Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 5 articles for you...
79

Wi-Fi Printing Risks Exposed by Drones and Mobile Devices Security Threats

You might think that working on a secured floor in a 30-story office tower puts you out of reach of Wi-Fi hackers out to steal your confidential documents. . But researchers in Singapore have demonstrated how attackers using a drone plus a mobile phone could easily intercept documents sent to a seemingly inaccessible Wi-Fi printer. The method they devised is actually intended to help organizations determine cheaply and easily if they have vulnerable open Wi-Fi devices that can be accessed from the sky. But the same technique could also be used by corporate spies intent on economic espionage. . But researchers in Singapore have demonstrated how attackers using a drone plus a mobile phone could. might, think, working, secured, floor, 30-story, office, tower, reach. . LinuxSecurity.com Team

Calendar%202 Mar 14, 2017 User Avatar LinuxSecurity.com Team Security Projects
76

Hacking Team's 400GB Data Breach: CEO Response And Implications

The chief executive of Hacking Team has finally spoken out about the cyberattack which allowed sensitive corporate data, exploits and customer history to enter the public domain.. Founded in 2003, Hacking Team provides surveillance tools and spyware to government agencies, intelligence outfits and law enforcement worldwide. The company's operations have always been a closely-guarded secret; however, a recent cyberattack has changed the company -- potentially in a fatal manner. This month, the surveillance firm suffered a data breach leading to 400GB of stolen data being released online. WikiLeaks has also published a treasure trove of emails contained within the files. The link for this article located at ZDNet Security is no longer available. . The CEO of Hacking Team responds to the significant data breach that has unveiled critical information, discussing the repercussions for their business activities.. Hacking Team, data breach, cybersecurity incident, surveillance technology. . Alex

Calendar%202 Jul 13, 2015 User Avatar Alex Organizations/Events
83

Hacking Team Data Breach: 400GB Exposed Corporate and Customer Information

The cyberattacker who stole 400GB in corporate data belonging to spyware firm Hacking Team has come forward. Hacking Team has not had a good week. The Milan, Italy-based company, known for selling surveillance and spyware tools to government agencies and private companies, experienced a data breach over the weekend which led to the alleged theft of 400GB of corporate data.. The file, which has spread like wildfire through torrent sharing, magnets and mirrors, contains information including customer lists, financial statements and allegedly the source code of tools supplied by the company. The link for this article located at ZDNet Security is no longer available. . Significant leak of corporate information by CyberOps, revealing customer databases and accounting details. Discover more here.. Data Breach, Spyware Tools, Cybersecurity Incident, Corporate Intelligence. . LinuxSecurity.com Team

Calendar%202 Jul 07, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Exxon, Shell, BP Cyber Incident: Data Theft From Chinese Servers

Computer hackers working through Internet servers in China broke into and stole proprietary information from the networks of six U.S. and European energy companies, including Exxon Mobil Corp., Royal Dutch Shell Plc and BP Plc, according to one of the companies and investigators who declined to be identified.. McAfee Inc., a cyber-security firm, reported Feb. 10 that such attacks had resulted in the loss of The link for this article located at Bloomberg is no longer available. . Attacks originating from Chinese networks led to considerable information breaches for leading oil firms, such as Chevron and Shell.. Data Theft, Cybersecurity, Energy Companies, Corporate Security. . LinuxSecurity.com Team

Calendar%202 Feb 24, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Encrypt Your Email To Shield Against Corporate Espionage

Corporate espionage is big business these days. So it makes sense to deploy some kind of encryption system to ensure that prying eyes can. The link for this article located at eSecurityPlanet is no longer available. . In the digital era, safeguarding email content is essential. Encryption protects private messages from espionage, ensuring confidentiality and secure access.. Email Security, Encryption Techniques, Data Protection. . Bill Locke

Calendar%202 Aug 23, 2007 User Avatar Bill Locke Network Security
74

Bluetooth Security Advisory: Remote Data Access Risks Identified

Serious flaws discovered in Bluetooth technology used in mobile phones can let an attacker remotely download contact information from victims' address books, read their calendar appointments or peruse text messages on their phones to conduct corporate espionage. . . .. Serious flaws discovered in Bluetooth technology used in mobile phones can let an attacker remotely download contact information from victims' address books, read their calendar appointments or peruse text messages on their phones to conduct corporate espionage. An attacker could even plant phony text messages in a phone's memory, or turn the phone sitting in a victim's pocket or on a restaurant table top into a listening device to pick up private conversations in the phone's vicinity. Most types of attacks could be conducted without leaving a trace. Security professionals Adam Laurie and Martin Herfurt demonstrated the attacks last week at the Black Hat and DefCon security and hacker conferences in Las Vegas. Phone companies say the risk of this kind of attack is small, since the amount of time a victim would be vulnerable is minimal, and the attacker would have to be in proximity to the victim. But experiments, one using a common laptop and another using a prototype Bluetooth "rifle" that captured data from a mobile phone a mile away, have demonstrated that such attacks aren't so far-fetched. Laurie, chief security officer of London-based security and networking firm ALD, discovered the vulnerability last November. Using a program called Bluesnarf that he designed but hasn't released, Laurie modified the Bluetooth settings on a standard Bluetooth-enabled laptop to conduct the data-collection attacks. The link for this article located at wired.com is no longer available. . Critical vulnerabilities in Wi-Fi can allow hackers to gain unauthorized access to private information from smartphones.. Bluetooth Security Flaws, Mobile Device Vulnerabilities, Remote Data Access. . Anthony Pell

Calendar%202 Aug 09, 2004 User Avatar Anthony Pell Network Security
81

Unseen Dangers of Document Sharing: Corporate Espionage Risks

Many documents published online may unintentionally reveal sensitive corporate or personal information, according to a US computer researcher. Simon Byers, at AT&T's research laboratory in the US, was able to unearth hidden information from many thousands of Microsoft Word documents . . . . Many documents published online may unintentionally reveal sensitive corporate or personal information, according to a US computer researcher. Simon Byers, at AT&T's research laboratory in the US, was able to unearth hidden information from many thousands of Microsoft Word documents posted online using a few freely available software tools and some basic programming techniques. Sophisticated editing programs will often store information in a document file that the end user will not see. Storing recently deleted text can, for example, make editing a more efficient process. But Byers says it could also expose unaware users to significant risks. In his report, Byers suggests that a crook could analyse electronic documents to gather information that could help them carry out corporate espionage or steal someone else's identity to commit fraud. "It is feasible that an individual may include their social security number on copies of a resume sent to prospective employers, but delete it from the version put online to guard against identify theft," Byers writes. The link for this article located at NewScientist is no longer available. . Many documents published online may unintentionally reveal sensitive corporate or personal informati. documents, published, online, unintentionally, reveal, sensitive, corporate, personal, informati. . LinuxSecurity.com Team

Calendar%202 Aug 19, 2003 User Avatar LinuxSecurity.com Team Privacy
81

Data Theft Insights From Australia's Major Corporations

THE corporate spy trade is booming. One-quarter of Australia's largest companies admit they are involved in "competitive intelligence gathering", according to a PricewaterhouseCoopers survey. The information-gathering techniques are almost always legal and carried out by trained professionals - often former government intelligence operatives highly trained in obtaining military and economic secrets. . . .. THE corporate spy trade is booming. One-quarter of Australia's largest companies admit they are involved in "competitive intelligence gathering", according to a PricewaterhouseCoopers survey. The information-gathering techniques are almost always legal and carried out by trained professionals - often former government intelligence operatives highly trained in obtaining military and economic secrets. But the operatives were spying on competing companies rather than foreign governments, and many companies were easy targets, PwC dispute analysis and investigations director Richard Batten said. "Corporations have people trained to obtain raw data from a wide range of sources and apply traditional intelligence analysis techniques to produce usable information," he said. "It's worrying to find 62 per cent of companies have no protection in place to stop the loss or theft of intellectual property -- even though 30 per cent admit already experiencing at least one incident." The link for this article located at News.com is no longer available. . THE corporate spy trade is booming. One-quarter of Australia's largest companies admit they are invo. corporate, trade, booming, one-quarter, australia's, largest, companies, admit. . LinuxSecurity.com Team

Calendar%202 Apr 10, 2002 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200