Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
83

FitBit Security Flaw: Bluetooth Exploit Enables Quick Malware Delivery

A security researcher has developed a method by which one can exploit a vulnerability in FitBit fitness trackers and subsequently deliver malware to the target device in 10 seconds. . Axelle Apvrille (@cryptax), a malware researcher at network security firm Fortinet, has found that FitBit wearables are open on their Bluetooth ports, a property which could enable an attacker to connect a device from within a few meters away and deliver malware to the bracelet. . Axelle Apvrille (@cryptax), a malware researcher at network security firm Fortinet, has found that F. security, researcher, developed, method, which, exploit, vulnerability, fitbit. . LinuxSecurity.com Team

Calendar%202 Mar 14, 2017 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Hackers Exploit Existing Tools, Ditch Malware For Attacks

To avoid detection, some hackers are ditching malware and living "off the land" -- using whatever tools are already available in the compromised systems, according to a new report from Dell SecureWorks. In fact, this has been the case for nearly all the intrusions analyzed by the Dell SecureWorks . The cyber criminals typically start out with compromised credentials, said Phil Burdette, senior security researcher at Atlanta-based Dell SecureWorks, Inc. . Cyber intruders are progressively steering clear of traditional malware tactics by capitalizing on legitimate software within infiltrated networks, which heightens risks for cybersecurity.. Hackers Tactics, Cybersecurity Threats, Existing Tools Exploitation. . LinuxSecurity.com Team

Calendar%202 Sep 14, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Red Hat Research: Vulnerable TLS Implementations Expose RSA Keys

A number of TLS software implementations contain vulnerabilities that allow hackers with minimal computational expense to learn RSA keys. Florian Weimer, a researcher with Red Hat, last week published a paper called . The TLS implementations in these products, Weimer said, lack proper hardening to defend against what is known as the Lenstra attack against the Chinese Remainder Theorem, also known as RSA-CRT. . Multiple susceptible TLS versions threaten RSA key integrity, as highlighted in Veimer's findings showcasing insufficient protections.. TLS Improvements, RSA Key Protection, Cryptography Security. . LinuxSecurity.com Team

Calendar%202 Sep 09, 2015 User Avatar LinuxSecurity.com Team Cryptography
83

Keycard Security Breach: Exploiting Access Control in Hotels

You probably don. The good news is that Brocious The link for this article located at MSNBC is no longer available. . Delve into the realm of hotel security flaws exposed by a master of keycard hacking, illustrating the ways common access systems can be breached.. Hotel Security, Lock Picking, Access Control, Security Breach. . LinuxSecurity.com Team

Calendar%202 Aug 03, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

XML Encryption Flaw Exposes Web Services To Security Risks

Watch your Web Services: the official XML Encryption Syntax and Processing standard can be broken. So say two researchers from Ruhr-University Bochum in Germany, who have demonstrated a practical attack against XML's cipher block chaining (CBC) mode. . "We were able to decrypt data by sending modified ciphertexts to the server, by gathering information from the received error messages," according to a statement released by the researchers, Juraj Somorovsky and Tibor Jager. They presented their findings in detail at last week's ACM Conference on Computer and Communications Security in Chicago. The link for this article located at Information Week is no longer available. . Experts uncover a weakness in JSON encryption that puts online services at risk, outlining actionable exploits on networks.. XML Encryption, Web Services Security, Encryption Flaw, Data Breach, Attack Method. . LinuxSecurity.com Team

Calendar%202 Oct 25, 2011 User Avatar LinuxSecurity.com Team Cryptography
83

LulzSec: Revamped Attack on Sun Newspaper Exposes Security Flaws

News yesterday that the Sun was hacked by LulzSec is just the latest in a long line of impressive hacks, but it again shows how hard it is to protect sites from such sustained, sophisticated attack.. LulzSec , a group of hackers which describes itself as, "a team of entertainment and security experts that specialise in the production of malicious comedic cybermaterials", managed to redirect visitors to the Sun's website yesterday evening to a hoax page falsely reporting that Rupert Murdoch had been found dead. It's not the first time a major UK newspaper has been hacked. Last April the Daily Telegraph saw its site hacked, apparently by a group angered by that paper's identification of Romanians as "gypsies" (they added a comment to one of paper's web pages that read, "Guess what, gypsies aren't romanians, morons.") The link for this article located at NewStatesman is no longer available. . LulzSec , a group of hackers which describes itself as, 'a team of entertainment and security expert. yesterday, hacked, lulzsec, latest, impressive. . LinuxSecurity.com Team

Calendar%202 Jul 19, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

Thomas Roth Exploits Rentable GPUs to Crack SHA-1 Secure Hashing

A German security enthusiast has used rented computing resources to crack a secure hashing algorithm (SHA-1) password. Thomas Roth used a GPU-based rentable computer resource to run a brute force attack to crack SHA1 hashes. . Encryption experts warned for at least five years SHA-1 could no longer be considered secure so what's noteworthy about Roth's project is not what he did or the approach he used, which was essentially based on trying every possible combination until he found a hit, but the technology he used. What used to be the stuff of distributed computing projects with worldwide participants that took many months to bear fruit can now be done by a lone individuals in minutes and using rentable resources that cost the same price as a morning coffee to carry out the trick. Roth's proof-of-concept exercise cost just $2. This was the amount needed to hire a bank of powerful graphics processing units to carry out the required number-crunching using the Cuda-Multiforcer. The link for this article located at The Register UK is no longer available. . Cryptography experts emphasize weaknesses in SHA-1; a Belgian enthusiast cracks the code leveraging budget-friendly cloud GPU services.. Hashing Algorithm, GPU Rental, SHA-1 Security, Brute Force Attack, Encryption Research. . LinuxSecurity.com Team

Calendar%202 Nov 19, 2010 User Avatar LinuxSecurity.com Team Security Projects
77

Security Risks in Hypervisors: Impacts Across Technology Sectors

The basic idea/thesis of this article (and the previous, unfinished draft) is this: hypervisors are getting more and more common, and are growing in deployment in everything from datacenter systems to embedded consumer electronics. But, as their deployment increases, more and more security concerns come into play, including a variety of attack methods and the dire consequences of a compromised hypervisor.. If you know what a hypervisor is, then skip this paragraph: A hypervisor is basically a very minimalist operating system designed with the purpose of abstracting real, physical computer hardware from one or more virtual machines running The link for this article located at The Coffee Desk is no longer available. . As virtualization expands across cloud computing and enterprise IT, security concerns tied to hypervisors are rising, necessitating robust measures for protection. Hypervisor Security, Virtualization Risks, Cloud Infrastructure Security. . LinuxSecurity.com Team

Calendar%202 Dec 03, 2009 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200