Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
83

Adobe Flash Player Critical Advisory: Email Exploit Attack Detected

An Adobe security advisory warns of a new critical vulnerability in Flash Player 10.2.153.1 for Windows, Macintosh, Linux and Solaris, Flash Player 10.2.156.12 for Android and the Authplay.dll component in Adobe Reader and Acrobat X 10.0.2 and all earlier versions. . There are already reports that the vulnerability is being exploited using crafted .swf files embedded in Microsoft Word .doc files which are sent as an email attachment. The vulnerability can, when exploited appropriately, allow an attacker to take control of a system. The Krebs on Security blog reports that the vulnerability has been used as part of a targeted spear-phishing campaign disguised as important government documents and launched against organisations or individuals who work for the US government. Another example of the attack shows an email with a title of "Disentangling Industrial Policy and Competition Policy In China" with a supposed copy of an article on that subject attached. The link for this article located at H Security is no longer available. . There are already reports that the vulnerability is being exploited using crafted .swf files embedde. adobe, security, advisory, warns, critical, vulnerability, flash, player. . LinuxSecurity.com Team

Calendar%202 Apr 12, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Adobe Reader X Launch: Enhanced Sandbox Security for PDFs

Adobe has released the next-generation version of its Reader software that includes a protected mode to prevent attacks through PDF files. The release of Adobe Reader X on Windows follows closely behind Adobe Acrobat X.. Both products include the protected mode, which uses a sandbox approach to prevent hacker attacks and has been built with input from business users and from across the software industry, including Microsoft and Google. The security initiatives are aimed at reducing both the frequency and the impact of security vulnerabilities, said Adobe.. Adobe Acrobat Pro DC integrates an advanced safety feature employing isolation techniques to improve document protection for its users.. Adobe Reader X, Secure PDF, Sandbox Features, Enhanced Security. . LinuxSecurity.com Team

Calendar%202 Nov 19, 2010 User Avatar LinuxSecurity.com Team Vendors/Products
83

Adobe Reader Threat - ZeuS Bot Exploit Poses Risk to Windows Users

According to several reports by anti-virus vendors, criminals have attempted to exploit an unpatched hole in Adobe Reader disclosed about two weeks ago to infect Windows PCs. The relevant malware includes the particularly dangerous ZeuS bot. The specially crafted documents are apparently sent to users as email attachments.. The "Launch Actions/Launch File" function in Adobe Reader allows the execution of scripts or EXE files embedded in PDFs. Although Adobe Reader asks users to agree to the execution of the file, this dialogue can be designed in such a way that users have no idea they may be allowing an infection in to their systems. Sophos have posted a demo which tries to persuade users to click an OK button on their blog. A report from M86Security describes a PDF document that tries to install the ZeuS bot. When opened, the document tries to save a further PDF document which contains the actual malware. The documents are probably nested in an attempt to trick virus scanners. Interestingly, Reader opens a user dialogue before saving the file, but Foxit automatically saves the file without requesting confirmation. The current version of Foxit at least opens a dialogue when trying to start the bot that is hidden in the PDF The link for this article located at H Security is no longer available. . Malware exploits unpatched Adobe Reader flaw, allowing execution of harmful scripts and exposing Windows users to threats.. Adobe Reader, malware exploit, Windows security. . LinuxSecurity.com Team

Calendar%202 Apr 16, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Adobe Reader PDF Security Risks from Executable Exploits Unveiled

A security researcher has demonstrated a mechanism that exploits PDF files without taking advantage of any particular vulnerabilities. Didier Stevens' proof of concept exploit relies on running an executable embedded in a PDF file - something that ought to be blocked - by launching a command that ultimately runs an executable.. In the case of Adobe Reader, such attempted launches generate a pop-up dialog box asking users if they want to proceed. However, this is not necessarily a major hurdle because Stevens was also able to manipulate the text displayed by the pop-up in a way that might easily fool most users. "With Adobe Reader, the only thing preventing execution is a warning," Stevens explains. "Disabling JavaScript will not prevent this, and patching Adobe Reader isn The link for this article located at The Register UK is no longer available. . Investigation into Adobe Reader exploits shows how embedded executables can mislead users and bypass protections effectively.. Adobe Reader Risks, PDF Security Exploits, Malicious PDF Files. . LinuxSecurity.com Team

Calendar%202 Apr 06, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Adobe Reader 45 Bugs Found: Key Cyber Threat Insights 2023

At the beginning of this decade, Microsoft represented a cybercriminal's dream target: universally-used software, brimming with bugs ready to be exploited to hijack users' PCs. But as the software giant has slowly cleaned up its security flaws, hackers are looking toward another vendor whose products are nearly as ubiquitous and whose bounty of vulnerabilities are just being discovered: Adobe.. According to Verisign's bug tracking division iDefense, 45 bugs in Adobe's ( ADBE - news - people ) Reader software were found by either cybersecurity researchers or malicious hackers this year and patched. In 2008, iDefense found 14 Reader bugs, double the number in 2007. Meanwhile, the number of bugs found in commonly-used Microsoft ( MSFT - news - people ) programs like Internet Explorer, Windows Media Player and Microsoft Office remained flat or dropped. Just 30 bugs were exposed in Internet Explorer compared with the same number last year, and 41 bugs were found in all of Microsoft's Office programs like PowerPoint, Word and Excel, down from 44 in 2008. When Forbes asked a group of cybersecurity researchers from security firms Tipping Point, iDefense and Qualys to name software programs with vulnerabilities most often used by hackers to victimize users' PCs this year, every one included Adobe Reader on their list. "It's a huge focus for attacks now, around 10 times more than Microsoft Office," says Wolfgang Kandek, chief technology officer at Qualys, a vulnerability scanning firm. The link for this article located at Alibaba is no longer available. . According to Verisign's bug tracking division iDefense, 45 bugs in Adobe's ( ADBE - news - people ) . beginning, decade, microsoft, represented, cybercriminal's, dream, target, universally-u. . LinuxSecurity.com Team

Calendar%202 Dec 11, 2009 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Adobe Reader 6.0.1 and 7.0.8 Critical: Exploit Cross-Site Scripting Risk

Adobe confirmed reports of serious flaws in its popular .pdf viewer Thursday and urged users to upgrade to the latest version without delay. . "Adobe is aware of the recent cross-site scripting vulnerability in versions 7.0.8 and earlier of Adobe Reader and Adobe Acrobat that could allow remote attackers to inject arbitrary JavaScript into a browser session," the vendor said in an emailed statement. "This is not a vulnerability in .pdf. Specifically, this issue could occur when a user clicks on a malicious link to a .pdf on the Web." While the latest version fixes the flaws, Adobe said it would also release patches next week for the older, vulnerable versions. Security experts have expressed alarm over the flaws, discovered by vulnerability researchers Stefano Di Paola and Giorgio Fedon. They warned that attackers could easily exploit the vulnerabilities to launch cross-site scripting attacks and do a variety of damage. Experts are particularly concerned because Adobe Reader is used by a huge segment of the computing population. According to the researchers' analysis, the trouble is in how Adobe tells the browser to handle .pdf files. Firefox and Internet Explorer are particularly vulnerable. The flaws affect Adobe Reader 6.0.1 for Windows via Internet Explorer 6 and version 7.0.8 for Windows via Firefox 2.0.0.1. Other versions may also be affected, warned Danish vulnerability clearinghouse Secunia. Though Adobe has fixed the security holes in version 8.0.0, experts worry that many users will be slow to upgrade, leaving themselves open to an easy attack. Adobe sought to raise awareness with its advisory yesterday. Regardless of the latest flaws, Adobe said users should always be cautious when clicking on links from unknown or even trusted sources. Cupertino, Calif.-based antivirus giant Symantec Corp. stressed the significance of the flaws in its blog this week. The vendor said that: * The ease in which they can be exploited is "breathtaking." Use of the feature in question requiresno exploitation of vulnerabilities on the server side. * Any Web site that hosts a .pdf file can be used to conduct an attack. "All the attacker has to do is find out who is hosting a .pdf file on their Web server and then piggy back on it to mount an attack," the Cupertino, Calif.-based vendor said. "What this means, in a nutshell, is that anybody hosting a .pdf file, including well-trusted brands and names on the Web, could have their trust abused and become unwilling partners in crime." * Due to the power and flexibility of JavaScript, the attacker has a wide scope for inflicting damage. The link for this article located at Search Security.com is no longer available. . Microsoft alerts customers about vulnerabilities in Windows Defender and advises prompt updates to protect against potential threats.. Adobe Reader, Cross-Site Scripting, Remote Exploit. . LinuxSecurity.com Team

Calendar%202 Jan 10, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200