Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
83

Intel: Platypus Attack Method Threatens Data Extraction

Security researchers have discovered a new attack method dubbed "Platypus" that can extract data from Intel CPUs. Intel has now released microcode updates to prevent malicious actors from exploiting the Intel RAPL mechanism with Platypus. . A team of academics has disclosed today a new attack method that can extract data from Intel CPUs. Named Platypus , an acronym for " P ower L eakage A ttacks: T argeting Y our P rotected U ser S ecrets," the attack targets the RAPL interface of Intel processors. RAPL , which stands for Running Average Power Limit, is a component that allows firmware or software applications to monitor power consumption in the CPU and DRAM. . A novel exploit technique dubbed Otter has been identified, allowing data retrieval from AMD processors, which has now been mitigated through firmware patches.. Intel Data Extraction, Platypus Attack Method, CPU Security Measures. . LinuxSecurity.com Team

Calendar 2 Nov 11, 2020 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

PDFex Attack: Data Exfiltration Threat to Widely Used PDF Readers

Have you heard about the new attack that German academics have developed that can extract and steal data from encrypted PDF files, sometimes without user interaction? Learn more: . Named PDFex, the new attack comes in two variations and was successfully tested against 27 desktop and web PDF viewers, including popular software such as Adobe Acrobat, Foxit Reader, Evince, Nitro, and Chrome and Firefox's built-in PDF viewers. The attack doesn't target the encryption applied to a PDF document by external software, but the encryption schemes supported by the Portable Document Format (PDF) standard, itself. The link for this article located at ZDNet is no longer available. . Uncover the techniques behind the PDFex vulnerability, which takes advantage of the encryption features in PDF documents, impacting leading systems and posing risks to sensitive information.. PDFex Attack, Data Extraction, PDF Encryption, Document Security. . LinuxSecurity.com Team

Calendar 2 Sep 30, 2019 User Avatar LinuxSecurity.com Team Cryptography
67

Christopher Tarnovsky's Insights on TPM Attacks and Key Extraction

An American hacker has, with a great deal of effort, managed to crack a Trusted Platform Module (TPM) by Infineon. He was able to read the data stored on the TPM chip, for instance cryptographic keys (RSA, DES) such as those also used by Microsoft's BitLocker on appropriate motherboards.. TPM hardware incorporates various levels of logical as well as physical measures designed to counter a range of attacks, such as differential electromagnetic analyses (DEMA) and even physical intrusions. Once the keys are retrieved, however, an attacker can read the encrypted data stored on a hard disk without needing a password. Previously known as the smart card hacker, Christopher Tarnovsky of Flylogic Engineering has presented his work at the Black Hat DC security conference. He apparently managed to suss out a processor in the "SLE 66CLX360PE"PDF family used in the TPM. For this purpose, he extracted the actual chip from the housing in his special lab using various procedures that involved liquids and gases (a video about this is available online). The link for this article located at H Security is no longer available. . A skilled programmer showcases breaching a Hardware Security Module to retrieve digital encryption keys and access secured information.. Trusted Platform Module,Cryptographic Keys,Data Encryption,Physical Security. . LinuxSecurity.com Team

Calendar 2 Feb 11, 2010 User Avatar LinuxSecurity.com Team Cryptography
74

In-Depth Exploration of CDPSnarf for CDP Packet Analysis

CDPSnarf is a network sniffer exclusively written to extract information from CDP packets. It provides all the information a . The link for this article located at Darknet.org is no longer available. . Dive into CDPSnarf, an advanced utility for harvesting information from CDP packets, and elevate your abilities in network analysis.. CDP Tools, Packet Analysis, CDPSnarf, Network Monitoring, Data Sniffer. . Brittany Day

Calendar 2 Apr 30, 2008 User Avatar Brittany Day Network Security
82

CTX's NetWitness: A Tool for ISPs to Ensure Data Compliance Safely

The Forensics Explorers division of CTX is ready to go to market with a Carnivore-like suite called NetWitness which, the company says, can enable ISPs to surrender to the Feds only those specific bits of information about a suspect which a court has authorized for collection.. . .. The Forensics Explorers division of CTX is ready to go to market with a Carnivore-like suite called NetWitness which, the company says, can enable ISPs to surrender to the Feds only those specific bits of information about a suspect which a court has authorized for collection. The NetWitness package can separate data to ensure strict, minimal compliance with a pen register or trap and trace order, and later associate the original content if a search warrant or a wiretap warrant is issued, Forensics Explorers General Manager Mark Longworth told The Register. Because Carnivore is capable of capturing far more data than a pen register or trap and trace order is meant to make available, an ISP may well prefer to install its own kit rather than trust Carnivore operators to stick to the letter of the law. . CTX's Forensics Team unveils DataGuardian, an adherent information gathering solution for internet service providers aimed at fulfilling legal inquiries from authorities.. Forensics Explorers, NetWitness, Data Collection, Compliance Tool. . Anthony Pell

Calendar 2 Oct 02, 2001 User Avatar Anthony Pell Government
81

Web Bugs And Tracking Devices Disrupting User Privacy Online

Piracy advocates claim that the use of sophisticated Web bug tracking devices "has grown dramatically" over the past year. More than 30 per cent of Web pages sampled during last year's Christmas season contained new generations of Web bugs that the . . . . Piracy advocates claim that the use of sophisticated Web bug tracking devices "has grown dramatically" over the past year. More than 30 per cent of Web pages sampled during last year's Christmas season contained new generations of Web bugs that the advertising industry is using to secretly track online surfers, said Richard Smith, CTO at the University of Denver's Privacy Foundation. He used a search engine and identified four million Web bugs planted by 30 vendors. Smith said he has found that bugs are planted by the Boston bank he uses for online banking, and on a hotel site offering Internet room-booking services. He said many companies aren't disclosing their use of bugs in their privacy policies, and at least one Web bug version he uncovered searches a user's computer while they are looking at the site. The link for this article located at Lexis-Nexis is no longer available. . Cybersecurity proponents argue that advanced tracking technologies have significantly escalated, affecting individual privacy rights.. Web Bugs, User Tracking, Privacy Risks, Digital Surveillance. . LinuxSecurity.com Team

Calendar 2 Apr 16, 2001 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here