Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 8 articles for you...
67

Understanding Un-Authentication Issues In Online Banking Networks

In computer security, a lot of effort is spent on the authentication problem. Whether it. This is important stuff, as anyone with an online bank account or remote corporate network knows. But a lot less thought and work have gone into the other end of the problem: how do you tell the system on the other end of the line that you The link for this article located at ThreatPost is no longer available. . This is important stuff, as anyone with an online bank account or remote corporate network knows. Bu. computer, security, effort, spent, authentication, problem, whether. . LinuxSecurity.com Team

Calendar%202 Sep 28, 2009 User Avatar LinuxSecurity.com Team Cryptography
74

Assessing Skype Security: Implications for Corporate Networks and Users

There's been a lot information -- and misinformation -- available about whether Skype is dangerous to corporate networks and individual users. How dangerous is it? In this article, I'll separate the truth from the myths when it comes to Skype vulnerabilities. . Skype is a peer-to-peer (P2P) application, meaning that users connect to one another directly and not through a central server for communication. Skype initially uses Internet-based servers to authenticate users when they log in and to track their status, but when a "chat" or instant message, "voice call" or "file transfer" is initiated, the parties involved in the communication do so in a P2P direct connection. If one or both of the users are behind a typical corporate Network Address Translation (NAT) firewall, the communication can be relayed through a Supernode because a direct P2P can't be established behind a NAT. In the case of a file transfer, you will see a message indicating your transfer is being relayed. The link for this article located at ComputerWorld is no longer available. . Using Skype as a P2P application presents risks that can jeopardize user security and privacy, necessitating awareness and proactive safety measures from users. Skype Security Risks, P2P Communication Threats, Corporate Network Safety. . Brittany Day

Calendar%202 Mar 06, 2007 User Avatar Brittany Day Network Security
72

Revamping Secure Connectivity in Corporate Networks Using SSH Tunnels

The goal of this article is to present a few effective methods to revamp the way you work in a restricted corporation-like network. In order to achieve it we. For simplicity reasons, throughout this text we The link for this article located at Polish Linux is no longer available. . Investigate techniques for optimizing tasks within limited networks through the establishment of SSH tunnels while maintaining robust security protocols. Uncover strategies.. SSH Tunnels, Firewall Proxies, Secure Corporate Connectivity. . Brittany Day

Calendar%202 Aug 24, 2006 User Avatar Brittany Day Firewalls
78

Panda Software Network Security Appliances: 8000 Series Launch

Panda Software has launched a series of security network appliance designed to fight viruses, control spam, and filter out non-business or unapproved web surfing. The Panda GateDefender 8000 series includes four devices, designed for companies ranging from small businesses to large enterprises. . . .. Panda Software has launched a series of security network appliance designed to fight viruses, control spam, and filter out non-business or unapproved web surfing. The Panda GateDefender 8000 series includes four devices, designed for companies ranging from small businesses to large enterprises. The devices can scan traffic at up to 30 Mbps and up to 600,000 messages per hour, with a minimum drain on network resources, according to Panda officials. It is designed to protect the corporate network perimeter against viruses, worms, and Trojans, detecting and eliminating malicious code in the six most widely-used protocols: HTTP, FTP, SMTP, POP3, IMAP4 and NNTP. The link for this article located at Preston Gralla is no longer available. . Panda Software has unveiled new cybersecurity solutions to combat malware and control junk emails for organizations. Discover additional details!. Panda Software, Network Security Appliance, Security Device. . LinuxSecurity.com Team

Calendar%202 Oct 01, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
83

Phishing Attacks: Steganography Threatens Corporate Security

In the escalating clash between online scammers and security vendors, the attackers have once again developed new tactics that give them the upper hand in bypassing filters and infiltrating corporate networks, experts say. . . .. The new techniques, which experts began seeing sporadically earlier this year and in large waves in recent weeks, involve the use of a process called steganography, or embedding or hiding text in an image. In the most recent cases, spam and phishing messages have incorporated complex images containing text. In some cases, the image files include hidden code designed to exploit known vulnerabilities in e-mail clients and Web browsers. The most prominent example of the steganography wave is a recent variation on the ubiquitous Citibank phishing scam that attempts to lure recipients into disclosing online banking user names and passwords. Previous versions used text and images, such as authentic-looking Citibank logos and privacy seals. But versions that began surfacing recently are made up of one large image file containing all the text. "We continually modify our systems to enhance safeguards for our customers," said a spokesperson for Citibank, a unit of Citigroup Inc., in New York. "It is also important that consumers be aware of these issues and act appropriately." The link for this article located at Dennis Fisher is no longer available. . The new techniques, which experts began seeing sporadically earlier this year and in large waves in . escalating, clash, between, online, scammers, security, vendors, attackers, again. . LinuxSecurity.com Team

Calendar%202 Sep 13, 2004 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Businesses Struggle With Wireless Security Risks in Europe

Businesses in Europe's leading financial centres are failing to secure their wireless access points despite the risk of "drive-by" hacking. More than 33% of businesses surveyed in London, Milan, Paris and Frankfurt are still making fundamental security mistakes, research by RSA Security revealed. . . .. Businesses in Europe's leading financial centres are failing to secure their wireless access points despite the risk of "drive-by" hacking. More than 33% of businesses surveyed in London, Milan, Paris and Frankfurt are still making fundamental security mistakes, research by RSA Security revealed. The failure of companies to use basic wireless security standards, such as WEP (Wired Equivalent Privacy), is leaving otherwise well-protected corporate networks with holes that could be exploited by hackers. "Once hackers are connected, they can do what they like," said Tim Pickard, director at RSA. "This instantly negates the effort and investment organisations have made in other areas to secure the corporate infrastructure." The survey found that the number of wireless networks has increased by 770% to more than 1,000 in London during the past three years. The link for this article located at ComputerWeekly is no longer available. . Across Europe, enterprises face threats from opportunistic intrusions owing to inadequate protection of Wi-Fi hotspots. More than a third do not meet fundamental security benchmarks.. wireless security, network protection, corporate security. . Anthony Pell

Calendar%202 Jun 22, 2004 User Avatar Anthony Pell Network Security
74

Understanding Wireless Security Risks in Corporate Environments

Additionally, wireless networks are complicating the security equation, as devices that once were predominantly corporate in nature, are now also accessing wireless data networks via hotspots and public areas. These wireless users may be providing malicious users with a backdoor . . . . Additionally, wireless networks are complicating the security equation, as devices that once were predominantly corporate in nature, are now also accessing wireless data networks via hotspots and public areas. These wireless users may be providing malicious users with a backdoor into corporate networks. Additionally, companies that have deployed wireless networks require additional security layers, as existing security measures built into the wireless standards are weak. Wireless LAN security gateways and wireless Intrusion Detection Systems have been developed to provide encryption for corporate wireless data and to identify potential hackers to the wireless network. The link for this article located at GeekZone is no longer available. . The advent of wireless connectivity alters the security paradigm, presenting businesses with a range of novel risks and weaknesses.. Wireless Security, Corporate Network Threats, Intrusion Detection Systems, Data Encryption. . Anthony Pell

Calendar%202 Dec 26, 2003 User Avatar Anthony Pell Network Security
74

Increased Attacks on Internal PCs in Corporate Networks

The security firm says cyber-attackers are refocusing their efforts on PCs inside the perimeter of corporate networks Corporations should be as concerned about personal computers inside the network perimeter as those riding its boundary, warns Symantec's security team. Vincent Weafer, senior . . . . The security firm says cyber-attackers are refocusing their efforts on PCs inside the perimeter of corporate networks Corporations should be as concerned about personal computers inside the network perimeter as those riding its boundary, warns Symantec's security team. Vincent Weafer, senior director of Symantec Security Response, said cyber-attackers are shifting their efforts from outside the intranet boundary to inside. The attackers are taking an increasing interest in intranet-facing private network services in common desktop personal computers. According to Weafer, the farms of desktops inside the network perimeter provide a rich picking ground for attackers. They are often less secure than systems that face the Internet directly, making them attractive recruits for orchestrated actions such as denial-of-service attacks, said Weafer. The link for this article located at ZDNet UK is no longer available. . Cybercriminals are steadily focusing their efforts on office computers inside business networks, threatening the integrity of internal system security.. Corporate Network Threats, Internal Security Risks, Cyber Attack Trends. . Anthony Pell

Calendar%202 Oct 15, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200