Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 79 articles for you...
83

Vermilion Strike: New Linux Cobalt Strike Port Boosts Attack Capabilities

Hackers have developed a Linux port of the Cobalt Strike penetration testing toolkit dubbed Vermilion Strike to evade malware detection. . Cyber criminals have developed a Linux port of the Cobalt Strike penetration testing tool that has been dubbed Vermilion Strike, security researchers have discovered. The tool has been developed from scratch to avoid detection from malware scanners. According to a report published by cloud security firm Intezer Labs, researchers last month discovered a fully undetected ELF implementation of Cobalt Strike’s beacon . The malware used Cobalt Strike’s Command and Control (C2) protocol when communicating to its C2 server and has remote access capabilities such as uploading files, running shell commands, and writing to files. . Hackers have developed a Linux variant of Cobalt Strike, upgrading their malware avoidance strategies with additional features.. Linux Port Cobalt Strike, Vermilion Strike, Malware Evasion, Penetration Testing Toolkit, Cyber Crime. . LinuxSecurity.com Team

Calendar%202 Sep 14, 2021 User Avatar LinuxSecurity.com Team Hacks/Cracks
209

Surge in Go Malware Attacking Linux Systems and IoT Devices Observed

There's been a 2,000% increase of new malware written in Go over the past few years. Many of these malware families are botnets targeting Linux and IoT devices to either install crypto miners or enroll the infected machine into DDoS botnets. . The number of malware strains coded in the Go programming language has seen a sharp increase of around 2,000% over the last few years, since 2017, cybersecurity firm Intezer said in a report published this week. The company's findings highlight and confirm a general trend in the malware ecosystem, where malware authors have slowly moved away from C and C++ to golang , a programming language developed and launched by Google in 2007. . The prevalence of malware variants developed in Go has surged, specifically aiming at Linux systems and IoT gadgets.. Go Malware, Linux Threats, IoT Security, Cyber Crime. . Brittany Day

Calendar%202 Mar 01, 2021 User Avatar Brittany Day Security Trends
83

Andrei Tyurin Extradition: JP Morgan Data Breach Charges Unveiled

Georgian officials have extradited Russian citizen Andrei Tyurin to the United States, where he will face charges related to a wide-ranging hacking campaign that targeted the US financial sector and included the 2014 breach of JP Morgan Chase. . The Manhattan US Attorney's office announced Friday that Tyurin was arrested by authorities in the country of Georgia at the request of the United States for his participation in hacking US financial organizations, brokerage firms, financial news publishers, and other companies. From 2012 to mid-2015, the campaign stole personal information of more than 100 million customers of target organizations. The breach at JP Morgan Chase was the largest theft of customer data from any single US financial institution in history with more than 80 million people affected. The link for this article located at DarkReading is no longer available. . The Manhattan US Attorney's office announced Friday that Tyurin was arrested by authorities in the c. georgian, officials, extradited, russian, citizen, andrei, tyurin, united, states, where. . LinuxSecurity.com Team

Calendar%202 Sep 11, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

North Korea Hacks Expose Weaknesses in Email Security and Risks

The North Korean group accused of some of the biggest cyber crimes ever conducted may have harnessed some highly sophisticated technologies, but their ability to break into computer networks worldwide often relied on nothing more than a bogus email. . The US Department of Justice has formally charged a North Korean programmer for his part in some of the largest cyber-attacks in recent years, conducted by a group backed by the North Korean government. The link for this article located at ZDNet is no longer available. . The cyber espionage strategies employed by North Korea reveal vulnerabilities in email systems, underscoring the global risks and techniques utilized in the realm of cybersecurity.. North Korea Hacking, Cyber Crime Tactics, Email Threats, Phishing Techniques, Network Risks. . LinuxSecurity.com Team

Calendar%202 Sep 08, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Ruslan Bondars Convicted: 35 Years For Aiding Hackers Against Anti-Virus

Scan4You, the largest known counter anti-virus website, went offline in May 2017 when two men were arrested in Latvia and extradited by the FBI to the United States.. 37-year-old Ruslan Bondars (also known by the online handle “Borland”), one of the men arrested in Latvia in May 2017, has now been convicted in a US court of one count of conspiracy to violate the Computer Fraud and Abuse Act, one count of conspiracy to commit wire fraud, and one count of computer intrusion with intent to cause damage. The link for this article located at WeLiveSecurity is no longer available. . Vasily Petrov sentenced for collaborating with cybercriminals, confronting lengthy incarceration due to breaches of cybersecurity regulations.. Cyber Crime, Anti-Virus Evasion, Law Enforcement, Computer Fraud Act. . LinuxSecurity.com Team

Calendar%202 May 22, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Vladimir Drinkman: Major Role In Historic U.S. Data Breach Incident

A Russian hacker extradicted to the US earlier this year admitted his role in the largest hack in US history. The attack compromised more than 160 million credit card numbers, resulting in hundreds of millions of US dollars in losses. . Vladimir Drinkman, 34, said Tuesday in federal court in Camden, New Jersey, that he plotted with four other men to steal credit card numbers from payments processors Global Payments and Heartland Payment Systems, grocery chain Hannaford Brothers and at least 14 other organisations from 2005 to 2012. . Vladimir Drinkman, 34, said Tuesday in federal court in Camden, New Jersey, that he plotted with fou. russian, hacker, extradicted, earlier, admitted, largest. . LinuxSecurity.com Team

Calendar%202 Sep 17, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

First U.S. Case of Hacking Scheme in Insider Trading Fraud

Recently, an international hacking ring was discovered to have stolen more than $100 million. The sophisticated plan demonstrated ingenuity on the part of the attackers. They exploited a core vulnerability of the financial system in one of the digital age. This is the first U.S. prosecuted criminal case in which the hackers teamed up with stockbrokers to commit to access inside information in their securities fraud plot.[ii] The link for this article located at Darkmatters is no longer available. . Discover the initial instance in the United States where cybercriminals and financial traders conspired to execute a securities scam amounting to millions of dollars.. Insider Fraud, Hacking Collaboration, Cybersecurity Issues. . LinuxSecurity.com Team

Calendar%202 Aug 19, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Trustwave Research: Rig Exploit Kit Affects Close to 1 Million Victims

LAS VEGAS . Researchers at Trustwave said in advance of this week The link for this article located at ThreatPost is no longer available. . Trustwave's cybersecurity experts emphasize the rising risk of the Rig Exploit Kit, potentially impacting 1 million people and raising major concerns about its effects. Rig Exploit Kit, Cyber Crime, Online Threats, Malware. . LinuxSecurity.com Team

Calendar%202 Aug 04, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200