Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -3 articles for you...
209

Exploring Linux’s Security Amid Increasing Cyber Threats and Malware

The OS enjoys a reputation for enhanced security. That might change as cyberattacks surge against Linux-based products and services. . Ransomware gangs are renowned for infighting. They squabble, they attack each other; they form alliances and desert them just as quickly. The results of this internecine conflict are often fruitful for cybersecurity researchers: take, for example, the leaking of malware code from Babuk, hacked in 2021 by cybercriminals disgruntled at being cheated by the notorious ransomware gang. The code was subsequently deployed by 10 additional ransomware gangs to garget VMware and ESXI servers, and spawned a string of variants that researchers have been busily patching ever since. What was interesting about this particular family of malware, however, was that it targeted the Linux operating system – a fast favourite of developers involved in building virtual machines in cloud-based web systems, web hosting for live websites or IoT devices. Its use has spiked in recent years, with an estimated 14 million internet-facing devices running on Linux on any given day, in addition to 46.5% of the top million websites by traffic and a whopping 71.8% of IoT devices. That’s great news for advocates of open-source software development, for which Linux has always been an example of what can be achieved when coding communities collaborate unencumbered by anything as vile as a corporate culture or a profit motive. It’s also thoroughly frightening for some cybersecurity experts. Not only is there a marked lack of ongoing research into the security of Linux-based systems as opposed to those based off more mainstream operating systems, but also no formal, overarching system for patching the vulnerabilities in this OS. Instead, as befits an open-source creation, ‘flavours’ of Linux are patched on an ad-hoc basis by developers with time and intellect to spare – a precious resource amid a veritable tsunami of cybercrime. Attackers are starting to notice. Lastyear, AtlasVPN found that over 1.9 million new malware threats had been detected – a year-on-year increase of 50%. . With rising cyber threats, the legendary defenses of Linux now seem at risk. Explore the rise of malware targeting Linux and the dangers it brings. Linux Security Threats,Cybercrime Trends,Ransomware Attacks. . Brittany Day

Calendar%202 Jun 27, 2023 User Avatar Brittany Day Security Trends
74

Network Driver Advisory: Critical Info Leakage Threat Identified

Security researchers at the firm @stake say they've found a flaw in how network device drivers send information that could create an "information leakage vulnerability" that may let hackers collect sensitive information sent from vulnerable devices. If successful, @stake says, hackers . . . . Security researchers at the firm @stake say they've found a flaw in how network device drivers send information that could create an "information leakage vulnerability" that may let hackers collect sensitive information sent from vulnerable devices. If successful, @stake says, hackers potentially could view "slices of previously transmitted packets or portions of kernel memory" over certain networks. The CERT Coordination Center has posted a long list (http://www.kb.cert.org/vuls/id/412115) of network vendors' products that could be vulnerable to the flaw. However, as of now, the majority of vendors haven't disclosed whether their device drivers are at risk. So far, Cisco Systems, F5 Networks, Hitachi, Microsoft, and NEC have reported that they're not vulnerable. According to @stake's advisory, the software and hardware vendors were notified of the potential flaw in June 2002. According to CERT, no statement concerning this vulnerability is yet available from more than 40 of the vendors notified more than six months ago. The link for this article located at CommWeb is no longer available. . Investigators have uncovered a vulnerability in network interface software that could expose confidential data, increasing the threat of unauthorized access to private details.. Information Leakage, Network Vulnerability, Device Driver Flaws, Data Exposure, Cybersecurity Advisory. . Anthony Pell

Calendar%202 Jan 08, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200