Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
83

Insights On The Acceleration Of Cyber Crime And Security Trends

Rarely a day goes by without news emerging about a giant company losing large amounts of sensitive data to a massive hacker attack. It might be Google one day, Sony the next, and a country's government agency the day after. Just replace the names, rinse, and repeat.. Reporters from across the country have approached me of late, asking for my views on the acceleration of hacker attacks and the current state of security. When I get through with my rant, they're pretty shaken. They didn't know things were as bad as they are, while I ask myself, "Where have these media types been hiding?" The link for this article located at PC World is no longer available. . Reporters from across the country have approached me of late, asking for my views on the acceleratio. rarely, without, emerging, about, giant, company, losing, large, amounts, sensitive. . LinuxSecurity.com Team

Calendar%202 May 11, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Apache.org Targeted Attack Exposes User Passwords and Risks

This is not the first time Apache.org has been hacked, it was comprised back in September 2009 using SSH keys. This time another targeted attack against the site was successful and allowed the attackers to capture the passwords of users logging into the bug-tracking service.. It also exposed the entire password list, which sadly although hashed was salted with a static salt rather than a random one..so it The link for this article located at Darknet is no longer available. . A coordinated breach of Apache.org exposed user passwords, highlighting security concerns for online account safety.. Apache security, password management, cybersecurity threats, user data exposure. . LinuxSecurity.com Team

Calendar%202 Apr 14, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Exploring Hacker Mindsets and Effective Defense Strategies

You can't defend against the cyber enemy if you don't know his movements or how he thinks. Sanjay Bavisi, president of security certification, training, and education organization EC-Council, at Interop Las Vegas next week will demonstrate step-by-step how a typical black-hat hacker executes an attack from reconnaissance to covering his tracks in the "Seven Habits of Highly Malicious Hackers" presentation on Thursday. . Bavisi also will provide tips on how to protect yourself from each step, as well as a peek into the hacker psyche. He says he'll also show a case study of a hack with national security implications, and how ethical hacking is a successful way to stem attacks. Here's the trajectory of a typical attack, according to Bavisi: The link for this article located at DarkReading is no longer available. . Bavisi also will provide tips on how to protect yourself from each step, as well as a peek into the . can't, defend, against, cyber, enemy, don't, movements, thinks, sanjay. . LinuxSecurity.com Team

Calendar%202 May 18, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

CWE and CAPEC Initiatives Boost Application Security Standards

MARCH 1, 2007 | ARLINGTON, Va. -- Black Hat DC -- Experts agree: The best way to secure applications is to build security in during the development phase. The problem is that there are few standards or templates for doing it. But that situation is about to change, according to speakers at the Black Hat conference here today. In fact, draft guidelines for specifying common security weaknesses and common attack patterns could be just weeks away. . In two separate presentations, experts from Mitre and Cigital -- two companies with long track records in government and industry standards -- outlined plans for the implementation of Common Weakness Enumeration (CWE) and Common Attack Pattern Enumeration and Classification (CAPEC), two specifications that could eventually help developers recognize weaknesses in their applications and anticipate common attack patterns that adversaries might use to break in. The proposed specifications would offer common methods for describing and categorizing weaknesses and attack vectors, much as Common Vulnerability Enumeration (CVE) and Common Malware Enumeration (CME) have done for vulnerabilities and malware. The CWE is in its fifth draft and is already delivering some benefits for software developers, according to Robert Martin, principal engineer at Mitre. It represents a "dictionary" of frequently made mistakes in software development that can lead to exploitable vulnerabilities, he said. "It's a common body of knowledge about software assurance that will help developers to build security into their applications," Martin said. The initiative, funded largely by the U.S. Department of Homeland Security (DHS), represents some 600 entries from more than 20 vendors of tools that help to identify security weaknesses in software. The link for this article located at Dark Reading is no longer available. . Professionals emphasize the importance of embedding security measures throughout the software development lifecycle to counteract frequent vulnerabilities..Application Security, CWE, CAPEC, Security Standards, Attack Patterns. . LinuxSecurity.com Team

Calendar%202 Mar 02, 2007 User Avatar LinuxSecurity.com Team Security Projects
81

Phishing Attacks Increase by 500%: SurfControl Report March 2024

More bad news about phishing attacks arrived Friday via message filtering firm SurfControl when it unveiled numbers showing the scams have increased nearly 500% since January. . . .. More bad news about phishing attacks arrived Friday via message filtering firm SurfControl when it unveiled numbers showing the scams have increased nearly 500% since January. Phishing attacks are spam messages that pose as legitimate mail from big-name banks, credit-card companies, and retailers. Links within the messages try to entice recipients to visit bogus Web sites, where they're told that their account information needs to be updated. Users who fall for the con divulge personal financial information, as credit-card and bank-account numbers, which is used by the attacker to siphon funds, purchase goods, or steal identities. The number of unique scams spotted by SurfControl has grown 477%, from 33 to 155 in the first five months of this year, according to Susan Larson, SurfControl's VP of global content. In the last 12 months, she added, phishing scams have rocketed by more than 5,000%--from three in May 2003, to 155 in 2004). Other phishing watchers have noted an even more dramatic rise in the raw numbers of phishing messages. In April, for instance, MessageLabs said it had seen phishing messages skyrocket from just 279 in September 2003, to 215,643 in March 2004. The link for this article located at informationweek.com is no longer available. . Scam emails are surging dramatically, showing an alarming 400% jump since the year's start, as noted in the findings from CyberWatch.. Phishing Attack,Cyber Threat,Financial Fraud. . LinuxSecurity.com Team

Calendar%202 May 14, 2004 User Avatar LinuxSecurity.com Team Privacy
83

Server Usage Trends: South Korea and China Dominating Cyber Attacks

Servers based in South Korea and China are the most commonly used in attacks on the Internet, following servers housed in the United States, according to a study released Monday by an infrastructure consulting firm. Using its more than 50 . . . . Servers based in South Korea and China are the most commonly used in attacks on the Internet, following servers housed in the United States, according to a study released Monday by an infrastructure consulting firm. Using its more than 50 sensors around the Internet to study more than 12 million probes and attacks, New York-based Predictive Systems found that 49 percent of all attacks took advantage of servers in the United States, 17 percent used South Korean servers, and about 15 percent used servers based in China. While the results don't suggest which nations have the most hackers, they do indicate that unsecured infrastructure is often co-opted by attackers in other countries and poses a significant risk to others connected to the Internet, said Richard Smith, a senior information security analyst with Predictive. The link for this article located at ZDNet is no longer available. . Servers based in South Korea and China are the most commonly used in attacks on the Internet, follow. servers, based, south, korea, china, commonly, attacks, internet, follow. . LinuxSecurity.com Team

Calendar%202 Mar 19, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Tracking Malicious Hacker Activity Through Honeynet Insights

A decoy computer network set up to record every attempt to crack it open and subvert it has revealed just how active and determined malicious hackers have become. Statistics gathered by the network show that computers connected to the web are . . . . A decoy computer network set up to record every attempt to crack it open and subvert it has revealed just how active and determined malicious hackers have become. Statistics gathered by the network show that computers connected to the web are scanned for weaknesses up to 14 times per day and that, on average, an attempt will be made to break into a net-connected computer every three days. The good news is that this project has highlighted the attack patterns used by hackers, which could help people predict when they are about to face an assault. The link for this article located at BBC is no longer available. . Uncover the functionality of a honeypot system as it captures cybercriminal activities and discerns invasion trends to enhance protective measures.. Honeynet Activity, Hacker Behavior, Cybersecurity Trends. . Anthony Pell

Calendar%202 Dec 26, 2001 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200