Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 28 articles for you...
77

Defending Oracle WebLogic from Hadooken Malware Threats

Cybercriminals have been relentlessly attacking the digital landscape, aiming to exploit vulnerabilities in well-known systems. One such exploit is the recently discovered Hadooken malware, which targets Oracle WebLogic applications. . To help you secure your server against this emerging threat, we will explore the intricacies of the Hadooken malware, understand its operational mechanics, and pinpoint the targets it aims to compromise. We'll then offer practical detection and mitigation advice for Linux administrators and organizations. An Introduction to Oracle WebLogic Server Oracle WebLogic Server is a leading enterprise-level Java EE application server widely utilized for building, deploying, and managing large-scale, distributed applications. Developed by Oracle, it boasts strong support for Java technologies, transaction management, and scalability. Due to its prevalence in critical sectors such as banking, e-commerce, and various business-critical systems, WebLogic is often a prime target for cyberattacks. Despite its robust architecture, WebLogic has been susceptible to attacks due to vulnerabilities such as deserialization flaws and improper access controls. Misconfigurations, like weak credentials or exposed admin consoles, can lead to severe consequences, including remote code execution (RCE), privilege escalation, and data breaches if not properly secured or patched. How Does Hadooken Malware Operate? Hadooken malware is a complex threat that targets WebLogic servers by exploiting weak credentials and other vulnerabilities. When executed, the malware introduces additional threats, including the Tsunami malware and a crypto-miner. Here's a breakdown of the Hadooken malware's operation: Source: AquaSec Blog Initial Access and Execution The attackers gain initial access by exploiting weak credentials on WebLogic servers. Once inside, they achieve remote code execution. The malicious script downloads two scripts, a shell script named ‘c’ and a Python scriptnamed ‘y’, which serve as secondary payload mechanisms. Payload Delivery The primary payload, Hadooken malware, gets downloaded into non-persistent temporary directories. The Python script iterates over several paths to secure the download and execution while subsequently deleting the original file to avoid detection. The shell script similarly downloads the Hadooken malware into the /tmp directory, executing and then deleting it to remain stealthy. Secondary Malware Hadooken executes to deploy both a crypto-miner and Tsunami malware. Once packed and unpacked, the crypto-miner is dropped into several paths: /usr/bin/crondr, /usr/bin/bprofr, and `/mnt/-java. The Tsunami malware is also deployed, randomly named, into the /tmp/ directory, although indications show it isn't immediately used in the attack. Persistence and Evasion Hadooken creates multiple cron jobs to maintain persistence, using random names and varying frequencies for execution scripts under different cron directories. The malware employs tactics to evade detection by renaming its crypto miner to familiar names like -bash and deleting logs after execution. Lateral Movement and Impact Hadooken attempts to iteratively access SSH keys, allowing it to move laterally across connected servers within an organization. The malware's impact is evident in its resource hijacking for crypto-mining and its potential to introduce ransomware such as RHOMBUS and NoEscape in prolonged campaigns. Detection and Mitigation: Best Practices for Linux Admins and Organizations Given the sophisticated nature of Hadooken malware and the severity of its impact, Linux administrators and organizations must adopt a comprehensive approach to detect, mitigate, and prevent such threats. Here are some actionable strategies to secure your server and your Linux environment against Hadooken malware: Infrastructure as Code (IaC) Scanning: Scan IaC templates such as Terraform, CloudFormation, or Kubernetes YAML files for potentialmisconfigurations before deployment. Cloud Security Posture Management (CSPM): Continuously scan cloud configurations for misconfigurations, compliance violations, and security risks across services like AWS, Azure, and GCP. Kubernetes Security and Configuration: Regularly scan Kubernetes clusters for compliance with security best practices. Ensure alignment with CIS Kubernetes benchmarks . Container Security: Perform thorough vulnerability scanning of container images and Docker files to identify and rectify misconfigurations and vulnerabilities. Runtime Security Monitoring: Implement runtime security tools to monitor cloud-native applications for anomalies and suspicious behaviors in real time. Our Final Thoughts on Protecting Against Hadooken Malware The Hadooken malware illustrates the evolving nature of cyber threats targeting enterprise-level applications like Oracle WebLogic. Linux administrators and organizations can significantly mitigate risk and safeguard critical systems by understanding its operation and adopting proactive and reactive security measures. Continuous vigilance, regular updates , strong authentication practices, and comprehensive security tools are paramount in maintaining a secure digital environment amidst these growing threats. . Fortify your system from Hadooken threats through effective detection, mitigation techniques, and essential guidelines for Linux administrators.. WebLogic Security, Malware Detection, Cyber Threats, Application Security, Linux Administration. . Brittany Day

Calendar%202 Sep 16, 2024 User Avatar Brittany Day Server Security
83

TargetCompany: New Ransomware Variant Threatens ESXi Systems Security

Security researchers have recently identified an innovative Linux ransomware variant developed by the TargetCompany ransomware group. This variant targets ESXi environments and uses a custom shell script for payload delivery and execution, something not previously observed by TargetCompany operations. . To help you avoid falling victim to this ransomwareransomware , we will discuss the threat posed by this emerging variant and provide practical advice for protecting your systems against it. How Does This New TargetCompany Ransomware Work & Why Is It So Dangerous? TargetCompany ransomware has developed a Linux variant with distinct characteristics that make it stand out from previous variants. One key capability of this new variant is exfiltrating victim information onto two servers simultaneously, giving ransomware operators backup copies of any compromised files. Furthermore, this variant detects whether victim machines run VMWare ESXi environments. Targeting these environments allows threat actors behind TargetCompany to disrupt operations more effectively and increase the chances of receiving ransom payments. This variant employs a shell script for payload delivery and execution, indicative of the ransomware group's continuous development to use more sophisticated attack techniques. Targeting Linux environments aligns with an increasing trend of ransomware groups expanding attacks to critical infrastructure sites, thereby expanding victim numbers. Upon successful exploitation, the ransomware encrypts critical ESXi servers by appending ".locked" extensions to encrypted files and leaving a ransom note named "HOW TO DECRYPT.txt." Additionally, this variant uses a custom shell script to download and execute its payload while exfiltrating victim information across multiple servers. Such tactics pose significant difficulties for defenders when investigating incidents and responding accordingly. TargetCompany ransomware poses an extremely severe threat to organizations that rely onvirtualization servers as part of their core infrastructure. Encryption can result in significant operational disruption and financial losses for affected organizations, making it essential for them to take proactive measures against attacks of this nature. As ransomware evolves in tactics and capabilities, robust cybersecurity defenses must also evolve alongside it to protect sensitive data against any unintended access attempts. Practical Advice for Securing Linux Systems With ransomware groups like TargetCompany emerging as ever more threatening, Linux admins must actively secure their systems against potential attacks. Here are some concrete recommendations to improve the security posture of your environment: Implement Multifactor Authentication (MFA): Enabling MFA can help protect networks by deterring attackers from moving laterally within them and decreasing risk associated with unauthorized access to critical systems and data. Adhere to the 3-2-1 Backup Rule: Adherence to the 3-2-1 rule can help organizations recover data more easily after ransomware attacks. By creating three copies in two formats—with one stored offsite—they will ensure they can quickly restore files when necessary. Maintain a Proactive System Patch Management Strategy: Staying current with updates to operating systems and applications is crucial to avoiding attacks, so having an effective patch management protocol is essential in addressing vulnerabilities before they are exploited by adversaries. Adopt Endpoint Protection Solutions: Integrating endpoint protection solutions that detect and block malicious activities at the system level can significantly enhance the security posture of Linux environments. Perform Regular Security Audits and Vulnerability Evaluations: It is wise to conduct routine security audits and vulnerability analyses to detect and address potential weaknesses that could be exploited by ransomware threats. Linux admins can enhance their cybersecuritystrategy to strengthen the resilience of their systems against evolving threats, such as the TargetCompany ransomware variant targeting ESXi environments, by adopting these best practices into their cybersecurity strategy. Our Final Thoughts on Securing Linux Systems Against This New Ransomware Variant The TargetCompany ransomware group's new Linux variant targeting ESXi environments is yet another indicator of evolving tactics employed by threat actors to exploit critical infrastructure. Organizations must remain vigilant and strengthen their cybersecurity defenses against ransomware attacks to reduce the risk of falling victim. By employing proactive security measures, adhering to best practices, and staying aware of emerging threats in today's constantly changing cybersecurity landscape, Linux administrators can better secure their systems and data against sophisticated ransomware threats that pose constant danger. . Grasping the intricacies of TargetCorp's latest Linux ransomware iteration is vital for fortifying your infrastructure against forthcoming vulnerabilities.. Linux Ransomware, ESXi Protection, TargetCompany Threats, Cybersecurity Best Practices. . Anthony Pell

Calendar%202 Jun 06, 2024 User Avatar Anthony Pell Hacks/Cracks
77

Combatting Magnet Goblin Linux Malware Threats and Security Solutions

Financially motivated hacking groups are increasingly exploiting newly disclosed vulnerabilities to deploy custom malware on public-facing servers. The threat actors are known as Magnet Goblin, and they have been quick to leverage one-day flaws, vulnerabilities for which a patch has been released but not yet applied by the target, to carry out their attacks. . Why Are the Implications of This Threat? The challenges faced by security practitioners in fighting against these types of threats must be acknowledged. While exploits are not immediately available upon disclosing a flaw, some vulnerabilities are easy to figure out and leverage through reverse-engineering the patch. This raises questions about the effectiveness of relying solely on patching as a defense mechanism. Are there other strategies and mechanisms that can be implemented to mitigate the impact of these attacks in the absence of a patch? Magnet Goblin targets Ivanti Connect Secure, Apache ActiveMQ, ConnectWise ScreenConnect, Qlik Sense, and Magento. This information can be precious to Linux admins, infosec professionals, and sysadmins, as it reveals the potential targets that must be closely monitored and patched diligently. The NerbianRAT malware, circulating since May 2022, is one variant that Magnet Goblin has been using to compromise servers. It is described as "sloppily compiled yet effective," which begs the question: how can a poorly constructed malware variant remain effective for such an extended period? Is this a testament to the ingenuity of the threat actors, or is there a flaw in the defense mechanisms employed by the targeted systems? How Can I Secure My Systems Against These Attacks? The importance of quick patching to combat 1-day exploitation cannot be overemphasized. However, it is not enough to rely solely on patching to ensure optimal security. Network segmentation, endpoint protection, and multi-factor authentication are additional security measures that can help mitigate the impact of potentialbreaches. It is crucial for security practitioners to not only stay informed about the newest vulnerabilities and exploits but also to implement a comprehensive security posture that goes beyond patching. Our Final Thought on Linux Malware Protection. This article aims to shed light on Magnet Goblin's activities and their exploitation of one-day flaws to deliver custom Linux malware. It highlights the challenges faced by security practitioners in detecting and mitigating these threats and raises essential questions about the efficacy of patching as the sole solution. By critically analyzing the implications and offering suggestions for comprehensive security measures, we hope to empower readers to prioritize their defense strategies and adapt to the ever-changing landscape of cyber threats. . Profit-driven cybercriminals target zero-day vulnerabilities to spread Windows-based malware. Discover strategies to mitigate these risks.. Linux Malware, Custom Malware, Cybersecurity Strategies, One-Day Exploits. . Brittany Day

Calendar%202 Mar 11, 2024 User Avatar Brittany Day Server Security
210

Terrapin Attack Advisory: OpenSSH Risk and Mitigation Strategies

Researchers recently uncovered a sophisticated attack dubbed Terrapin that takes advantage of a weakness in the SSH protocol to gain access to servers. The attack targets a specific implementation issue in OpenSSH 7.2 through 8.8 that allows remote code execution. By sending carefully crafted data, attackers can overflow the stack buffer and execute commands, leading to complete server compromise. . This is especially concerning for Linux system administrators , as SSH is widely used to manage Linux servers and infrastructure remotely. The vulnerability allows attackers to bypass authentication and gain elevated privileges on the target system. While patches have been released, Terrapin serves as an urgent reminder that determined adversaries are probing for weaknesses in core internet infrastructure. Proactive vigilance and defense-in-depth strategies remain essential to secure critical systems and data. How Does the Terrapin Attack Work? The Terrapin attack showcases the ingenuity of threat actors and illustrates why continued vigilance is necessary even with tried and true protocols like SSH. The malware , named Terrapin by security researchers, abuses the SSH protocol in a novel way to infect Linux systems and maintain persistence. Specifically, it modifies the SSH server daemon's host keys which are used to authenticate SSH sessions. When an SSH client first connects to a server, the server provides its host key fingerprint. The client caches this key to validate future connections. Terrapin secretly replaces the server's legitimate host keys with ones it controls. The next time a user logs in, their SSH client sees the fake host key and warns about a possible man-in-the-middle attack. However, many admins train themselves to accept key changes reflexively. Terrapin relies on this conditioned response to sneak its malicious host key onto the client's system. Now any future SSH connections get silently redirected through a proxy controlled by the attackers. This not only allowsthe threat actors to intercept sensitive data but also gives them remote access to pivot further into the breached network. All while avoiding detection by blending in with expected SSH communication. The researchers note that Terrapin shows intelligence gathering and patience on the attacker's part. Instead of immediately exploiting a breach, they stealthily set the trap and then wait for the catch. This highlights the need for admins to stay alert to subtle signs of compromise even after an initial infection. What Are the Implications for Linux Admins? The Terrapin attack concerns Linux admins and system administrators for several reasons. While this vulnerability affects OpenSSH, one of the most widely used tools for remote administration, the implications extend beyond just SSH. This attack shows how a single vulnerability in a core protocol can lead to full system compromise. Once the attackers have an initial foothold from the SSH exploit, they can potentially access any other service or data on the server. Servers are often bastions of an organization's entire infrastructure, so a compromise of one server can spread network-wide. As a privilege escalation attack, Terrapin bypasses authentication and gives the attacker immediate root access. This allows attackers to control and hide within compromised servers fully. Even with audit logging and monitoring, malicious actions are harder to detect if initiated by root. The targeting of IoT and embedded Linux devices is also troubling. As more critical infrastructure relies on connected Linux devices, attacks against them become higher risk. Malicious control of power grids, manufacturing systems, medical devices, and more through Terrapin could lead to safety, privacy, and reliability issues. For Linux admins, Terrapin means a renewed focus on patching , and upgrades are essential. However, it also shows the importance of reducing attack surface area through tight system hardening, network segmentation, the principle of least privilege,and other defensive best practices. Proactive logging, monitoring, and auditing are also key to help detect anomalous behaviors indicative of intrusion. How Can I Prevent the Terrapin Attack? The Terrapin attack targets vulnerabilities in SSH client software on Linux systems. While patches are still pending for some distros, there are several ways Linux admins can defend against this threat: Upgrade SSH Client - Ensure you are running the latest SSH client version without known vulnerabilities. Fully patch or upgrade vulnerable systems. Limit SSH Access - Only allow SSH connections from specific IP addresses or networks that need it. Restrict access to SSH internally when possible. Disable Password Auth - Require public key authentication for SSH instead of passwords. This prevents brute force attacks. Install Intrusion Detection - Monitor SSH logs closely for signs of compromise. Deploy host and network monitoring to detect brute-force attacks in real-time. Segment Networks - Use internal firewall rules and VLANs to isolate critical systems. Don't allow lateral movement between subnets and environments. Enforce MFA - Require multi-factor authentication for all SSH access. This will stop stolen credentials from being easily abused. Raise Awareness - Educate users on social engineering and securely sharing credentials. Limit access to only those needing it. Staying vigilant and proactively securing SSH access will make it much harder for threats like Terrapin to exploit environments. However, continued patching, upgrades, and monitoring are critical for identifying and stopping new vulnerabilities. Monitoring for Compromise While patching and upgrading software is critical, it's also important to monitor systems for signs of compromise. Here are some tips: Review logs regularly - Look for unusual failed login attempts or activities during off hours. Unauthorized access attempts could indicatebrute-force hacking attempts. Inspect running processes - Use commands like ps and top to look for unknown or suspicious processes. Attackers often try to hide malware by naming it after legitimate system processes. Check network connections - Tools like netstat this can show open ports and connections. Backdoors and malicious software often communicate over the network. Monitor user accounts - Look for unauthorized new users or changes to existing users like added sudo rights. Attackers try to create backdoor accounts. Scan for malware - Run rootkit scanners like rkhunter and chkrootkit. They check for signs of known malware. Also, scan things like PHP files for hidden code injections. Verify file integrity - Use a file integrity checker like Tripwire or AIDE to alert on unauthorized file changes. Attackers often modify system binaries or add malicious files. Monitor security patches - Check that all security updates are applied promptly to ensure known vulnerabilities can't be exploited. Staying vigilant is key. Even if patches are applied, assume systems can still be compromised. Actively hunting for the signs of intrusion is critical, especially on internet-facing systems. Patching Vulnerabilities Keeping SSH software up-to-date is one of the most important things Linux admins can do to prevent Terrapin and other attacks. The Terrapin attack exploits a vulnerability in OpenSSH that was patched in version 8.8 in April 2022. However, many organizations are slow to patch and upgrade services like SSH once they are running smoothly in production environments. The tendency to continue running outdated software is understandable but very risky from a security perspective. New vulnerabilities in protocols like SSH are discovered frequently, and threat actors quickly weaponize them in attacks. Unpatched systems running old SSH versions are sitting ducks. Upgrading to the latest OpenSSH release should be a toppriority for any organization exposed to the internet and relying on SSH for remote access. Dedicate the resources to testing patches and upgrades in dev environments before promoting them to production. Establish policies and procedures to ensure SSH daemons and clients stay current going forward. The effort required for ongoing patching and upgrades is far less than that needed to detect, contain, and recover from a breach. Take software updates and patches seriously, especially for security-critical network services like SSH. Multi-Factor Authentication Multi-factor authentication (MFA) is an important security control to implement for SSH access. Instead of relying solely on a username and password for authentication, MFA requires users to provide an additional factor, such as a one-time code sent to their mobile device. Enabling MFA provides significant security benefits for SSH: Provides an additional layer of protection beyond just a password. If credentials are compromised in a breach, an attacker still cannot access SSH without the additional factor. Defends against brute force attacks. Even if an attacker determines a user's password through guessing, MFA will block access without the secondary authentication factor. Protects against password reuse risks. An exposed password on one system does not enable access to SSH if MFA is required. Adds user-friendly options like push notifications and biometrics for the second factor. Can detect suspicious login attempts and block illegitimate access. For Linux administrators already using SSH keys for authentication, MFA further strengthens security. Overall, implementing MFA is one of the most meaningful controls an organization can adopt to secure SSH access and defend against advanced attacks like Terrapin. The minimal extra effort for users to authenticate with a second factor provides major security dividends and peace of mind. Network Segmentation Minimizing lateral movement is critical for mitigating attacks likeTerrapin. Segmenting networks into zones using firewalls, VLANs, and access controls can limit the blast radius if an attacker breaches part of the infrastructure. Admins should segment based on trust levels, using strict rules to filter traffic between zones. Critical servers like domain controllers should be isolated from general-purpose systems. Test/dev environments should also be segregated from production to prevent test instances from being used to pivot into production systems. Zero-trust network architectures take segmentation further by denying traffic by default and restricting communication to only what is explicitly allowed on a policy basis. While complex to implement correctly, zero trust significantly raises the bar for attackers attempting lateral movement. With the highly connected nature of modern networks, no segmentation is foolproof. But intelligent network segregation remains an important defense-in-depth measure against attacks like Terrapin that rely on pivoting through systems after gaining an initial foothold. Insider Threats The Terrapin attack highlights the risks that come from malicious insiders who have privileged access to systems. Even with strong perimeter defenses, a rogue admin on the inside can carry out damaging attacks. Some ways to mitigate insider threats: Implement separation of duties and least privilege access. Don't give any single person too much power. Use monitoring and auditing to detect anomalous behavior from privileged accounts. Look for unusual login times, commands run, and files accessed. Enforce multi-factor authentication for admin logins. This raises the bar for stealing credentials. Log and alert on suspicious admin activities like disabling security tools, excessive data exfiltration, or tampering with logs. Conduct background checks during the hiring process for sensitive roles. Screen for potential red flags. Implement behavioral analytics to spot risky user behavior patterns.Model normal vs abnormal activities. Provide anonymous reporting channels for employees to flag concerning insider actions. Foster an ethical workplace culture with clear policies, expectations, and accountability. Insider threats are hard to eliminate entirely, but taking proactive steps can help reduce the risk and damage they can inflict. Ongoing vigilance is required, along with being alert to warning signs. The Importance of Ongoing Cyber Vigilance The Terrapin attack demonstrates the ever-evolving nature of cyber threats and the need for continuous security monitoring and vigilance. Even if all known vulnerabilities are patched, new attack methods can emerge anytime. Organizations should have robust security awareness training to alert employees to potential risks. Monitoring systems and access logs can help detect anomalies that may indicate compromise. But technology alone is not enough. A vigilant security culture requires engagement from every employee, not just IT staff. With distributed workforces connecting remotely, risks multiply. Everyone has a role to play in spotting and reporting possible intrusions. Cyber hygiene, like strong, unique passwords and multi-factor authentication, is a daily habit. As defenders, we must be proactive, not reactive. The threats won't wait for us to catch up. Only persistent preparation and vigilance give us a fighting chance against sophisticated adversaries. Complacency is the enemy. We must continually adapt and improve defenses in anticipation of what comes next. Be sure to subscribe to our weekly newsletters to stay up-to-date on the latest advisories, information, and insights impacting the security of your Linux systems. Stay safe out there! . Linux system admins should stay vigilant against the Terrapin attack targeting SSH protocol flaws to infiltrate systems.. OpenSSH Vulnerability, SSH Exploit, Linux Threats, Cybersecurity Defense. . Brittany Day

Calendar%202 Jan 02, 2024 User Avatar Brittany Day Security Vulnerabilities
79

Innovative Sandboxing Techniques Strengthen Malware Defense Strategies

Hackers are finding ways to bypass sandboxes and sneak in their malware, so some vendors are creating new approaches to counter them. Attackers continue to find ways to evade traditional sandboxes, and some vendors are looking to raise the bar with new approaches to isolating and vetting files.. Sandboxing adds an extra layer of protection, diverting untrusted files or programs from unverified third parties, suppliers, or websites into a separate, secure environment where they can be inspected for malicious code. Based on that inspection, the attachments, files or applications are either allowed to enter or rejected from moving further into the network. The link for this article located at Dark Reading is no longer available. . Sandboxing adds an extra layer of protection, diverting untrusted files or programs from unverified . hackers, finding, bypass, sandboxes, sneak, their, malware, vendors, creatin. . LinuxSecurity.com Team

Calendar%202 Sep 07, 2015 User Avatar LinuxSecurity.com Team Security Projects
79

Exploring Honeypots and Their Role in Cyber Deception Challenges

As a concept, honeypots can be a powerful tool for detecting malware. But in the emerging field of cyber deception, they're not up to the task of fooling attackers and getting our hands on their resources.. Cyber deception is a growing industry, offering defenders a chance to turn the table on attackers. But are the tools up to the task? Iran and a leading cloud provider The link for this article located at Dark Reading is no longer available. . Digital misdirection is a burgeoning domain, offering protection specialists avenues to outsmart intruders and enhance protective strategies.. Honeypots, Cyber Deception, Attack Mitigation, Security Strategies, Threat Detection. . LinuxSecurity.com Team

Calendar%202 Aug 04, 2015 User Avatar LinuxSecurity.com Team Security Projects
76

Black Hat 2014: Key Presentations and Defense Strategies Against Attacks

As the world. Here is a sampling of some of the hottest presentations and defensive measures speakers will release in order to block the attacks they describe. The link for this article located at CSO Online is no longer available. . Black Hat 2014 highlighted vital conversations and insights to enhance defenses against growing cyber threats, featuring Chris Wysopal on APTs and Katie Moussouris on disclosure practices. Black Hat 2014,Cybersecurity Strategies,Defense Mechanisms. . Dave Wreski

Calendar%202 Jul 30, 2014 User Avatar Dave Wreski Organizations/Events
83

Damballa Network Security Command-and-Control Mitigation Strategies

Cyber threat fighter, Damballa Inc., has released its . Damballa is a specialist in network security. Cyber crime is orchestrated using remote control communications via the internet, also known as command-and-control (CnC). Their aim is to help protect corporations, ISPs and telecommunications service providers from cyber threat attacks used for organized, online crime. They say they have a unique, global approach that rapidly isolates the command-and-control needed to launch cyber attacks. The link for this article located at IT WIre is no longer available. . AegisTech focuses on safeguarding digital infrastructure, effectively containing threats and enhancing resilience against malicious activities.. Botnet Management, Threat Prevention, Network Security, Cyber Crime Defense. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200