Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 20 articles for you...
83

Firmware Exploit Threatens Older Macs with Permanent Backdooring

Macs older than a year are vulnerable to exploits that remotely overwrite the firmware that boots up the machine, a feat that allows attackers to control vulnerable devices from the very first instruction. . The attack, according to a blog post published Friday by well-known OS X security researcher Pedro Vilaca, affects Macs shipped prior to the middle of 2014 that are allowed to go into sleep mode. He found a way to reflash a Mac's BIOS using functionality contained in userland, which is the part of an operating system where installed applications and drivers are executed. By exploiting vulnerabilities such as those regularly found in Safari and other Web browsers, attackers can install malicious firmware that survives hard drive reformatting and reinstallation of the operating system.. Older Mac models face increased risks from firmware exploits due to outdated software and lack of updates, enabling remote attacks and data breaches. Mac Security,Firmware Exploits,Remote Control Attacks,OS X Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
72

Drupal 7.x Advisory Critical: SQL Injection and Firewall Bypass Risks

Late last year, CSO Online reported on a vulnerability in Drupal that could have left thousands of websites compromised. Last week, researchers examined the attack in more detail, measuring the time it would take to compromise a website completely.. On October 15, 2014, Drupal urged users to apply an update that fixed an SQL Injection vulnerability. Unfortunately, unless the patch was applied within a seven hour window, Drupal warned administrators that they should just assume installations in the Drupal 7.x branch before version 7.32 were already compromised. The link for this article located at CSO Online is no longer available. . On November 25, 2015, WordPress recommended that users implement a patch addressing a Cross-Site Scripting vulnerability.. Drupal Security, SQL Injection Threats, Web Application Security. . Alex

Calendar%202 Mar 24, 2015 User Avatar Alex Firewalls
67

CryptoWall Ransomware Insights: $1.1M Revenue And Payment Risks

CryptoWall is a million-dollar business. The file-encrypting ransomware has netted the criminal gang responsible for its development and dispersal, more than $1.1 million in the six months it. The ransom payments are in stark contrast to the recommendations of some experts who advise ransomware victims to avoid remitting payments because decryption keys or instructions on how to unlock computers or recover files generally are not provided by the criminals. The link for this article located at ThreatPost is no longer available. . Payments to ransomers bring dangers, as specialists recommend avoiding them; analysis of the CryptoWall malware that gathered vast sums.. Ransomware Attacks, File Encryption Strategies, Cybercrime Prevention, CryptoWall Analysis. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2014 User Avatar LinuxSecurity.com Team Cryptography
83

Zero-Day Exploit: WiFi Pineapples Attacked at Def Con 22

The WiFi Pineapple makes man-in-the-middle attacks incredibly easy, but users better know what they're doing before trying out the Pineapple at the biggest hacker hangout in the U.S. A classic example of that wisdom can be seen via a screenshot tweeted by @JoFo after an intern deployed a Pineapple at Def Con 22. . Feel free to see it yourself in the original form, but the general gist is below...with creative asterisk spellings for words I can't publish here. Hopefully you will be as amused by the message as I was.. Feel free to see it yourself in the original form, but the general gist is below...with creative ast. pineapple, makes, man-in-the-middle, attacks, incredibly, users, better, they'. . LinuxSecurity.com Team

Calendar%202 Aug 12, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Heartbleed Exploitation: Emerging Evidence Before Public Exposure

Yesterday afternoon, Ars Technica published a story reporting two possible logs of Heartbleed attacks occurring in the wild, months before Monday's public disclosure of the vulnerability. It would be very bad news if these stories were true, indicating that blackhats and/or intelligence agencies may have had a long period when they knew about the attack and could use it at their leisure.. In response to the story, EFF called for further evidence of Heartbleed attacks in the wild prior to Monday. The first thing we learned was that the SeaCat report was a possible false positive; the pattern in their logs looks like it could be caused by ErrataSec's masscan software, and indeed one of the source IPs was ErrataSec.. Investigations suggest possible vulnerabilities exploited in early instances of Spectre, prompting the EFF to examine these developments further.. Heartbleed Exploitation, Cyber Attack Reports, Security Investigations. . LinuxSecurity.com Team

Calendar%202 Apr 10, 2014 User Avatar LinuxSecurity.com Team Privacy
82

North Korean DDoS Attacks: March 2023 Examination and Future Risks

The cyber attacks that paralyzed a handful of major South Korean websites earlier this year were almost certainly carried out by North Korea or parties allied with the country, computer security company McAfee said Tuesday in a report.. The company's analysis, carried out with the help of the South Korean and U.S. governments, is one of the most thorough yet published on the March attacks, and details how they were carried out, and why they were so difficult to counter. In investigating the incident, the report draws clear parallels with a similar attack that knocked South Korean and U.S. websites offline in 2009 and comes to an unsettling conclusion: the attacks were likely designed to test South Korea's cyber defense and response, and could be the prelude of a much larger attack in the future. The link for this article located at Network World is no longer available. . The company's analysis, carried out with the help of the South Korean and U.S. governments, is one o. cyber, attacks, paralyzed, handful, major, south, korean, websites, earlier. . Alex

Calendar%202 Jul 06, 2011 User Avatar Alex Government
78

Understanding Anonymous's Sony Attack and Console Modifications

Recently, we have saw a . Why attack Sony? Because Anonymous believes individuals should be able to modify PlaySation3 consoles and Sony The link for this article located at Corrections is no longer available. . In 2011, Anonymous targeted Sony for limiting user freedoms, emphasizing the clash between gamer rights and corporate control in digital spaces.. Anonymous Hacking,Cyber Activism,Playstation 3 Security,Console Modification. . LinuxSecurity.com Team

Calendar%202 May 16, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
74

Exploring Security Flaws in Amazon Cloud Services and Attack Tactics

Amazon. The attack is based on the fact that Amazon The link for this article located at tech.blorge is no longer available. . Investigate the weaknesses in Amazon's cloud infrastructure that have been targeted in current cyber incidents and develop strategies to bolster your security measures.. Amazon Cloud Security, Data Breaches, Cyber Attack Prevention. . Alex

Calendar%202 Jan 12, 2011 User Avatar Alex Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200