Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 3 articles for you...
83

Dropbox Security Breach: GitHub Code Theft via Phishing Attack

Dropbox has revealed details of a phishing attack to which it fell victim. In the attack, a threat actor was able to steal code from the company after gathering employee credentials to GitHub repositories.. The security breach took place in the middle of last month, with GitHub notifying Dropbox of suspicious account activity on October 14. The cloud storage company says that the code that was accessed "contained some credentials -- primarily, API keys -- used by Dropbox developers" but insists that "no one's content, passwords, or payment information was accessed", and that its core apps and infrastructure were unaffected. In a blog post that goes into some detail about the incident, Dropbox says: "In today's evolving threat landscape, people are inundated with messages and notifications, making phishing lures hard to detect. Threat actors have moved beyond simply harvesting usernames and passwords, to harvesting multi-factor authentication codes as well. In September, GitHub detailed one such phishing campaign, in which a threat actor accessed GitHub accounts by impersonating the code integration and delivery platform CircleCI. We recently learned that Dropbox was targeted by a similar campaign. . Dropbox encountered a serious cybersecurity incident, in which source code was compromised from GitHub through phishing tactics; however, essential systems remain intact.. Dropbox Security, GitHub Phishing Attack, Code Theft Risk, API Key Protection. . LinuxSecurity.com Team

Calendar%202 Nov 02, 2022 User Avatar LinuxSecurity.com Team Hacks/Cracks
76

Dropbox Bug Hunt: 264 Flaws Uncovered With $319,300 Reward

Dropbox has uncovered 264 vulnerabilities, paying out US$319,300 in bounties, after a one-day bug hunt in Singapore that brought together hackers from 10 nations around the world. Hosted by bug bounty platform HackerOne, the live event saw 45 of its members from countries such as Japan, India, Australia, Hong Kong, and Sweden, and some as young as 19, galvanise in the city-state in an attempt to infiltrate Dropbox's targeted systems. . The cloud storage vendor days earlier had revealed parts of its "attack" scope, so HackerOne members already had identified and submitted dozens of potential bugs before the live event. According to a company spokesperson, the focus this time was on Dropbox and its recent acquisition of digital workflow platform, HelloSign. The link for this article located at ZDNet is no longer available. . Dropbox's bug hunt uncovered 264 vulnerabilities, rewarding hackers with $319,300 for their findings in Singapore.. dropbox, uncovered, vulnerabilities, paying, us$319, bounties, one-day. . Brittany Day

Calendar%202 Apr 06, 2019 User Avatar Brittany Day Organizations/Events
81

Exposed iSCSI Storage Clusters Present Major Data Breach Threats

Over 13,000 iSCSI storage clusters are currently accessible via the internet after their respective owners forgot to enable authentication. . This misconfiguration has the risk of causing serious harm to devices' owners, as cyber-criminal groups could access these internet-accessible hard drives (storage disk arrays and NAS devices) to replace legitimate files with malware, insert backdoors inside backups, or steal company information stored on the unprotected devices. The link for this article located at ZDNet is no longer available. . More than 12,000 open SMB file shares can be found on the internet, posing a threat of unapproved access and possible information leaks.. iSCSI Access Risk, Storage Cluster Security, Internet Vulnerability. . LinuxSecurity.com Team

Calendar%202 Apr 02, 2019 User Avatar LinuxSecurity.com Team Privacy
83

Dropbox Data Breach: Customer Data Compromised Causing Spam Issues

Cloud storage service provider Dropbox has acknowledged that a file containing private customer data was stolen from the Dropbox account of one of the company's employees and that the information was subsequently used to send out spam messages to users.. In mid-July, a number of Dropbox users complained that they were receiving spam at email addresses used exclusively to sign into the storage service. As it turns out, this was no coincidence The link for this article located at H Security is no longer available. . In mid-July, a number of Dropbox users complained that they were receiving spam at email addresses u. cloud, storage, service, provider, dropbox, acknowledged, containing, private, customer. . LinuxSecurity.com Team

Calendar%202 Aug 01, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Increased Spam Attacks Targeting Dropbox Users From Online Casinos

Spammers are currently sending large volumes of spam to users of cloud storage service provider Dropbox. The H's associates at heise Security have so far received four different pieces of German-language spam at an email address used solely to register with Dropbox, and some of their readers have reported the same problem; similar reports can also be found on the Dropbox forums. In almost all cases, the spam is for suspicious-looking online casinos.. The link for this article located at H Security is no longer available. . Fraudsters prey on OneDrive users with questionable betting site advertisements. Check out the concerning testimonials from victims and analysts.. Dropbox Spam Attacks, Online Casino Fraud, Email Threats. . LinuxSecurity.com Team

Calendar%202 Jul 18, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
82

Megaupload Legal Threats: Possible File Deletion On February 2, 2012

Federal prosecutors who accuse file-sharing site Megaupload of being a hotbed of digital piracy say the site's customer files, presumably including perfectly legal ones, may be deleted starting Thursday. . "It is our understanding that the hosting companies may begin deleting the contents of the servers beginning as early as February 2, 2012," U.S. Attorney Neil H. MacBride said in a letter filed in federal court. The letter, submitted Friday in the Eastern District of Virginia, says that government investigators have finished executing search warrants at centers where Megaupload and MegaVideo files are stored. The link for this article located at CNN is no longer available. . Court alerts indicate possible removal of Dropbox's content in light of copyright concerns. Keep updated.. Megaupload Data Deletion, Digital Piracy Risks, Cloud Storage Legal Issues. . Dave Wreski

Calendar%202 Jan 31, 2012 User Avatar Dave Wreski Government
67

Dropbox Security Investigation Over User Data Breach Risks

Popular cloud storage service Dropbox is misleading users into thinking it is more secure than it really is, says a security researcher and academic, who has asked for the FTC to investigate.. Dropbox has around 25 million users. It's often used as an escape hatch by owners of Apple's iPhone and iPad: the iOS slabs don't expose the device's local file system or provide the end user with a way of manipulating files. "Dropbox's customers face an increased risk of data breach and identity theft because their data is not encrypted according to industry best practices," says Christopher Soghoian, who filed the complaint. Soghoian is a researcher at the Center for Applied Cybersecurity Research at Indiana University. He explains that unlike other cloud services The link for this article located at The Register UK is no longer available. . Dropbox has around 25 million users. It's often used as an escape hatch by owners of Apple's iPhone . popular, cloud, storage, service, dropbox, misleading, users, thinking, secure. . LinuxSecurity.com Team

Calendar%202 May 16, 2011 User Avatar LinuxSecurity.com Team Cryptography
81

Evaluating Google's Cloud Storage Trust Amid Security Concerns

Google is pushing full steam ahead with their office strategy, and their hope is to convince a lot of individuals and businesses to trust Google enough to store their documents on Google's servers instead of their own computers, or servers under their control. The fact that unauthorized document access is a simple password guess or government "request" away already works against them. But the steady stream of minor security incidents we've seen (many very recently) can also hurt Google in the long run. Running applications for businesses is serious stuff, and Google needs to be diligent about security. . The link for this article located at TechCrunch is no longer available. . Google's security missteps can erode user trust, leading individuals and businesses to reconsider their cloud data storage options amid growing competition.. Google Security, Cloud Storage Risks, User Trust Issues, Data Privacy, Business Application Security. . LinuxSecurity.com Team

Calendar%202 Oct 19, 2006 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200