Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 14 articles for you...
210

Google Chrome Update: Addressing Critical Chromium Flaws on Linux

Google Chrome, one of the world's most widely used web browsers, has recently been scrutinized due to the discovery of multiple Chromium vulnerabilities that threaten user safety and privacy. Chromium is the open-source web browser project that is the basis of Chrome and many other widely used browsers. . These issues highlight the struggle between providing user-friendly software and protecting it with robust security measures. I'll explain these recent vulnerabilities in more depth, help you determine if you are at risk, and explain how to update Chrome to protect your privacy and security online. Unpacking These Recent Chromium Vulnerabilities Google released a critical security update to Google Chrome on August 6, 2024, to address a series of vulnerabilities that potentially allowed attackers to install malicious code on users' systems. Linux version 127.0.6533.99 aims to address these flaws. CVE-2024-7532 was identified as the most severe vulnerability involving out-of-bounds memory access in ANGLE (Almost Native Graphics Layer Engine). Considered critical, this flaw could enable attackers to execute arbitrary code, and cause system crashes. Apart from CVE-2024-7532, the update includes resolution for several high-severity issues: CVE-2024-7533 is a use-after-free vulnerability in the Sharing feature. CVE-2024-7550 is a type confusion flaw in the V8 JavaScript engine. CVE-2024-7534 is a heap buffer overflow in the Layout component CVE-2024-7535 represents inappropriate implementation in V8. CVE-2024-7536 involves WebAudio use-after-free vulnerabilities that enable malicious actors to gain unauthorized access, access sensitive data, or inject and execute arbitrary malicious code. Impact and Risk Evaluation Due to Chrome's widespread usage across platforms, these vulnerabilities have far-reaching ramifications. One immediate risk for individual users lies in their privacy and security. If their browser session becomes hijacked, personal andfinancial data could be stolen, and unwanted actions could be taken on their behalf. Organizations that rely heavily on web applications for operations are especially at risk since security flaws in these apps could allow attackers to penetrate organizational networks and steal sensitive data. This risk is especially acute in finance, healthcare, and government services. Any user, small business owner, or large enterprise using unpatched versions of Google Chrome could be susceptible to these vulnerabilities. This includes individual users and businesses without rapid update policies in place. Why Are Timely Updates Essential & How Can I Update Chrome on Linux? These vulnerabilities have been addressed with Google's recent Chrome update . Updating immediately is an essential preventative measure against potential attacks. Google did not reveal specifics regarding each vulnerability to protect against further exploitation. Instead, it is relying on users updating their browsers to protect themselves. Updating Google Chrome on Linux can be an effortless but effective way of protecting against vulnerabilities that exist within it. Here's how to update: Launch Google Chrome: Launching the Chrome browser is the first step in getting Google Chrome up and running. Access the Menu: To open, click on the three-dot menu in your browser's top-right corner. Navigating to Help: Navigate to Google Chrome > About, and your browser will take you directly to a page that displays its current version and checks for updates. Automatic Update: If an update is available, Chrome will begin the update process automatically. Wait for it to download and install before taking action. Restart Chrome: Once the update is installed, the browser must be relaunched to complete it successfully. An icon will remind you when it is ready and to relaunch immediately afterward. Verifying Your Updates: To ensure the update has taken effect, visit Help > About Google Chrome to view its updatedversion number. Our Final Thoughts on These Severe Chromium Bugs Chromium vulnerabilities are a stark reminder of the perils inherent to digital security and highlight the necessity of constant vigilance. Users can significantly mitigate risks by understanding these vulnerabilities and possible repercussions and updating their systems with security patches . Linux users should follow this straightforward update process to safeguard their digital privacy and security. Staying informed and proactive is critical in protecting our digital lives! . Enhance your system's security with Chromium by ensuring that Google Chrome is freshly updated on Linux. Safeguard your privacy and maintain user safety efficiently.. Google Chrome Security, Chromium Update, User Privacy Measures, Cybersecurity Risks. . Brittany Day

Calendar%202 Sep 04, 2024 User Avatar Brittany Day Security Vulnerabilities
214

Identifying Risks From Unsupported IoT Devices in Your Network

Imagine reading a headline in tomorrow’s news stating that your neighbor’s identity was stolen and their life savings cleaned out by criminals who entered through their ‘smart’ washing machine. Sound ridiculous? Well, have you checked your own home Wi-Fi network lately? . You might have several connected household gadgets and other internet of things (IoT) devices tethered wirelessly through a misconfigured router with no firewall settings. Is the firmware current? Are security patches up to date? Still not convinced this is a serious problem? Then consider this glaring example of how dangerous an outdated device can be. . With increasing smart devices at home, unsupported IoT risks rise. They lack updates, making them vulnerable to attacks and undermining network reliability.. IoT Devices, Cybersecurity Risk, Network Protection, Firmware Updates, Security Challenges. . Brittany Day

Calendar%202 Aug 30, 2021 User Avatar Brittany Day IoT Security
83

Understanding User Behavior: Seven Ways Users Compromise Security

Common knowledge has it that users are the weakest link in the IT risk management world. Many of their methods involve just a little bit of psychological sleight of hand because phishing and social engineering tend to play a part in most attacks. Here are some of the worst ways users make themselves open to the onslaught.. Many of their methods involve just a little bit of psychological sleight of hand because phishing an. common, knowledge, users, weakest, management, world. . LinuxSecurity.com Team

Calendar%202 Apr 21, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Mafiaboy Discusses Cloud Risks at Hitachi Data Systems Forum

Michael Calce, the reformer hacker from Montreal who will forever be known as Mafiaboy, told a group of IT professionals yesterday that he has serious concerns about the inherent vulnerabilities in the latest evolution of information technology: cloud computing.. Calce was a guest-speaker at storage vendor Hitachi Data Systems' (HDS) (NYSE: HIT) annual Information Forum event in Toronto. He came to fame in 2000 when, as a teenager, he launched a series of denial of service attacks that crippled the Web sites of companies such as CNN, Amazon, Dell and Yahoo, leading to a manhunt by the RCMP and the FBI and his eventual arrest. Having completed his sentence and matured beyond the The link for this article located at IT Business is no longer available. . Calce was a guest-speaker at storage vendor Hitachi Data Systems' (HDS) (NYSE: HIT) annual Informati. michael, calce, reformer, hacker, montreal, forever, known, mafiaboy, group. . LinuxSecurity.com Team

Calendar%202 Nov 24, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

McAfee Report: Alarming Surge In Spam And Malware Activity

Spam and botnets have hit their highest levels ever, according to McAfee's second-quarter Threats Report, released Wednesday. McAfee's Avert Labs says spam recorded in the second quarter shot up 80 percent compared with the first quarter of the year.. This follows a brief reprieve from spam following last year's shutdown of the McColo ISP. June alone saw the largest amount of spam recorded by McAfee, surpassing the previous monthly high in October by more than 20 percent. McAfee now estimates that spam accounts for 92 percent of all e-mail. The link for this article located at CNET is no longer available. . This follows a brief reprieve from spam following last year's shutdown of the McColo ISP. June alone. botnets, their, highest, levels, according, mcafee's, second-quarter, threats. . Anthony Pell

Calendar%202 Jul 29, 2009 User Avatar Anthony Pell Network Security
77

Microsoft IIS Server Exposes Double Malware Risk According To Research

Web sites running Microsoft Corp.'s Web server software are twice as likely to be hosting malicious code as other Web sites, according to research from Google Inc. Last month, Google's Anti-Malware team looked at 70,000 domains that were either distributing malware or hosting attack code. "Compared to our sample of servers across the Internet, Microsoft IIS features twice as often as a malware-distributing server," wrote Google's Nagendra Modadugu, in a Tuesday blog posting. . The link for this article located at ComputerWorld is no longer available. . The link for this article located at ComputerWorld is no longer available.. sites, running, microsoft, server, software, twice, likely, hosting, malicious. . LinuxSecurity.com Team

Calendar%202 Jun 06, 2007 User Avatar LinuxSecurity.com Team Server Security
77

Exploring Cookie Security Threats and Misconfigurations

Within one week's time, we stumbled across two different sites using cookies the wrong way. While the attack vectors were a bit different, both sites trusted the cookie data to secure their users. Let's break this cookie down so we can understand its intent. First, you can easily tell who the cookie belongs to . Unpack prevalent cookie setup issues and discover methods to manage cookie information securely for enhanced safeguarding.. Web Cookies, Secure Data Handling, Cookie Best Practices, Cybersecurity Risks. . LinuxSecurity.com Team

Calendar%202 Dec 18, 2006 User Avatar LinuxSecurity.com Team Server Security
83

London Wireless Conference: Fake Wi-Fi Login Spreads Linux Malware

Security experts attending the Wireless LAN Event in London last Wedesday found that anonymous hackers in the crowd had created a Web site that looked like a genuine log-in page for a Wi-Fi network, but which actually sent 45 random viruses to computers that accessed it. "[This] gets very nasty as we've never seen it before," said Spencer Parker, a director of technical solutions at AirDefense. "It downloads 45 different randomly generated viruses, worms and keyloggers so antivirus software doesn't protect it. It doesn’t recognise the signatures." . Parker said that the hackers walked around the exhibition carrying a Linux-based laptop running software that turned it into a wireless access point. Initially, they labelled the hotspot "Free_Internet_Access", then "BTOpenzone" and then "T-Mobile". Parker, whose computer was infected by the attack, believes that the Web site was up for half an hour. The link for this article located at ZDNet is no longer available. . Cybercriminals utilized a Unix-based notebook to set up a fraudulent Wi-Fi access point, distributing harmful software during an IT expo in London.. Wi-Fi Attack, Wireless Security Threats, Cybersecurity Risks, Linux Malware, IT Conference Incident. . LinuxSecurity.com Team

Calendar%202 Apr 26, 2005 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200