Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 11 articles for you...
210

X.Org: Security Advisory on Severe Memory Flaws and Code Execution Risks

After recent heap overflow, out-of-bounds write, and privilege escalation flaws brought X.Org into the spotlight, more severe memory safety, use-after-free, heap buffer overread, and code execution vulnerabilities have been identified in the popular X server. These issues affect the X.Org X11 server. . To help you secure your systems against exploits leading to service disruption, data compromise, and other damaging repercussions, we'll explore the vulnerabilities found, their impact, and how to mitigate them. What Vulnerabilities Have Been Found in the X.Org X11 Server? What Is the Impact of These Flaws? Vulnerabilities discovered in X.Org X11 include: The X.Org X Server incorrectly handled memory when processing the RRChangeOutputProperty and RRChangeProviderProperty APIs. An attacker could use this issue to cause the X Server to crash or obtain sensitive information. ( CVE-2023-6478 ) The X.Org X Server incorrectly handled memory when processing the DeviceFocusEvent and ProcXIQueryPointer APIs. An attacker could use this issue to cause the X Server to crash, obtain sensitive information, or execute arbitrary code. ( CVE-2023-6816 ) The X.Org X Server incorrectly handled reattaching to a different master device. An attacker could use this issue to cause the X Server to crash, leading to a denial of service, or possibly execute arbitrary code. ( CVE-2024-0229 ) The X.Org X Server incorrectly labeled GLX PBuffers when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. ( CVE-2024-0408 ) The X.Org X Server incorrectly handled the curser code when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. ( CVE-2024-0409 ) The X.Org X Server incorrectly handled memory when processing the XISendDeviceHierarchyEvent API. An attacker could use this issue to cause the X Server to crash or execute arbitrary code. ( CVE-2024-21885 ) The X.Org X Serverincorrectly handled devices being disabled. An attacker could use this issue to cause the X Server to crash or execute arbitrary code. ( CVE-2024-21886 ) Heap buffer overread/data leakage in ProcXIGetSelectedEvents. ( CVE-2024-31080 ) Heap buffer overread/data leakage in ProcXIPassiveGrabDevice. ( CVE-2024-31081 ) User-after-free in ProcRenderAddGlyphs. ( CVE-2024-31083 ) These vulnerabilities could have severe repercussions on impacted systems, enabling attackers to disrupt services and steal sensitive information, potentially resulting in the complete compromise of your critical Linux systems. How Can I Secure My Systems Against These X.Org Bugs? An essential X.Org update that fixes these issues has been released. We urge all impacted users to update to the latest version of X.Org as soon as possible. Applying the patches released by your distro(s) will protect your systems against attacks leading to downtime and compromise. To stay informed of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter , and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on X for real-time updates on advisories for your distro(s) . . With new vulnerabilities in X.Org, adopting a multi-layered security approach is crucial. Steps like patching, access controls, and user education are essential. X.Org security, Memory safety fixes, Linux code execution, Open source update. . Anthony Pell

Calendar 2 Apr 15, 2024 User Avatar Anthony Pell Security Vulnerabilities
212

Exploit Risks of Misconfigured Azure Services in EmojiDeploy Attack Chain

Multiple misconfigurations in a service that underpins many Azure features could have allowed an attacker to remotely compromise a cloud user's system. . An attack chain exploiting misconfigurations and weak security controls in a common Azure service is highlighting how lack of visibility impacts the security of cloud platforms. The "EmojiDeploy" attack chain could allow a threat actor to run arbitrary code with the permission of the Web server, steal or delete sensitive data, and compromise a targeted application, Ermetic stated in its Jan. 19 advisory . An attacker could use a trio of security issues affecting the common Source Code Management (SCM) service — a cloud service used by many Azure applications without an explicit indication to the user, according to Ermetic. The issues demonstrate that the security of cloud platforms are undermined by the lack of visibility into what those platforms do under the hood, says Igal Gofman, head of research for Ermetic. The link for this article located at DarkReading is no longer available. . A vulnerability pathway leveraging insufficient configurations and lax defenses in a widely used Azure platform could present significant threats.. AzureService, CloudSecurity, MisconfigurationRisk, AttackChain. . Brittany Day

Calendar 2 Jan 26, 2023 User Avatar Brittany Day Cloud Security
83

LabCorp Data Security Incident: Numerous Patient Records Exposed

LabCorp, a healthcare diagnostics company, has shut down its systems after a suspected network breach, which could have put millions of health records at risk. . In a report to the United States Securities and Exchange Commission, the company announced that during the weekend of July 14 2018, it had detected suspicious activity on its IT network and immediately took specific systems offline. The company said that the suspicious activity has been detected only on LabCorp Diagnostics systems, and that "there was no indication that it affected systems used by Covance Drug Development." The link for this article located at InfoSecurity is no longer available. . LabCorp's potential cyber attack threatens vast amounts of health data, leading to system lockdown for security measures.. LabCorp Breach, Network Compromise, Health Data Security. . LinuxSecurity.com Team

Calendar 2 Jul 19, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

HealthEquity: 23000 Accounts Compromised Due To Email Breach

Sometimes all it takes is one employee to spark a cybersecurity wildfire, as HealthEquity learned this week. The company, which handles more than 3.4 million health savings accounts, suffered a data breach when an unauthorized person accessed an employee's email account.. The incident took place on April 11 and was discovered two days later. When the company learned an employee's email was compromised, it removed access to the mailbox and hired a forensics firm to confirm the breach did not affect other HealthEquity systems. The link for this article located at DarkReading is no longer available. . The incident took place on April 11 and was discovered two days later. When the company learned an e. sometimes, takes, employee, spark, cybersecurity, wildfire, healthequity, learned. . LinuxSecurity.com Team

Calendar 2 Jun 15, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Drupal.org User Data Breach Investigation: Unauthorized Access Revealed

The Drupal.org security team says it has discovered unauthorised access to Drupal.org and groups.drupal.org account information which has exposed user names, country, and email addresses along with hashed passwords. . No credit card information was stored on the servers, but the investigation is ongoing and the team says it "may learn about other types of information compromised". The link for this article located at H Security is no longer available. . Inquiry in progress following the revelation of unauthorized entry into user records on Drupal.org, revealing confidential details.. Drupal Security, User Data Breach, Unauthorized Access, Account Security. . LinuxSecurity.com Team

Calendar 2 May 30, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

State Employee Phishing: Risks to Data Security From Official Emails

The email sent to several thousand of state employees in early February looked official. It featured the state logo and a familiar warning that email access was about to be cut off because the employee. If an employee clicked, a screen popped up asking for more data, including the employee The link for this article located at Forbes is no longer available. . Public sector workers are encountering phishing attacks as cybercriminals send spoofed communications to obtain confidential information.. State Employee Cybersecurity, Phishing Risks, Data Security Threats. . LinuxSecurity.com Team

Calendar 2 Mar 07, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

SwaggSec Claims Breach of Warner Bros and China Telecom Networks

A hacking group is claiming to have breached the networks of Warner Bros. and China Telecom, releasing documents and publishing login credentials.. Swagger Security, or "SwaggSec," announced the breach Sunday on Pastebin, providing a link to the files on The Pirate Bay. The group has been active since early this year when it claimed credit for stealing user names and passwords for an ordering system belonging to the contract manufacturer Foxconn, which builds devices for technology companies including Apple. The link for this article located at Computer World is no longer available. . The hacker collective known as 'SwaggSec' asserts it has infiltrated both Paramount Pictures and China Unicom, releasing confidential files online.. SwaggSec,Hack,Credentials,Network Security,Cybersecurity. . LinuxSecurity.com Team

Calendar 2 Jun 04, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

d33ds Team Breaches Rival Hacker's Online Shop Selling Compromised Access

A hacking group called d33ds broke into the online shop of a rival hacker who sells unauthorized access to high-profile websites and data.. This illegal marketplace has been used in the past to advertise information stolen from websites belonging to the U.S. Army, the U.S. Department of Defense, the South Carolina National Guard and other institutions. Its owner, a hacker calling himself Srblche, also offered services that included compromising the particular servers his customers wanted. According to Rob Rachwald, director of security strategy at security firm Imperva, Srblche is believed to be Kuwaiti. "We tracked his Facebook profile," Rachwald said Thursday. The link for this article located at Computer World is no longer available. . An adversarial cybercriminal's digital store is infiltrated by a competing faction, disclosing a seedy bazaar for hacked web platforms.. Compromised Websites, Cybercrime, Hacking Group, Data Breach, Security Incident. . LinuxSecurity.com Team

Calendar 2 Nov 04, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here