Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 8 articles for you...
210

PHP: CVE-2023-0567 Critical Risk: Bypass Password Check Threat

It was recently discovered that PHP could be made to bypass password checking if a specially crafted input was provided (CVE-2023-0567). . This flaw could possibly allow applications to accept any password as valid, contrary to expectations, potentially leading to the compromise of critical systems and sensitive information. With a low attack complexity, no user interaction required, and a high confidentiality impact, it is crucial that all impacted users apply the PHP updates issued but their distro(s) immediately to protect the privacy and confidentiality of their systems and their sensitive data. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . A significant vulnerability in PHP may allow applications to circumvent password verification, thereby endangering confidential information.. PHP Vulnerability, Bypass Security, Critical Threat. . Brittany Day

Calendar%202 May 11, 2023 User Avatar Brittany Day Security Vulnerabilities
81

250,000 Exposed US Diplomatic Cables Raise Security Concerns

Some 250,000 diplomatic dispatches from the US State Department have accidentally been made completely public. The files include the names of informants who now must fear for their lives. It is the result of a series of blunders by WikiLeaks and its supporters.. In the end, all the efforts at confidentiality came to naught. Everyone who knows a bit about computers can now have a look into the 250,000 US diplomatic dispatches that WikiLeaks made available to select news outlets late last year. All of them. What's more, they are the unedited, unredacted versions complete with the names of US diplomats' informants -- sensitive names from Iran, China, Afghanistan, the Arab world and elsewhere. The link for this article located at Spiegel is no longer available. . In the end, all the efforts at confidentiality came to naught. Everyone who knows a bit about comput. diplomatic, dispatches, state, department, accidentally, complete. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2011 User Avatar LinuxSecurity.com Team Privacy
81

Lessons From WikiLeaks: Security Practices and Data Handling Risks

IT and security professionals routinely use USBs, smartphones, and tablets to move and back up confidential files, yet their organizations haven't made changes in the wake of the WikiLeaks leaks.. Maybe the massive disclosure of diplomatic memos from the U.S. State Department by WikiLeaks didn't serve as much of a cautionary tale for preventing the leak of sensitive data after all: Most IT and security professionals say they use USBs, smartphones, and tablets to move and back up confidential files, and 65 percent say they don't have a handle on what files and data leave the enterprise, a new survey says. The survey of 200 IT and security pros at the RSA Conference last month in San Francisco revealed some risky practices by users who theoretically should know better -- including 77 percent saying that they send payroll, customer data, financial, and other classified information via unsecured email monthly. "One thing we know is that people do what they need to do to be productive, and they find their own mechanisms to do this better. This is not malicious, but it puts companies at risk," says Hugh Garber, product marketing manager for Ipswitch, which conducted the survey. "If there's not a tool, they use their own stuff -- a lot are turning to USB drives, file-sharing sites, and their personal email [if corporate email restricts file-size attachments, for instance]. And that just enforces lower visibility to IT and brings more risk." The link for this article located at Dark Reading is no longer available. . Maybe the massive disclosure of diplomatic memos from the U.S. State Department by WikiLeaks didn't . security, professionals, routinely, smartphones, tablets, confi. . LinuxSecurity.com Team

Calendar%202 Mar 09, 2011 User Avatar LinuxSecurity.com Team Privacy
81

WikiLeaks Allegation Of P2P Misuse For Accessing Confidential Documents

As much as half of the secret documents posted by WikiLeaks may have been siphoned from peer-to-peer users who incorrectly configured their file-sharing software, according to evidence gathered by a security firm.. Tiversa, a Pennsylvania company that in 2009 uncovered confidential blueprints of the US President's Marine One helicopter being traded over P2P networks, told Bloomberg News the evidence suggests that WikiLeaks volunteers actively sought out confidential documents, despite claims by the whistle-blower website that it doesn't know who provides it with the information it gets. The link for this article located at The Register UK is no longer available. . Tiversa, a Pennsylvania company that in 2009 uncovered confidential blueprints of the US President's. secret, documents, posted, wikileaks, siphoned, peer-to-peer. . LinuxSecurity.com Team

Calendar%202 Jan 24, 2011 User Avatar LinuxSecurity.com Team Privacy
67

Effective Encryption Methods to Safeguard Sensitive Information

Here's the perfect plan to solve all those pesky security problems. Confidentiality and data leakage, secure backups, individual privacy, data integrity, identity and access management - all can be dealt with in some way by encryption. So why don't we all just use it then, and be done?. Of course encryption is out there, embedded in various technologies The link for this article located at The Register UK is no longer available. . Of course encryption is out there, embedded in various technologies The link for this article locate. here's, perfect, solve, those, pesky, security, problems, confidentiality, leakage. . LinuxSecurity.com Team

Calendar%202 Jun 07, 2010 User Avatar LinuxSecurity.com Team Cryptography
81

Revolutionary Optical Method Enhances Data Security Over Public Networks

At this week's annual meeting of the Optical Society of America in Rochester, N.Y., Bernard Wu and Evgenii Narimanov of Princeton University will present a method for transmitting secret messages over existing public fiber-optic networks, such as those operated by Internet service providers. This technique could immediately allow inexpensive, widespread, and secure transmission of confidential and sensitive data by governments and businesses. Wu and Narimanov's technique is not the usual form of encryption, in which computer software scrambles a message. Instead, it's a more hardware-oriented form of encryption--it uses the real-world properties of an optical-fiber network to cloak a message. . The sender transmits an optical signal that is so faint that it is very hard to detect, let alone decode. The method takes advantage of the fact that real-world fiber-optics systems inevitably have low levels of "noise," random jitters in the light waves that transmit information through the network. The new technique hides the secret message in this optical noise. The link for this article located at PhyOrg is no longer available. . Discover the innovative optical signaling approach that enables confidential data transfer across open fiber optic networks.. Secure Data Transmission,Fiber Network Security,Confidential Message Transmission,Optical Encryption Techniques. . LinuxSecurity.com Team

Calendar%202 Oct 13, 2006 User Avatar LinuxSecurity.com Team Privacy
81

Digital Signatures: Risks and Legal Binding in Linux Systems

Digital signatures were designed to allow secure, confidential communication between two parties. As Wikipedia describes it: "A user may digitally sign messages using his private key, and another user can check that signature (using the public key contained in that user's certificate issued by a certificate authority). This enables two (or more) communicating parties to establish confidentiality, message integrity and user authentication without having to exchange any secret information in advance." . Are digital signatures legally binding? Usually. Check your local statutes. Are they foolproof? Not usually. For years, Prof. Ferenc Leitold of the University of Veszprem has been explaining the dangers of digital signatures to the world at large. This week, he's doing it again at the 15th EICAR Annual Conference in Hamburg, Germany. The link for this article located at Email Battles is no longer available. . Are digital signatures legally binding? Usually. Check your local statutes. Are they foolproof? Not . digital, signatures, designed, allow, secure, confidential, communication, between, parties. . LinuxSecurity.com Team

Calendar%202 May 08, 2006 User Avatar LinuxSecurity.com Team Privacy
81

Maintaining Client Confidentiality in Networked Systems Effectively

Along with the benefits of networked systems – easy information sharing and the ability to work wherever and whenever – comes responsibility. Professionals in all industries have the responsibility to protect their customers’ (and their own) confidentiality. When professionals access their office networks and exchange information with other organisations, confidentiality is paramount, though not always easy to achieve. . The link for this article located at Net-Security.org - Logerror is no longer available. . Delve into the vital role of confidentiality in networked systems, emphasizing data security and professional accountability.. Network Confidentiality, Data Protection, Information Security. . LinuxSecurity.com Team

Calendar%202 Mar 03, 2006 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200