Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 12 articles for you...
83

Enemybot Botnet Exploits Web Servers and Android Devices Effectively

A nascent Linux-based botnet named Enemybot has expanded its capabilities to include recently disclosed security vulnerabilities in its arsenal to target web servers, Android devices, and content management systems (CMS). . "The malware is rapidly adopting one-day vulnerabilities as part of its exploitation capabilities," AT&T Alien Labs said in a technical write-up published last week. "Services such as VMware Workspace ONE, Adobe ColdFusion, WordPress, PHP Scriptcase and more are being targeted as well as IoT and Android devices." First disclosed by Securonix in March and later by Fortinet, Enemybot has been linked to a threat actor tracked as Keksec (aka Kek Security, Necro, and FreakOut), with early attacks targeting routers from Seowon Intech, D-Link, and iRZ. The link for this article located at The Hacker News is no longer available. . Malware network targeting web platforms, iOS gadgets, and content management systems through newly uncovered security gaps.. Enemybot Botnet, Android Exploitation, Web Server Threats, CMS Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jun 01, 2022 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Spearphone Attack On Android: Capture Loudspeaker Data Unnoticed

Have you heard about Spearphone, a newly demonstrated attack that takes advantage of a hardware-based motion sensor, called an accelerometer, which comes built into most Android devices and can be unrestrictedly accessed by any app installed on a device even with zero permissions? . Earlier this month, The Hacker News covered a story on research revealing how over 1300 Android apps are collecting sensitive data even when users have explicitly denied the required permissions. The research was primarily focused on how app developers abuse multiple ways around to collect location data, phone identifiers, and MAC addresses of their users by exploiting both covert and side channels. Now, a separate team of cybersecurity researchers has successfully demonstrated a new side-channel attack that could allow malicious apps to eavesdrop on the voice coming out of your smartphone's loudspeakers without requiring any device permission. The link for this article located at The Hacker News is no longer available. . Recent investigations reveal a vulnerability enabling applications to record audio from device speakers without explicit user consent, jeopardizing personal privacy.. Spearphone Attack, Android Security Issue, Malicious App Threats, User Data Privacy. . LinuxSecurity.com Team

Calendar%202 Jul 17, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Exploring Android Botnets: Cryptocurrency Mining Risks and ADB Exploits

There is a new cryptocurrency-mining botnet that arrives via open ADB (android Debug Bridge) ports and can spread via SSH, according to Trend Micro. . Android-based devices are susceptible to the malware due to the use of ADB. The attack exploits open ADB ports, and can spread from the infected host to any system that has had a previous SSH connection with the host. This exploitation is similar to the Satori bonnet. According to ZDNet, many Android devices have the ADB developer function and command-line tool disabled by default, but some devices do ship with the feature enabled. If it’s enabled, the device is susceptible to the attack. The link for this article located at Security Today is no longer available. . Devices using Android systems are vulnerable to malware through ADB connections. The threat capitalizes on exposed ports to proliferate.. Cryptocurrency Mining,Botnet Security,Malware Exploits,Android ADB,SSH Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jun 26, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Android Devices Face New Vulnerability Leading to Unresponsiveness Issues

Researchers have developed an attack that puts more than 50 percent of Android phones into the digital equivalent of a persistent vegetative state in which they're almost completely unresponsive and are unable to perform most functions, including making or receiving calls. . The vulnerability, which resides in the mediaserver service Android uses to index media files, can most easily be exploited by luring a vulnerable phone to a booby-trapped website. Presumably, the phone can be revived by restarting it, but according to a blog post published Wednesday by a researcher from security firm Trend Micro, the bug can also be exploited by malicious apps. In this latter scenario, the malicious app could be designed to automatically start each time the phone is turned on, causing it to crash shortly after each restart.. A recent flaw has been discovered in Android devices, causing a system freeze through exploits related to multimedia services.. Android Phones Vulnerabilities, MediaServer Exploit, Security Threats. . LinuxSecurity.com Team

Calendar%202 Jul 30, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Shielding Android Devices From Stagefright Text Malware Threat

If your smartphone or tablet vendor doesn't fix the Stagefright security hole, this text-message based malware can be really scary. But you can protect yourself from it with a few simple steps.. Frankly most people who get malware are asking for trouble. They open a suspicious file from a stranger, go to a skanky website, or download the movie or game that came out yesterday from BitTorrent. Then, there's Stagefright. With malware based on this security hole all you need to do is to get a text on your unpatched Android device, and, bang, you're hacked. The link for this article located at ZDNet Security is no longer available. . Grasp the implications of Stagefright on Android systems, and discover effective measures to safeguard your device against this concerning malware risk.. Android Malware, Stagefright Threat, Smartphone Security, Mobile Protection. . LinuxSecurity.com Team

Calendar%202 Jul 28, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Google: Default Data Encryption in Next Android Release

Google is turning on data encryption by default in the next version of Android, a step that mirrors broad moves in the technology industry to ensure better data security.. Android has been capable of encryption for more than three years, with the keys stored on the device, according to a Google spokesman. The link for this article located at CSO Online is no longer available. . The latest update to Android introduces advanced security measures, including automatic data encryption to safeguard users' personal information more effectively.. Data Encryption, Android Security, Device Protection, User Data Safety. . LinuxSecurity.com Team

Calendar%202 Sep 19, 2014 User Avatar LinuxSecurity.com Team Cryptography
78

Android Security Risks for Enterprises and BYOD Practices

If you're an Android user -- or want to be -- you've likely heard about all the security risks of Google's mobile operating system. But how real are these threats, and how much damage can they do? Despite the fears, are Android devices actually a safe bet for an enterprise mobility strategy?. These are key questions for any organization thinking about a broad Android rollout or even simple acceptance of Android devices in a BYOD context. The answers may not be what you expect. The link for this article located at InfoWorld is no longer available. . These are key questions for any organization thinking about a broad Android rollout or even simple a. you're, android, you've, likely, heard, about, security, risks. . LinuxSecurity.com Team

Calendar%202 Dec 17, 2013 User Avatar LinuxSecurity.com Team Vendors/Products
82

Understanding NSA Enhancements In The Android Ecosystem

Tech giants listed as part of the National Security Agency. So there The link for this article located at BusinessWeek is no longer available. . So thereThe link for this article located at BusinessWeek is no longer available.. giants, listed, national, security, agency, therethe, article, located. . Dave Wreski

Calendar%202 Jul 05, 2013 User Avatar Dave Wreski Government
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200