Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Macs older than a year are vulnerable to exploits that remotely overwrite the firmware that boots up the machine, a feat that allows attackers to control vulnerable devices from the very first instruction. . The attack, according to a blog post published Friday by well-known OS X security researcher Pedro Vilaca, affects Macs shipped prior to the middle of 2014 that are allowed to go into sleep mode. He found a way to reflash a Mac's BIOS using functionality contained in userland, which is the part of an operating system where installed applications and drivers are executed. By exploiting vulnerabilities such as those regularly found in Safari and other Web browsers, attackers can install malicious firmware that survives hard drive reformatting and reinstallation of the operating system.. Older Mac models face increased risks from firmware exploits due to outdated software and lack of updates, enabling remote attacks and data breaches. Mac Security,Firmware Exploits,Remote Control Attacks,OS X Vulnerabilities. . LinuxSecurity.com Team
Late last year, CSO Online reported on a vulnerability in Drupal that could have left thousands of websites compromised. Last week, researchers examined the attack in more detail, measuring the time it would take to compromise a website completely.. On October 15, 2014, Drupal urged users to apply an update that fixed an SQL Injection vulnerability. Unfortunately, unless the patch was applied within a seven hour window, Drupal warned administrators that they should just assume installations in the Drupal 7.x branch before version 7.32 were already compromised. The link for this article located at CSO Online is no longer available. . On November 25, 2015, WordPress recommended that users implement a patch addressing a Cross-Site Scripting vulnerability.. Drupal Security, SQL Injection Threats, Web Application Security. . Alex
CryptoWall is a million-dollar business. The file-encrypting ransomware has netted the criminal gang responsible for its development and dispersal, more than $1.1 million in the six months it. The ransom payments are in stark contrast to the recommendations of some experts who advise ransomware victims to avoid remitting payments because decryption keys or instructions on how to unlock computers or recover files generally are not provided by the criminals. The link for this article located at ThreatPost is no longer available. . Payments to ransomers bring dangers, as specialists recommend avoiding them; analysis of the CryptoWall malware that gathered vast sums.. Ransomware Attacks, File Encryption Strategies, Cybercrime Prevention, CryptoWall Analysis. . LinuxSecurity.com Team
The WiFi Pineapple makes man-in-the-middle attacks incredibly easy, but users better know what they're doing before trying out the Pineapple at the biggest hacker hangout in the U.S. A classic example of that wisdom can be seen via a screenshot tweeted by @JoFo after an intern deployed a Pineapple at Def Con 22. . Feel free to see it yourself in the original form, but the general gist is below...with creative asterisk spellings for words I can't publish here. Hopefully you will be as amused by the message as I was.. Feel free to see it yourself in the original form, but the general gist is below...with creative ast. pineapple, makes, man-in-the-middle, attacks, incredibly, users, better, they'. . LinuxSecurity.com Team
Yesterday afternoon, Ars Technica published a story reporting two possible logs of Heartbleed attacks occurring in the wild, months before Monday's public disclosure of the vulnerability. It would be very bad news if these stories were true, indicating that blackhats and/or intelligence agencies may have had a long period when they knew about the attack and could use it at their leisure.. In response to the story, EFF called for further evidence of Heartbleed attacks in the wild prior to Monday. The first thing we learned was that the SeaCat report was a possible false positive; the pattern in their logs looks like it could be caused by ErrataSec's masscan software, and indeed one of the source IPs was ErrataSec.. Investigations suggest possible vulnerabilities exploited in early instances of Spectre, prompting the EFF to examine these developments further.. Heartbleed Exploitation, Cyber Attack Reports, Security Investigations. . LinuxSecurity.com Team
The cyber attacks that paralyzed a handful of major South Korean websites earlier this year were almost certainly carried out by North Korea or parties allied with the country, computer security company McAfee said Tuesday in a report.. The company's analysis, carried out with the help of the South Korean and U.S. governments, is one of the most thorough yet published on the March attacks, and details how they were carried out, and why they were so difficult to counter. In investigating the incident, the report draws clear parallels with a similar attack that knocked South Korean and U.S. websites offline in 2009 and comes to an unsettling conclusion: the attacks were likely designed to test South Korea's cyber defense and response, and could be the prelude of a much larger attack in the future. The link for this article located at Network World is no longer available. . The company's analysis, carried out with the help of the South Korean and U.S. governments, is one o. cyber, attacks, paralyzed, handful, major, south, korean, websites, earlier. . Alex
Recently, we have saw a . Why attack Sony? Because Anonymous believes individuals should be able to modify PlaySation3 consoles and Sony The link for this article located at Corrections is no longer available. . In 2011, Anonymous targeted Sony for limiting user freedoms, emphasizing the clash between gamer rights and corporate control in digital spaces.. Anonymous Hacking,Cyber Activism,Playstation 3 Security,Console Modification. . LinuxSecurity.com Team
Amazon. The attack is based on the fact that Amazon The link for this article located at tech.blorge is no longer available. . Investigate the weaknesses in Amazon's cloud infrastructure that have been targeted in current cyber incidents and develop strategies to bolster your security measures.. Amazon Cloud Security, Data Breaches, Cyber Attack Prevention. . Alex
Get the latest Linux and open source security news straight to your inbox.