Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
209

Evolving OpenSSL Threats: Defense Strategies After Heartbleed

In 2014, the cybersecurity community witnessed a critical OpenSSL vulnerability, “ Heartbleed ,” which changed how the world perceived digital security. It is considered to be among the most serious flaws in internet history. Heartbleed not only exposed the weaknesses in popular cryptographic protocols but also the potential repercussions of a small coding error. . Following the Heartbleed event, the cybersecurity landscape experienced a dramatic change as the emphasis shifted to fortifying security protocols and resolving the root causes of vulnerabilities. Several upgrades, improved code standards, stringent security audits, and a dedication to addressing identified vulnerabilities were the outcomes of this momentum. However, as with any constantly evolving technology, vulnerabilities continued to emerge in OpenSSL despite these efforts. The post-Heartbleed vulnerabilities remind us that security is an ongoing process, and we must remain vigilant, ensuring that security practices align with the latest security recommendations. The link for this article located at Security Boulevard is no longer available. . Following the Equifax breach, the landscape of digital security shifted dramatically, highlighting the critical need for persistent awareness.. OpenSSL Threats,Cybersecurity Trends,Code Vulnerabilities,Protocol Security. . Brittany Day

Calendar%202 Nov 17, 2023 User Avatar Brittany Day Security Trends
82

APT36 Threatens Indian Government Agencies with Custom Malware

APT36 is a highly sophisticated APT (Advanced Persistent Threat) group known for conducting targeted espionage in South Asia and is strongly linked to Pakistan. . While this APT group is known for targeting the following Indian sectors: Government Defense Education Since 2013, this APT group has been active, and to conduct cyber espionage, it uses the following methods:- Credential harvesting Malware distribution Here below, we have mentioned the resources used by APT36:- Custom-built remote administration tools targeting Windows Lightweight Python-compiled cyber espionage tools serving specific purposes targeting Windows and Linux Weaponized open-source C2 frameworks like Mythic Trojanized installers of Indian government applications like KAVACH multi-factor authentication Trojanized Android apps Credential phishing sites targeting Indian government officials Zscaler analysts dubbed the Windows backdoor used by APT36 ‘ElizaRAT,’ because of unique strings in observed C2 commands. The link for this article located at CyberSecurity News is no longer available. . APT36 utilizes tailored malicious software targeting Indian governmental divisions such as education and defense, representing significant risks.. APT36,CyberEspionage,GovernmentMalware,EducationSecurity,DefenseAttacks. . Brittany Day

Calendar%202 Sep 16, 2023 User Avatar Brittany Day Government
76

Nokia Android NFC Exploits: Security Issues And Mitigations

A new technology being added to smartphones running the Google Android and Linux-based MeeGo operating systems makes it trivial for hackers to electronically hijack handsets that are in close proximity, a researcher appearing at the Black Hat security conference said.. By exploiting multiple security weakness in the industry standard known as Near Field Communication, smartphone hacker Charlie Miller can take control of handsets made by Samsung and Nokia. The attack works by putting the phone a few centimeters away from a quarter-sized chip, or touching it to another NFC-enabled phone. Code on the attacker-controlled chip or handset is beamed to the target phone over the air, then opens malicious files or webpages that exploit known vulnerabilities in a document reader or browser, or in some cases in the operating system itself.. Leveraging flaws in NFC technology may result in unauthorized access to mobile devices. Discover methods to address and reduce these security risks.. NFC Security, Smartphone Hack, Android Threats. . Dave Wreski

Calendar%202 Jul 25, 2012 User Avatar Dave Wreski Organizations/Events
79

Apache Server Defense Against DDoS Attacks: Apache Killer Threat

Apache, the open-source Web server, is the most popular Web server on the planet. It's also as safe as safe can be. Well, usually it is. An old, unfixed security hole has come back to haunt the Apache webmasters in the form of a Distributed Denial of Service (DDoS) attack tool: Apache Killer. . You may have already heard about this, and ignored it. I mean, in a world where every day brings a new security hole announcement but the Web keeps working anyway, many people have taken to a "Who cares" attitude. That's usually a mistake. And, when it comes to Apache Killer, it could be a business-killing mistake. The link for this article located at svjn / HP is no longer available. . Uncover strategies to shield your web server from Apache Killer's DDoS onslaughts and enhance your cybersecurity measures.. Apache Server, DDoS Attack, Open Source Security, Web Defense, Cybersecurity Tips. . LinuxSecurity.com Team

Calendar%202 Aug 29, 2011 User Avatar LinuxSecurity.com Team Security Projects
79

U.S. Department of Defense Introduces Lightweight Secure Linux Distro

The U.S. Department of Defense and the Air Force Research Laboratory have decided to respond and offer up a way to use a PC securely by developing a new lightweight and secure Linux distribution.. It The link for this article located at Geek.com is no longer available. . Explore a new minimalistic Linux distribution developed by the U.S. Department of Defense tailored for safe computing environments.. Lightweight Linux Distribution, Secure Computing Solutions, U.S. Department of Defense. . LinuxSecurity.com Team

Calendar%202 Jul 22, 2011 User Avatar LinuxSecurity.com Team Security Projects
82

Gates Issues Warning: Huge Cyber Threats To U.S. Infrastructure

Officials from the Departments of Defense (DoD) and Homeland Security (DHS) this week warned that the prospect of a cyber attack remains imminent even as their agencies continue to monitor threats to U.S. critical infrastructure. . Speaking at The Wall Street Journal's CEO Council, Secretary of Defense Robert M. Gates said the future threat of a cyber attack is "huge," while there is a "considerable current threat." "That's just the reality we all face," he said according to a transcript of his comments. The link for this article located at Information Week is no longer available. . During a dialogue at the World Economic Forum, Security Chief Lee cautions about massive digital risks facing America's foundational systems.. Cybersecurity, Threat Assessment, Critical Infrastructure, Cyber Warfare, Defense Security. . Alex

Calendar%202 Nov 19, 2010 User Avatar Alex Government
81

Government's Approach to Balancing Security and Privacy Rights

If you don't want the government to do what it must to protect you from terrorists, you should butt out, said Heather MacDonald, a lawyer at the Manhattan Institute, a conservative think tank. She made her remarks Wednesday at the 13th . . . . If you don't want the government to do what it must to protect you from terrorists, you should butt out, said Heather MacDonald, a lawyer at the Manhattan Institute, a conservative think tank. She made her remarks Wednesday at the 13th annual Computers, Freedom and Privacy conference. And, she urged, stop all the panic-stricken screaming, because it's endangering human lives. Al-Qaida and other terrorist groups wield technology as a weapon with no worries about privacy rights, MacDonald said. But fear and distrust of anti-terrorism and surveillance technology hampers the U.S. government's ability to shore up defenses and stop attacks before they happen. The link for this article located at Wired.com is no longer available. . If you don't want the government to do what it must to protect you from terrorists, you should butt . don't, government, protect, terrorists, should. . LinuxSecurity.com Team

Calendar%202 Apr 04, 2003 User Avatar LinuxSecurity.com Team Privacy
82

Homeland Security Summit 2023: Explore Technology and Ventures in Defense

In a sure sign of the changing times, executives from promising technology start-ups will rub elbows with venture capitalists and representatives from the federal government at an exclusive Florida resort next month to hatch ideas for one of the hottest areas . . . . In a sure sign of the changing times, executives from promising technology start-ups will rub elbows with venture capitalists and representatives from the federal government at an exclusive Florida resort next month to hatch ideas for one of the hottest areas of technology investment these days: domestic defense. Dubbed "The Technology & Homeland Security Summit," the two-day event will be held in Orlando November 1-2, according to the summit organizers, Infinite Personal Networks LLC. An exclusive event, the summit is limited to only 35 participants and requires parties interested in attending to submit an application "describing their role in the homeland security industry" before being allowed to attend. For those whose applications are accepted, the registration fee for the conference is $3,000, a price that does not include travel or accommodations, according to information provided by the organizers. The link for this article located at idg.net is no longer available. . In a sure sign of the changing times, executives from promising technology start-ups will rub elbows. changing, times, executives, promising, technology, start-ups, elbows. . Anthony Pell

Calendar%202 Oct 17, 2002 User Avatar Anthony Pell Government
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200