Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
77

Heartbleed Analysis: 74% Global 2000 Remain Exposed To Flaw

According to research from Venafi, a vast majority of the world's top businesses are still vulnerable to Heartbleed, which was disclosed a year ago this month. The OpenSSL flaw impacted organizations both large and small, but the latest figures show that 74-percent of the Global 2000 remain vulnerable.. Heartbleed (CVE-2014-0160) was fully disclosed on April 7, 2014. The problematic code was originally introduced to the OpenSSL platform in 2012, but remained undetected until researchers performed an audit. The link for this article located at CSO Online is no longer available. . The Heartbleed vulnerability is still a pressing issue, as 74% of leading companies continue to be at risk. Explore the insights from the study.. Heartbleed Vulnerability, OpenSSL Flaw Analysis, Corporate Risk Assessment. . LinuxSecurity.com Team

Calendar%202 Apr 08, 2015 User Avatar LinuxSecurity.com Team Server Security
74

Dan Jackson Discusses Network Security Issues and Prevention Strategies

"We've had a focus on education because we felt if we could demonstrate to the marketplace that we could sit in the wildest of environments, it would demonstrate true security functionality," said DeepNines President Dan Jackson. . . .. "We've had a focus on education because we felt if we could demonstrate to the marketplace that we could sit in the wildest of environments, it would demonstrate true security functionality," said DeepNines President Dan Jackson. "At universities you would not believe the spike in traffic and the spike in malicious traffic when school comes back in service." With their bottom lines and corporate reputations at risk, many security professionals, tired of being able only to react to viruses and worms, are looking for ways to prevent degradation and infection. Worms and viruses cost organizations billions of dollars and hundreds of man-hours. Spam has grown to represent between 60 percent and 70 percent of all e-mail, according to published reports. And even the companies charged with helping businesses secure their networks now are coming under attack. In April, for example, Cisco (Nasdaq: CSCO) warned customers about a hole in its Wireless LAN Solution Engine. The link for this article located at Alison Diana is no longer available. . Uncover key perspectives from Alex Turner on enhancing cybersecurity measures and thwarting illicit attacks across varied settings.. Network Security, Threat Prevention, Security Education. . Anthony Pell

Calendar%202 Oct 18, 2004 User Avatar Anthony Pell Network Security
82

Middle East Focus on Information Security Governance in Corporations

DUBAI - A large number of corporations in Middle East are beginning to identify 'information security' as a core area of corporate governance, said sources from information security sector. The need of the hour for Middle East is to have effective Information Secured networks to protect from potential network threats. . . .. DUBAI - A large number of corporations in Middle East are beginning to identify 'information security' as a core area of corporate governance, said sources from information security sector. The need of the hour for Middle East is to have effective Information Secured networks to protect from potential network threats. Recently, according to Symantec's Internet Security Threat Report, Middle East leads the world as the source of Internet threats per capita. The link for this article located at Khaleej Times is no longer available. . DUBAI - A large number of corporations in Middle East are beginning to identify 'information securit. dubai, large, number, corporations, middle, beginning, identify, 'information, securit. . Anthony Pell

Calendar%202 Sep 27, 2004 User Avatar Anthony Pell Government
74

Risks of Using Self-Installed Instant Messaging in Corporate Networks

Instant messaging (IM) is taking off in companies but self-installed consumer versions of software that allows this type of communication are posing a "rampant security risk" on networks. Already some companies see IM as a time wasting technology - as . . . . Instant messaging (IM) is taking off in companies but self-installed consumer versions of software that allows this type of communication are posing a "rampant security risk" on networks. Already some companies see IM as a time wasting technology - as was the case when email, web access and even the telephone were first put on workers' desks - but the latest warning, levelled by Blue Coat Systems, is based on three key factors. The security appliance vendor highlights that IM is used to send files which firewalls don't pick up because they do not pass through corporate email systems; they are not checked for viruses; and they are not logged. The link for this article located at silicon.com is no longer available. . Real-time communication platforms can compromise organizational safety through unauthorized personal applications, endangering system stability.. Instant Messaging, Corporate Security, Software Risks. . Anthony Pell

Calendar%202 Feb 06, 2003 User Avatar Anthony Pell Network Security
82

Corporate Data Security Measures Under Legislative Review

Corporate America's reluctance to be more forthcoming about internal data security measures has come under scrutiny on Capitol Hill. "I'm not sure the general population realizes just how interconnected all of the ordering processing systems are. My concerns are right in . . . . Corporate America's reluctance to be more forthcoming about internal data security measures has come under scrutiny on Capitol Hill. "I'm not sure the general population realizes just how interconnected all of the ordering processing systems are. My concerns are right in the core of our business," said Cangemi. However, there's a big knowledge gap in corporate America when it comes to risk, which stems from the fact that corporate boards are primarily staffed by CEOs and not CIOs, he said. "We're just getting to the point where there are [chief financial officers] on the board," said Cangemi. "There are no CIOs yet." The link for this article located at Computer World is no longer available. . The hesitation of businesses in the United States to reveal their internal cybersecurity protocols prompts worries regarding interlinked networks.. Data Governance, Corporate Risk, Security Compliance, Information Security, Data Integrity. . Anthony Pell

Calendar%202 Apr 03, 2001 User Avatar Anthony Pell Government
83

Analysis of Recent Linux Defacements in Major Corporations

I had meant to do an update to my previous high profile summary of sorts. After drinking a Corona I began working on this post and it hit home yet again. Half way through writing this, another server on Hewlett Packard's network was defaced. I don't know what I find more ironic, that four HP servers were defaced this month, or that in each case they were running Windows NT or Linux instead of HP-UX (their own unix operating system). Toward the end of this list are two sites that also strike a bit of irony.. . .. I had meant to do an update to my previous high profile summary of sorts. After drinking a Corona I began working on this post and it hit home yet again. Half way through writing this, another server on Hewlett Packard's network was defaced. I don't know what I find more ironic, that four HP servers were defaced this month, or that in each case they were running Windows NT or Linux instead of HP-UX (their own unix operating system). Toward the end of this list are two sites that also strike a bit of irony. Toshiba Australia ICQ Compaq Computer Corp, Altavista Compaq Computer Corp Hewlett-Packard (Ironically, three of these machines running Windows NT instead of HP-UX, and one running Linux...) Olympic Committee Sony Taiwan Iomega Corporation The New York Times Intel Corporation Sharp Philippines Go.Com Gateway 2000 Inc PSINet NEC Chile Packard Bell Chile Memorex Sony Italy Lycos, Inc McDonalds UK Motorola Mexico It is always somewhat ironic when security companies or security related sites get defaced. Attrition is just waiting until we end up mirroring our own defacement. Computer Security Auditing Network SecureNet BR . Exposing the paradox in the latest noteworthy breaches affecting prominent companies and Linux infrastructures.. High Profile Defacements, Linux Breaches, IT Security Incidents. . LinuxSecurity.com Team

Calendar%202 Feb 23, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200