Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
210

Chrome 134 Update: Critical Fixes for Linux Users' Security

Google recently took an important step toward increasing web browsing security by unveiling Chrome 134 to patch several severe vulnerabilities. As a Linux administrator, staying informed on such updates to protect systems against potential threats is paramount. This release addresses critical issues like an out-of-bounds read in V8 and defects across DevTools Profiles and PDFium. . Keeping your Chrome browser updated, as cyber threats become increasingly sophisticated, can significantly lower security risks and ensure an enhanced browsing experience. Let's take a look at the bugs fixed in Chrome 134, their potential impact, and ways we can best protect ourselves as Chrome users. Understanding the Chrome 134 Security Update Chrome 134 marks an exceptional leap forward in browser security, patching multiple critical and high-severity vulnerabilities reported by Zhenghang Xiao and Nan Wang as CVE-2025-1914 . These vulnerabilities could result in crashes, data corruption, or remote attacks to exploit and execute code - this finding is especially noteworthy given that V8 serves as Chrome's JavaScript engine that renders webpages and runs scripts. DevTools vulnerabilities such as CVE-2025-1915 were also addressed, which are essential for debugging and optimizing web applications. It was discovered that improperly restricting pathnames to restricted directories posed a risk of unauthorized access. Other medium-severity issues include use-after-free vulnerabilities in Profiles ( CVE-2025-1916 ) and inappropriate implementations in Browser UI ( CVE-2025-1917 ), both of which enable attackers to compromise browser stability and security. Low-severity issues were also addressed, including improper implementations in Selection and Permission Prompts ( CVE-2025-1922 and CVE-2025-1923 ). Examining The Impact of These Fixes The fixes introduced in Chrome 134 are critical for all impacted Chrome users. If left unpatched, these vulnerabilities could allow attackers to execute arbitrary code,steal sensitive information, or crash the browser, causing significant disruptions. High-severity vulnerabilities, such as out-of-bounds reads and use-after-free bugs, can cause serious harm. Attackers might exploit these flaws to bypass security measures built into your OS or browser. By addressing these flaws, Chrome 134 helps block potential exploit paths, further strengthening your systems' security posture. Medium and low severity issues may seem less immediately concerning; however, they still play an essential part in increasing browser robustness and resilience. Security only stands up when all weak links are properly addressed. Minor problems can often become part of larger attack strategies, so every fix contributes to creating a safer browsing environment overall. Ensuring Your Chrome Browser Is Protected Staying up-to-date is critical to protecting against potential vulnerabilities in Chrome browsers. While updating on Linux can be relatively painless, updating all systems across an organization requires time and attention. Start by opening Chrome and entering its settings menu (represented by three vertical dots in the upper right corner). From here, navigate to Help > About Google Chrome for help. If an update is available, it will automatically download. Once this process has finished, it's important to relaunch the browser to complete its installation. Although updates on individual machines can be managed manually, automating updates across an enterprise can be simplified using various system management tools such as Puppet , Chef , or even simple cron jobs. These tools streamline this process and ensure all users within a network receive critical security patches without manual intervention. This automation saves time and ensures all critical patches are applied promptly. Debian , Mageia and openSUSE have released important security advisory updates regarding fixes for these flaws. It is crucial that all impacted users apply the updates released by theirdistro(s) promptly to mitigate risk. Reporting Issues and Contributing to Security Once you detect issues or vulnerabilities, you must report them promptly. Google offers bug bounties for serious security vulnerabilities to encourage researchers and professionals to discover and fix flaws quickly. You can report problems by filing an entry in Chrome Bug Tracker with as much detail as possible so developers can address them efficiently. Participating actively in Chrome's reporting process improves its security while providing a safer internet for all. Your participation helps foster collaboration within the broader cybersecurity community, strengthening security and creating greater resilience. Our Final Thoughts on the Significance of the Chrome 134 Update Chrome 134 marks an important advancement toward safeguarding browsing experiences for all users, particularly enterprise environments where security cannot be compromised. As a Linux security admin, it is critical to ensure your browser remains updated against newly discovered vulnerabilities. Understanding their impact and maintaining timely updates will significantly lower risk. Staying informed via official channels such as Chrome Releases and actively engaging in the security community are great ways to build and sustain an effective security posture for your organization. Reporting issues also helps strengthen Chrome's security infrastructure, creating a safer internet. By taking these steps you are both protecting yourself and contributing to efforts by individuals worldwide to strengthen web security. . The latest Chrome 134 patch resolves severe vulnerabilities, boosting the browser's protection for users on macOS.. Chrome Update, Linux Browser Security, Software Patching, Cyber Threats, V8 Security. . Brittany Day

Calendar%202 Mar 13, 2025 User Avatar Brittany Day Security Vulnerabilities
81

Chrome Extensions Threat: 33 Million Downloads In Eavesdropping Campaign

Have you heard that Google has removed scores of malicious and fake Chrome extensions being used in a global eavesdropping campaign? . The threat was spotted by Awake Security, which detected 111 of the malicious extensions over the past three months. When it notified Google of the issue last month, it claimed that 79 were present in the Chrome Web Store, where they had been downloaded nearly 33 million times. Figures for the others not in the official marketplace are hard to calculate for obvious reasons. “These extensions can take screenshots, read the clipboard, harvest credential tokens stored in cookies or parameters, grab user keystrokes (like passwords), etc,” it said in a report detailing the investigation. . The discovery of over 33 million downloads of harmful Chrome extensions poses a critical risk to security, underscoring the importance of protecting user privacy.. chrome extensions, malicious software, eavesdropping threats, user privacy. . LinuxSecurity.com Team

Calendar%202 Jun 19, 2020 User Avatar LinuxSecurity.com Team Privacy
210

Chrome Bug Bounty Rises To $30,000 For Security Reports

Attention ethical hackers: Google has just announced that it decided to increase the bounties offered for Google Chrome browser security vulnerabilities, with the maximum payment now reaching $30,000! . The Google Chrome Vulnerability Rewards Program was released in 2010, and the search giant says it received no less than 8,500 reports since then. Furthermore, the bounties that it offered as part of the program total more than $5 million. Now Google is willing to pay even more for Chrome security vulnerabilities, so the maximum baseline reward amount is increased from $5,000 to $15,000. Furthermore, the top bounty is now $30,000, up from $15,000. The link for this article located at Softpedia News is no longer available. . Google boosts rewards for Chrome security flaws, offering as much as $30,000 for submissions.. Google Chrome Bounty, Ethical Hacking Opportunities, Browser Security Rewards. . Brittany Day

Calendar%202 Jul 19, 2019 User Avatar Brittany Day Security Vulnerabilities
81

Refined JavaScript Techniques for History Theft Exploits

Two developers have refined techniques for rummaging through browser histories to the extent that web sites can now find out what articles a user has recently read on news sites, their exact postcode and which search terms that have entered into search engines. The developers, Artur Janc and Lukasz Olejnik, have now refined their JavaScript code to carry out history stealing six times faster than previous methods.. History stealing makes use of the way browsers record whether users have previously clicked on a link (a simple online test is available). Previously clicked links are displayed in a different colour to links to pages which have not yet been visited. The different colours are produced by a change in the style sheet (CSS) for the HTML file, which the browser stores as an attribute in its history. JavaScript can be used to test a list of potential web sites and the style sheet's colour scheme and work out which web sites have been visited. The longer the list, the greater the chance of scoring a hit. The refined JavaScript code allows a web site to test 30,000 links per second. There are also methods for accessing browser history which do not make use of JavaScript. These involve taking advantage of the ability to use style sheets to load different background images depending on whether or not a web site has previously been visited. An attacker can query a user's history without using JavaScript by using crafted HTML pages and observing which images the web pages load. Janc and Olejnik have also included this method, which they claim works even where JavaScript is disabled and plug-ins like NoScript are installed, in their test. The link for this article located at H Security is no longer available. . History stealing makes use of the way browsers record whether users have previously clicked on a lin. developers, refined, techniques, rummaging, through, browser, histories, extent. . LinuxSecurity.com Team

Calendar%202 May 24, 2010 User Avatar LinuxSecurity.com Team Privacy
83

Adobe Flash Attack Exposes User Content to Malware Risks

Researchers show how Adobe Flash can be exploited in browsers when victim visits sites that accept user-generated content. Researchers have discovered a new attack that exploits the way browsers operate with Adobe Flash -- and there's no simple patch for it. . The attack can occur on Websites that accept user-generated content -- anything from Webmail to social networking sites. An attacker basically takes advantage of the fact that a Flash object can be loaded as content onto a site and then can execute malware from that site to infect and steal information from visitors who view that content by clicking it. "Everyone is vulnerable to this, and there's nothing anyone can do to fix it by themselves," says Michael Murray, CSO for Foreground Security, which today posted demonstrations of such an attack against Gmail, SquirrelMail, and cPanel's File Manager. "We're hoping to get a message out to IT adminstrators and CIOs to start fixing their sites one at a time." Do you feel like you could be a victim of this attack, or do you think that you don't go to sites that would be risky enough to be subjected to this attack? How often do you look for vendor vulnerabilities like this? Please let us know! The link for this article located at Dark Reading is no longer available. . The attack can occur on Websites that accept user-generated content -- anything from Webmail to soci. researchers, adobe, flash, exploited, browsers, victim, visits, sites, accept. . LinuxSecurity.com Team

Calendar%202 Nov 13, 2009 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Google Chrome: Immediate Security Flaws and Potential Exploits

Less than a day after Google arrived on the browser scene with the launch of Chrome, two security researchers have disclosed separate vulnerabilities that could be exploited to compromise the software. Researcher Aviv Raff told SCMagazineUS.com on Wednesday that Chrome suffers from the same . The link for this article located at SC Magazine is no longer available. . The link for this article located at SC Magazine is no longer available.. google, arrived, browser, scene, launch, chrome, security. . Brittany Day

Calendar%202 Sep 04, 2008 User Avatar Brittany Day Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200