Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 5 articles for you...
212

Exploit Risks of Misconfigured Azure Services in EmojiDeploy Attack Chain

Multiple misconfigurations in a service that underpins many Azure features could have allowed an attacker to remotely compromise a cloud user's system. . An attack chain exploiting misconfigurations and weak security controls in a common Azure service is highlighting how lack of visibility impacts the security of cloud platforms. The "EmojiDeploy" attack chain could allow a threat actor to run arbitrary code with the permission of the Web server, steal or delete sensitive data, and compromise a targeted application, Ermetic stated in its Jan. 19 advisory . An attacker could use a trio of security issues affecting the common Source Code Management (SCM) service — a cloud service used by many Azure applications without an explicit indication to the user, according to Ermetic. The issues demonstrate that the security of cloud platforms are undermined by the lack of visibility into what those platforms do under the hood, says Igal Gofman, head of research for Ermetic. The link for this article located at DarkReading is no longer available. . A vulnerability pathway leveraging insufficient configurations and lax defenses in a widely used Azure platform could present significant threats.. AzureService, CloudSecurity, MisconfigurationRisk, AttackChain. . Brittany Day

Calendar 2 Jan 26, 2023 User Avatar Brittany Day Cloud Security
79

Exploring Microsoft Project Freta: Free Service For Linux Forensics

Have you heard about Microsoft's Project Freta - a new free-to-use Linux forensics and rootkit malware detection service? . The cloud offering, dubbed Project Freta , is a snapshot-based memory forensic mechanism that aims to provide automated full-system volatile memory inspection of virtual machine (VM) snapshots, with capabilities to spot malicious software, kernel rootkits , and other stealthy malware techniques such as process hiding . The project is named after Warsaw's Freta Street , the birthplace of Marie Curie, the famous French physicist who brought X-ray medical imaging to the battlefield during World War I. The link for this article located at The Hacker News is no longer available. . Google's Project Tremor provides a complimentary online platform for Windows memory analysis and malware identification tools.. Linux Forensics, Project Freta, Rootkit Detection, Cloud Service, Malware Detection. . LinuxSecurity.com Team

Calendar 2 Jul 07, 2020 User Avatar LinuxSecurity.com Team Security Projects
74

Key Security Questions For Assessing Cloud Service Providers

As security teams try to help line-of-business users and other IT practitioners take advantage of cloud benefits as safely as possible, they're increasingly stepping into the role of trusted advisor. The scalability, flexibility, and convenience of software-as-a-service (SaaS), infrastructure-as-a-service (IaaS), and platform-as-a-service (PaaS) offerings frequently come at the cost of added risk to the business. . It is up to information security pros to help evaluate potential providers to best evaluate where those risks are coming from. Dark Reading talked to a number of experts to come up with 10 must-answer questions that security personnel should get the business in the habit of asking before signing a service agreement. The link for this article located at Dark Reading is no longer available. . It is up to information security pros to help evaluate potential providers to best evaluate where th. security, teams, line-of-business, users, other, practitioners, advantage. . Anthony Pell

Calendar 2 May 14, 2015 User Avatar Anthony Pell Network Security
83

CodeSpaces.com Cloud Breach: Critical Data Loss Incident

A code-hosting and project management services provider was forced to shut down operations indefinitely after a hacker broke into its cloud infrastructure and deleted customer data, including most of the company's backups. . The customers of CodeSpaces.com, run by a company based in Wayne, New Jersey, called AbleBots, were informed Wednesday that their data might have been permanently lost following the compromise of the company's account on Amazon's Elastic Compute Cloud (EC2). The link for this article located at TechWorld is no longer available. . DataVault.io faced a significant security incident that compromised user information and system backups, leading to a halt in operations.. Cloud Security Threats, Code Hosting Risks, Data Breach Incidents. . LinuxSecurity.com Team

Calendar 2 Jun 19, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Google Cloud Transitioning To Debian Distribution For Services

Google has been using its own custom version of Linux, Google Compute Engine Linux, as it loads its customers' applications into its infrastructure as a service. . It announced Thursday that it's dropping that approach in favor of using the Debian Linux distribution. Debian Linux is the output of the Debian open source code project. All Linuxes use a kernel produced by the Linux kernel development process, led by Linus Torvalds. But Linux distributors surround the kernel with features that may match other Linux distributions or may differentiate that particular distribution. For example, Ubuntu was an early cloud supporter when it included Eucalyptus modules; then it switched to OpenStack as its primary cloud offering. The link for this article located at Information Week is no longer available. . Amazon moves from proprietary software to Ubuntu for its server solutions, boosting interoperability within the open-source ecosystem.. Google Cloud, Debian Linux, Cloud Infrastructure, Open Source Project. . Anthony Pell

Calendar 2 May 13, 2013 User Avatar Anthony Pell Network Security
83

Evernote Data Breach: 50 Million Users Affected After Password Reset

Evernote and its 50 million-user population are having a bad week. The productivity software-as-a-service issued a systemwide password reset for all of its users on Saturday after a hacker or group of hackers broke into its user database and swiped various bits of user information, including usernames, emails and passwords.. It's another weapon in the arsenal of cloud skeptics, who tend to point at breaches like this as proof the cloud is not secure. Of course, that's ridiculous, as these breaches are less common than attacks or theft within the four walls of a business. Still, Evernote is coming under fire The link for this article located at Read this full article is no longer available. . It's another weapon in the arsenal of cloud skeptics, who tend to point at breaches like this as pro. evernote, million-user, population, having, productivity, software-as-a-se. . LinuxSecurity.com Team

Calendar 2 Mar 06, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

SHA-1 Exploit By Thomas Roth: Cloud Services And Wireless Security

A hacker claims he's used Amazon's cloud services to bust open SHA-1, a wireless network security standard, and he says he'll be demonstrating his process at an upcoming Black Hat get-together. Malicious hackers could quickly set up brute-force attack systems using the cloud, but critics say real-world password cracks might not come so easily.. German hacker Thomas Roth's announcement that he used Amazon.com's (Nasdaq: AMZN) cloud service to crack a wireless network security standard has left some security researchers scratching their heads. Others are merely shaking them in disbelief. That attack was launched against the SHA-1 hash algorithm. Roth's conclusions are that the SHA-1 algorithm is not fit for password hashing, and the compute power offered by cloud services makes it cheap and easy to launch brute-force attacks on passwords. However, it's been known since 2005 that the SHA-1 algorithm has flaws, and the National Institute of Standards and Technology is seeking to replace it. The link for this article located at Tech News World is no longer available. . German hacker Thomas Roth's announcement that he used Amazon.com's (Nasdaq: AMZN) cloud service to c. hacker, claims, amazon's, cloud, services, sha-1, wireless, network, security. . LinuxSecurity.com Team

Calendar 2 Jan 12, 2011 User Avatar LinuxSecurity.com Team Cryptography
74

VeriSign Launches Cloud-Based DNSSec Signing Service for Registrars

VeriSign has announced the rollout of its cloud-based DNSSec Signing Service for registrars, which allows DNSSec provisions to be added to second-level domain names. Pat Kane, assistant general manager of naming services at VeriSign, told V3.co.uk that progress being made is at the registry and root levels. . "Root signing is key to building a safer infrastructure and the real heavy lifting on that is done by the registrars. Today we've begun to enable the tools to help registrars meet the demands of their customers," he said. More and more domains are signing up to DNSSec, Kane added, including full integration with .edu. Registrars will be able to evaluate the service until the end of next year. DNSSec provides a better level of security that existing provisions and is useful at thwarting man-in-the-middle and cache poisoning attacks. . Cloudflare launched a new DNS Firewall solution aimed at improving protection for enterprise networks against threats.. DNSSec Signing Service, VeriSign Security, Registrar Tools, Domain Signing, Cloud Security. . Alex

Calendar 2 Dec 02, 2010 User Avatar Alex Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here