Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 28 articles for you...
79

Google Enhances Rewards For Identifying Linux Kernel Exploits

'Experimental mitigations' in a custom kernel could make life harder for hackers. . Google says it uses Linux in "almost everything" from Chromebooks to the cloud. Now it is increasing its rewards for security researchers who can spot flaws in the open-source operating system. Since 2020, Google has run an open-source Kubernetes-based Capture-the-Flag (CTF) project called kCTF which allows researchers to connect to its Google Kubernetes Engine (GKE) instances, and try to hack them to capture a flag. Every 'flag' caught so far has been a container breakout through a Linux kernel vulnerability. . Microsoft, heavily invested in cloud computing, increases incentives for developers uncovering software vulnerabilities, fortifying system defenses.. Linux Kernel Flaws, Google Security, Open Source Research, Kubernetes Capture-the-Flag. . LinuxSecurity.com Team

Calendar%202 Aug 12, 2022 User Avatar LinuxSecurity.com Team Security Projects
76

Google Launches Triple Reward Bug Bounty For Linux Kernel Flaws

Linux is everywhere and it needs extra protection, according to Google. "We are constantly investing in the security of the Linux Kernel because much of the internet, and Google – from the devices in our pockets, to the services running on Kubernetes in the cloud – depend on the security of it," said Eduardo Vela from the Google Bug Hunters Team . . Google has kicked off a special three-month bug bounty targeting flaws in the Linux kernel with triple the rewards for security researchers. The new bounty, announced this week , looks to harden the Linux kernel in specific edge cases. It's offering up to $31,337 ( Leet ) to security researchers who can exploit privilege escalation in Google's lab environment with a patched vulnerability; and $50,337 for anyone who can finds a previously undisclosed or zero-day flaw, or for discovering a new exploit technique. . Google has introduced a quarterly bug bounty program targeting vulnerabilities within the Linux kernel, significantly enhancing incentives for security researchers.. Linux Kernel Security, Bug Bounty Program, Security Research, Exploit Techniques. . Brittany Day

Calendar%202 Nov 03, 2021 User Avatar Brittany Day Organizations/Events
79

Microsoft's $100K Bug Bounty For Securing Azure Sphere Technology

Researchers have three months to find problems in the software for net-connected devices like baby monitors and refrigerators. . Microsoft wants Azure Sphere to be a really secure foundation for internet of things devices like webcams and garage doors, so it's offering researchers up to $100,000 to find a way to break into the technology. Azure Sphere combines an approved processor with Microsoft's own customized version of Linux called Sphere OS and a security service to detect problems and issue updates. . Microsoft has introduced a substantial $100K initiative to attract bug hunters, enhancing Azure Sphere's security for smart home tech, showcasing its commitment to safeguarding IoT devices.. Azure Sphere Security,Bug Bounty Program,IoT Device Protection. . LinuxSecurity.com Team

Calendar%202 May 08, 2020 User Avatar LinuxSecurity.com Team Security Projects
79

Azure Sphere OS Bug Bounty: Win Up To $100,000 Testing Security

Microsoft is offering hackers up to $100,000 if they can break the security of the company’s custom Linux OS. The software giant built a compact and custom version of Linux last year for its Azure Sphere OS, which is designed to run on specialized chips for its Internet of Things (IoT) platform. The OS is purpose-built for this platform, ensuring basic services and apps run isolated in a sandbox for security purposes. . Microsoft now wants hackers to test the security of the Azure Sphere OS, paying up to $100,000 if the Pluton security subsystem or Secure World sandbox is breached. The bug bounty program is part of a three-month research challenge that runs from June 1st until August 31st. “We will award up to $100,000 bounty for specific scenarios in the Azure Sphere Security Research Challenge during the program period,” explains Sylvie Liu, a security program manager at Microsoft’s Security Response Center. . Google is providing $150,000 for evaluating the security of its Android platform, showcasing a significant initiative in enhancing cybersecurity.. Azure Sphere OS, Microsoft Security, bug bounty program, IoT security. . LinuxSecurity.com Team

Calendar%202 May 06, 2020 User Avatar LinuxSecurity.com Team Security Projects
79

Kubernetes Bug Bounty Program: Join and Secure Containerization

Want to help lock down Kubernetes and make some money while you're at it? The Cloud Native Computing Foundation has a new bug bounty program for you. . Kubernetes , the container orchestration program, has become hotter than hot. Everyone -- and I mean everyone -- is adopting it . But with quarterly major updates and everyone rushing to deploy it, security is a real worry. Thus, the Kubernetes Product Security Committee, funded by the Cloud Native Computing Foundation (CNCF) is launching a new bug bounty program to reward Kubernetes security bug hunters. The bug bounty program has been in a private beta release for several months now. Almost two years since the initial proposal, the program is now ready for all security researchers. The link for this article located at ZDNet is no longer available. . Participate in the exciting Kubernetes security initiative to enhance digital safety and receive incentives for your findings.. Kubernetes Bug Bounty, Container Security, Cloud Native Computing. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2020 User Avatar LinuxSecurity.com Team Security Projects
78

NordVPN: Enhancements After Server Breach and Cybersecurity Audit

Following an attack that breached one of its servers, NordVPN is taking several steps in an effort to show customers that it can still provide secure access to the internet. Learn more: . NordVPN is taking steps to ensure customers that it can stay true to its promise of providing "secure and private access to the internet" after admitting that an attacker breached one of its servers. To start with, its in-house team of penetration testers will now be working with cybersecurity firm VerSprite to conduct comprehensive penetration testing, intrusion handling and source code analysis. The firm will also help NordVPN form an independent cybersecurity advisory committee as part of their long-term partnership. In an effort to find vulnerabilities before a bad actor does again, it's also launching a bug bounty program over the next few weeks. NordVPN also promises to undergo a complete a full-scale third-party independent security audit covering its hardware, software, backend architecture, backend source code and internal procedures in 2020. The link for this article located at Engadget is no longer available. . Following a server compromise, NordVPN is bolstering its security protocols by implementing comprehensive audits and introducing a bug bounty initiative.. NordVPN, Security Audit, Threat Management, Bug Bounty, Cybersecurity Enhancement. . LinuxSecurity.com Team

Calendar%202 Oct 30, 2019 User Avatar LinuxSecurity.com Team Vendors/Products
79

Optimizing Bug Bounty Programs for Enhanced Security and Efficiency

In this article, Threatpost catches up with David Baker, the chief security officer at Bugcrowd, about the future of bug bounty programs. While bug-bounty programs may seem like a cure-all solution for companies looking discover vulnerabilities in their systems more efficiently, the fact remains that a program could overwhelm a firm’s internal security team and cause other major headaches if implemented the wrong way. . “You have to realize that the crowd is going to find a lot more vulnerabilities than your typical in-house pen-test team. So oftentimes, there’s this engineering push back, like hold on, we don’t have our internal processes set up,” David Baker, chief security officer at Bugcrowd told Threatpost. Threatpost caught up with Baker to discuss the right — and wrong — approaches for implementing a bounty program that can boost companies’ security effectively with minimal operational disruption. The link for this article located at Threatpost is no longer available. . Exploring strategies for successful bug bounty programs reveals the importance of clarity, communication, and community engagement in enhancing security and processes. Bug Bounty Programs, Security Approaches, Vulnerability Management, Crowdsourced Testing, Operational Efficiency. . LinuxSecurity.com Team

Calendar%202 Jul 12, 2019 User Avatar LinuxSecurity.com Team Security Projects
76

Dropbox Bug Hunt: 264 Flaws Uncovered With $319,300 Reward

Dropbox has uncovered 264 vulnerabilities, paying out US$319,300 in bounties, after a one-day bug hunt in Singapore that brought together hackers from 10 nations around the world. Hosted by bug bounty platform HackerOne, the live event saw 45 of its members from countries such as Japan, India, Australia, Hong Kong, and Sweden, and some as young as 19, galvanise in the city-state in an attempt to infiltrate Dropbox's targeted systems. . The cloud storage vendor days earlier had revealed parts of its "attack" scope, so HackerOne members already had identified and submitted dozens of potential bugs before the live event. According to a company spokesperson, the focus this time was on Dropbox and its recent acquisition of digital workflow platform, HelloSign. The link for this article located at ZDNet is no longer available. . Dropbox's bug hunt uncovered 264 vulnerabilities, rewarding hackers with $319,300 for their findings in Singapore.. dropbox, uncovered, vulnerabilities, paying, us$319, bounties, one-day. . Brittany Day

Calendar%202 Apr 06, 2019 User Avatar Brittany Day Organizations/Events
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200