Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 36 articles for you...
210

Blumira Uncovers New Log4j Attack Vector via Javascript WebSocket

A basic Javascript WebSocket connection can trigger a local Log4j remote code attack via a drive-by compromise. Wonderful. Truly wonderful. . It doesn't rain, but it pours. Previously, one assumption about the 10 out of 10 Log4j security vulnerability was that it was limited to exposed vulnerable servers. We were wrong. The security company Blumira claims to have found a new, exciting Log4j attack vector . You didn't really want to take this weekend off, did you? Of course not! Instead, you'll be chasing down vulnerable Log4j code ever deeper into your network. According to Blumira, this newly-discovered Javascript WebSocket attack vector can be exploited through the path of a listening server on their machine or local network. An attacker can simply navigate to a website and trigger the vulnerability. Adding insult to injury, WebSocket connections within the host can be difficult to gain deep visibility into. That means it's even harder to detect this vulnerability and attacks using it. The link for this article located at ZDNet is no longer available. . Uncovering a fresh vulnerability in Log4j via JavaScript WebSocket communications prompts significant security alarms.. Log4j Attack Vector, Javascript Exploit, Remote CodeExecution. . Brittany Day

Calendar%202 Dec 18, 2021 User Avatar Brittany Day Security Vulnerabilities
212

Top Cloud Security Threats Facing Linux Operating Systems Today

Linux is growing in popularity due to the impressive security, stability and flexibility of the OS, making it an increasingly attractive attack target. Learn about the top cloud security threats to your Linux system. . Many regard Linux as the most secure operating system due to its stability, flexibility, and open-source nature. Linux is also powerful and dependable when it comes to performance and efficiency. Linux has also proven its superiority by continuing to be the only operating system to be used in all of the world’s top 500 supercomputers. It also supports nontraditional IT applications such as heavy machinery controlling, robotics, high-speed trains, and even major space programs. And in an increasingly cloud-centric world, Linux allows organizations to leverage and get the most of their cloud-based environments and power their digital strategies. But this success has a downside: With Linux an increasingly popular choice for businesses counting on, it is now a major attack vector for cybercriminals looking to find holes in its security. Cybersecurity company Trend Micro released a new research report that sheds light on the current state of Linux security. The report provides several valuable insights and focuses on vulnerability distribution, major threats, and security drawbacks of the Linux operating system. It is especially eye-opening for those who mistakenly believe Linux is invulnerable to attacks. . As Linux in the cloud rises, it shapes infrastructure and cybersecurity. This article uncovers growing threats and essential strategies for robust protection against vulnerabilities. Linux Cloud Security, Cybersecurity Threats, Attack Vectors. . Anthony Pell

Calendar%202 Sep 03, 2021 User Avatar Anthony Pell Cloud Security
209

Understanding Supply Chain Risks and Protective Strategies

Experts including Dr. David Wheeler, Director of Open Source Software Supply Chain Security at the Linux Foundation , discuss the growing trend in software supply chain attacks which use “ dependency or namespace confusion ” techniques, and how to secure software supply chains against these attacks. . Following a growing trend in software supply chain attacks which use “ dependency or namespace confusion ” techniques, I sat down for a discussion on software supply chain security with a few experts on the topic. Dr. David Wheeler, Director of Open Source Software Supply Chain Security at the Linux Foundation Dr. Trey Herr, Director of Cyber Statecraft Initiative at the Atlantic Council Brian Fox, CTO and Co-founder of Sonatype As the attack vector continues to gain further steam in the early months of 2021, we chatted about what’s happening, why this vector has taken off and how organizations can protect ourselves. The link for this article located at Security Boulevard is no longer available. . Fortify your development pipelines against emerging threats by leveraging professional advice and implementable tactics.. Supply Chain Security, Dependency Confusion, Software Protection. . Brittany Day

Calendar%202 Mar 09, 2021 User Avatar Brittany Day Security Trends
83

FBI Alerts: Drovorub Malware Targeting Linux By Russian State Hackers

Drovorub - yet another strain of malware targeting Linux systems - is being used by malicious Russian hackers to spy on users, steal files and hijack devices. . The revelation from the FBI and National Security Agency that Russian military intelligence has built malware to target Linux systems is the latest dramatic twist in the unrelenting cybersecurity battle. The two agencies have revealed that Russian hackers have been using the previously undisclosed malware for Linux systems, called Drovorub, as part of their cyber-espionage operations. The malware allows hackers to steal files and take over devices . . CIA and DHS disclose Kinsing malware utilized by Chinese cybercriminals to target Linux platforms for information theft.. Drovorub Malware, Linux Security Threat, Russian Cyber Attacks, Malware Surveillance. . LinuxSecurity.com Team

Calendar%202 Aug 17, 2020 User Avatar LinuxSecurity.com Team Hacks/Cracks
210

Research on FPGA Cards Improving Rowhammer Attack Efficiency

In a new research paper published on the last day of 2019, a team of American and German academics has shown that field-programmable gate array (FPGA) cards can be abused to launch better and faster Rowhammer attacks. Learn more about how FPGA cards can be abused for faster and more reliable Rowhammer attacks: . The new research expands on previous work into an attack vector known as Rowhammer . Rowhammer attacks were first detailed in 2014. The attack exploits a design flaw in the hardware modern memory cards -- most commonly known as RAM. The link for this article located at ZDNet is no longer available. . The latest study builds upon earlier findings about a vulnerability termed Rowhammer, uncovering exploitation through FPGA manipulation.. Rowhammer Exploit, FPGA Attacks, Memory Exploitation. . Brittany Day

Calendar%202 Jan 02, 2020 User Avatar Brittany Day Security Vulnerabilities
83

O.MG Cable: Malicious Lightning Cable Threat To Computers

Remember the O.MG cable? A project by self-taught electronics hacker _MG_ , it’s a malicious Lightning cable that looks just like the regular overpriced piece of wire that connects your iPhone to a computer. The cable is now about to hit mass distribution. Learn more: . Embedded in it is a tiny Wi-Fi transceiver that can operate as an access point or a wireless client. When the victim plugs it into their computer, an attacker within radio distance can connect to the cable with a mobile app and use it to manipulate the computer. An attacker can reach the O.MG cable from 300 feet away using Wi-Fi from a regular phone, but a suitable booster antenna connected to your computer or phone could enable a connection from even further away. The link for this article located at NakedSecurity is no longer available. . The O.MG cable appears as a normal Lightning cable but hides dangerous capabilities, allowing cyber attackers to exploit users connecting their devices.. Malicious Cable, Wi-Fi Transceiver, Electronics Hack. . LinuxSecurity.com Team

Calendar%202 Oct 02, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
210

phpMyAdmin Zero-Day Advisory: Medium Severity CSRF Attack Risk

Are you a phpMyAdmin user? A researcher has just published a zero-day security bug in one of the web’s most popular database administration software packages. Learn more: . The bug makes it possible for an attacker to delete a server by hijacking a user’s account in phpMyAdmin , a 21-year-old open-source tool used to manage MySQL and MariaDB databases. The flaw is a classic cross-site request forgery (CSRF). It’s a long-used attack in which an attacker can force a logged-in user’s browser to perform malicious actions such as changing their account details. A browser request includes any details associated with the site, such as the user’s session cookie, making it difficult to distinguish between the real request and a forged one. The bug report on the Full Disclosure mailing says that an attack would have to target phpMyAdmin’s setup page. The CVE listing for the bug gives it a medium severity rating. The link for this article located at Naked Security is no longer available. . The bug makes it possible for an attacker to delete a server by hijacking a user’s account inphpMy. phpmyadmin, researcher, published, zero-day, security. . Brittany Day

Calendar%202 Sep 20, 2019 User Avatar Brittany Day Security Vulnerabilities
210

Google Chrome Security Advisory: Address Remote Control Threat Immediately

A security flaw in Google Chrome allows an attacker to eventually take control a vulnerable host, and Google recommends users to deploy a patch as soon as possible. All versions of the browser are affected, including Google Chrome for Linux. Learn more: . The bug was discovered by the Center for Internet Security, who writes that governments might be the primary target of any potential attack. The vulnerability requires users to visit a malicious website, at which point an attacker could attempt to run arbitrary code with the final goal of taking control of the device. The link for this article located at Softpedia News is no longer available. . An urgent vulnerability in Mozilla Firefox has been discovered, which could permit external manipulation through infected webpages. Please upgrade at once to protect your system.. Google Chrome Security, Remote Code Execution, Browser Vulnerability. . Brittany Day

Calendar%202 Sep 02, 2019 User Avatar Brittany Day Security Vulnerabilities
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200