit organization which funds Linux development so that the developers remain independent of any particular vendor or commercial group. Linux.com is the news, information and community site for people interested in the operating system and LinuxFoundation.org provides information on the foundation’s activities. The sub-domains, such as the Linux Developer Network and the video site, are also used for disseminating information.

To read the original eWeek article, click here: Linux Foundation, Linux.com Hacked in Kernel.com Breach

Recommended for you...

SailPoint Intros Accelerated Application Management Solution
Jordan Smith
Aug 22, 2025
ConnectWise Partners with Proofpoint on Security in Asio
Jordan Smith
Aug 22, 2025
RegScale CRO on Channel Growth in Risk & Compliance
Victoria Durgin
Aug 22, 2025
Manny Rivelo on Evolving Channel & How MSPs Can Get Ahead
Victoria Durgin
Aug 20, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.