Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 6 articles for you...
72

WAF Bypass Method Discovered in Claroty Research on Cambium Security

Researchers at industrial and IoT cybersecurity firm Claroty have identified a generic method for bypassing the web application firewalls (WAFs) of several major vendors. . Claroty’s researchers discovered the method following an analysis of Cambium Networks’ wireless device management platform. They discovered a SQL injection vulnerability that could be used to obtain sensitive information, such as session cookies, tokens, SSH keys and password hashes. Exploitation of the flaw worked against the on-premises version, but an attempt to exploit it against the cloud version was blocked by the Amazon Web Services (AWS) WAF, which flagged the SQL injection payload as malicious. Further analysis revealed that the WAF could be bypassed by abusing the JSON data sharing format . JSON syntax is supported by all major SQL engines and it’s enabled by default. The link for this article located at Security Week is no longer available. . Experts at Claroty uncovered a technique that circumvents leading vendor WAF protections, highlighting weaknesses within Cambium's systems.. WAF Bypass, SQL Injection Vulnerability, Cybersecurity Research. . Brittany Day

Calendar%202 Dec 14, 2022 User Avatar Brittany Day Firewalls
83

Undetected RotaJakiro Linux Malware Exfiltrates Sensitive Data

Researchers have discovered a dangerous strain of Linux malware Dubbed " RotaJakiro " that went undetected for three years, enabling its operators to harvest and exfiltrate sensitive data from infected systems. . A previously undocumented Linux malware with backdoor capabilities has managed to stay under the radar for about three years, allowing the threat actor behind to harvest and exfiltrate sensitive information from infected systems. Dubbed " RotaJakiro " by researchers from Qihoo 360 NETLAB, the backdoor targets Linux X64 machines, and is so named after the fact that "the family uses rotate encryption and behaves differently for root/non-root accounts when executing." The link for this article located at The Hacker News is no longer available. . Uncover the cunning Windows virus SneakyRodent that remained hidden for over three years, quietly siphoning off confidential information.. Linux Malware,RotaJakiro,Data Exfiltration,Data Security,Malware Threat. . LinuxSecurity.com Team

Calendar%202 Apr 29, 2021 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

HARES Software Protection: Innovative Anti-Reverse Engineering Method

Software reverse engineering, the art of pulling programs apart to figure out how they work, is what makes it possible for sophisticated hackers to scour code for exploitable bugs. It. At the SyScan conference next month in Singapore, security researcher Jacob Torrey plans to present a new scheme he calls Hardened Anti-Reverse Engineering System, or HARES. Torrey The link for this article located at Wired is no longer available. . Discover an innovative approach that has the potential to transform how software safeguards itself from reverse engineering, as introduced by Jacob Torrey.. Software Protection, Anti-Reverse Engineering, Cybersecurity Research. . LinuxSecurity.com Team

Calendar%202 Feb 12, 2015 User Avatar LinuxSecurity.com Team Cryptography
74

Innovative Botnet Communication Analysis and Reverse Engineering Techniques

Networks of compromised computers controlled by a central server, better known as botnets, are a Swiss Army knife of tools for online criminals. Hackers can use these co-opted systems to churn out spam, host malicious code, hide their tracks on the Internet, or flood a corporate network to cut off its access to the Web.. Whenever a new botnet appears, researchers race to reverse engineer the software it installs on a victim's machine, and to decode the way each bot communicates with the controlling server. Because these communications are often encrypted, such analyses can take weeks or months. Now researchers from the University of California at Berkeley and Carnegie Mellon University have created a way to automatically reverse engineer the communications between compromised computers and their controlling servers. In a paper to be presented this week at the Association for Computing Machinery's Conference on Computer and Communications Security, the researchers show how automatic reverse engineering can decipher the structure and purpose of the communications between a command-and-control server and its bots. The link for this article located at Technology Review is no longer available. . Whenever a new botnet appears, researchers race to reverse engineer the software it installs on a vi. networks, compromised, computers, controlled, central, server, better, known, botnets. . Alex

Calendar%202 Nov 13, 2009 User Avatar Alex Network Security
83

Cult of the Dead Cow Introduces New Malware Analysis Tool for Researchers

In the annals of computer "(in)security," few groups are as well known as the Cult of the Dead Cow (cDc). They are now adding a new chapter to their infamous history with the release of a new malware search engine that enables researchers to analyze over 31,000 "hostile" files. It's all part of an effort the cDc calls "offensive computing." Originally founded in 1984, cDc and its members are well known for a number of their efforts over the past 22 years. . The link for this article located at eSecurityPlanet.com is no longer available. . The link for this article located at eSecurityPlanet.com is no longer available.. annals, computer, '(in)security, groups, known. . LinuxSecurity.com Team

Calendar%202 Aug 09, 2006 User Avatar LinuxSecurity.com Team Hacks/Cracks
82

Federal Cybersecurity Coordination Recommendations on R&D

The Bush administration has drafted a federal plan to improve cybersecurity research and development. Yesterday, the National Science and Technology Council, a Cabinet-level body that coordinates governmentwide science and technology policies, issued a preprint release of the “Federal Plan for Cyber Security and Information Assurance Research and Development.. In addressing gaps in the country’s current cybersecurity activities, the 121-page report recommends setting R&D priorities and strengthening coordination between agencies and the private sector. The plan also calls for implementing emerging technologies, road maps and metrics. It does not address specific funding levels or budgets. Industry officials and lawmakers had been urging the administration to improve federal cybersecurity and information assurance R&D. Officials are billing this plan as the first step toward developing a federal agenda. Members of more than 20 government organizations prepared the document as part of the Interagency Working Group on Cyber Security and Information Assurance. The link for this article located at Federal Computer Week is no longer available. . In addressing gaps in the country’s current cybersecurity activities, the 121-page report recommen. administration, drafted, federal, improve, cybersecurity, research, development. . Brittany Day

Calendar%202 Apr 25, 2006 User Avatar Brittany Day Government
83

Exploring Witty Worm Origins: Target Systems and Exploit Methods

The Witty worm, which infected more than 12,000 servers a year ago, came from a single computer in Europe and used a U.S. military base's vulnerable systems to kick-start the epidemic, according to an analysis released by three researchers this week. . The researchers combined records from the initial spread of the Witty worm along with an analysis of the random number generator used by the program to pick its targets and discovered that the worm almost certainly spread initially from a computer owned by a customer of a European Internet Service Provider. The analysis also found that about 10 percent of the Internet's addresses would not have been generated, thus infected, by the Witty worm and that 110 computers at a U.S. military base were likely among a "hit list" of systems that were targeted explicitly by the worm. "We hope that the principle of exploiting a worm's structure will be more broadly applicable to forensics of future worms," said Vern Paxson, senior researcher with International Computer Science Institute at the University of California at Berkeley and one of the three researchers who co-authored the analysis of the Witty worm. Paxson, along with another researcher at ICSI and a computer science graduate student at the Georgia Institute of Technology, published the results in a paper this week, including new details of the worm's spread. The link for this article located at SecurityFocus is no longer available. . Investigations have traced the Clever caterpillar's beginnings and expansion, illuminating its primary target platforms and evaluation techniques.. Witty Worm, Malware Analysis, Cybersecurity Research. . LinuxSecurity.com Team

Calendar%202 May 25, 2005 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

UC Berkeley and USC Grant: Building Models For Internet Attacks

A team of professors from the University of California-Berkeley and University of Southern California has received a $5.46 million grant to build one of the most realistic models of the Internet -- and then wreck it with debilitating hacker attacks. Working . . . . A team of professors from the University of California-Berkeley and University of Southern California has received a $5.46 million grant to build one of the most realistic models of the Internet -- and then wreck it with debilitating hacker attacks. Working with researchers from Network Associates Laboratories and other institutions, the team is trying to answer questions with major national security implications: What would really happen if the Internet were hit with an attack bigger than the Nimda or Slammer worms? Could we fight it with existing technology? Or would everything connected to the Internet, from private e-mail boxes to automatic teller networks to power plants, topple like a house of cards? The link for this article located at Seattle Pi is no longer available. . A group from MIT and Stanford investigates digital fortitude through simulations and assessments of catastrophic online breaches.. Internet Modeling, Cybersecurity Research, Attack Simulation. . Anthony Pell

Calendar%202 Nov 07, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200