Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
74

Locking Down Linux Network Security with Private Routing Techniques

Linux runs a huge portion of today's infrastructure because it gives administrators an unusual amount of control over the system. That control extends to networking, where almost every aspect of packet flow, routing, filtering, and interface behavior can be customized. The trade-off is that very little of that hardening happens automatically. A fresh installation is usually built to communicate, not to isolate. . As environments grow, servers start exchanging data with monitoring platforms, storage systems, container hosts, cloud services, and internal applications. Some of those connections are intentional. Others remain long after the service that required them has disappeared. Private routing brings that communication back under control by defining where traffic is allowed to move instead of assuming every system should be able to reach every other system. Securing Administrative Access and Digital Identities Many network incidents don't begin with a firewall failure. They begin with an administrator losing control of the account that manages the environment. It's common for cloud consoles, DNS providers, monitoring platforms, backup services, and virtualization dashboards to share the same administrative email address. That account receives alerts, approves authentication requests, resets passwords, and often becomes the recovery path for everything else. If someone gains access to it, they may never need to attack the network directly. That's why identity should be addressed before touching routing tables or firewall policies. If there is any reason to believe those credentials have been exposed, take the time to reset your Google password or secure whichever primary administrative account your infrastructure depends on. Recovering those identities first keeps infrastructure alerts, password recovery requests, and management portals under your control while the rest of the environment is being reviewed. Once that's done, changes to routing and segmentation become much easier to trustbecause the accounts responsible for managing them haven't been left as an open question. Mitigating Application Layer Vulnerabilities Not every server deserves the same level of trust, even if they're running on the same network. Media processing systems are a good example. They often accept files from outside users, perform complex decoding operations, and rely on large third-party libraries that receive regular security updates. Recent disclosures involving ffmpeg reminded administrators how quickly a flaw in widely deployed software can become a much larger operational problem when that application sits beside more sensitive systems. Network segmentation changes the outcome. A vulnerable media server may still require patching, but it doesn't need unrestricted access to internal databases, authentication services, or file storage. Restricting communication to specific destinations keeps each workload focused on its own responsibilities. If one application behaves unexpectedly, the rest of the environment isn't automatically exposed simply because every route was left open. Patching the Core Operating System Firewall rules have one important assumption built into them. The operating system enforcing those rules is still trustworthy. Once root access is obtained, that assumption disappears. Routing tables can be rewritten, forwarding rules adjusted, firewall policies removed, and network activity hidden without changing the overall architecture. From the outside, the environment may still appear properly segmented while the host itself has already stopped enforcing those controls. That is one reason kernel updates deserve the same attention as firewall maintenance. Security researchers continue to uncover vulnerabilities that remained unnoticed for years, including a recently disclosed root-level issue that had existed for nearly a decade before administrators were advised to prioritize patching. Keeping Linux systems current isn't separate from network hardening. It's part of thesame effort because every routing decision ultimately depends on the operating system applying it correctly. Implementing Effective Private Routing Rules Open a firewall that's been running for several years, and the rule set often tells a story. Temporary exceptions become permanent. Test environments survive long after the project ends. Legacy services keep old ports open because nobody wants to remove something that might still be needed. Eventually, the firewall reflects years of operational history instead of the network that exists today. A default-deny policy forces that conversation back into the open. Using tools such as iptables, nftables , or UFW , administrators explicitly define the traffic that belongs while everything else remains blocked. That approach usually produces smaller, easier-to-audit rule sets because every allowed connection has an identifiable purpose. The same thinking applies to NAT and IP forwarding. Internal addresses should stay internal whenever possible, and administrative access is generally easier to monitor when it passes through a dedicated bastion host or jump server instead of exposing multiple management interfaces directly to the internet. Fewer entry points also make it much harder for external scanners to build an accurate picture of the network. Addressing Industry Standards and Compliance Compliance requirements tend to expose network designs that grew without much planning. During an audit, it's difficult to justify why a public web server can freely communicate with systems storing payment information or customer records if that connection serves no operational purpose. Questions like that often reveal routing decisions that were made years earlier and never revisited. Most regulatory frameworks expect sensitive workloads to be separated from internet-facing services through logical or physical segmentation. Private routing supports that separation by making communication predictable and intentional. Instead of relying on assumptionsabout how systems should behave, administrators can demonstrate exactly which connections exist and why they're allowed. That level of visibility helps during audits, but it also makes day-to-day administration much less complicated because unexpected traffic stands out instead of blending into everything else. Sustaining Network Integrity Over Time Networks rarely become less complicated on their own. New applications appear. Old servers stay online longer than expected. Teams add temporary firewall rules during deployments, migrations, or troubleshooting sessions, and many of those changes quietly survive well past their original purpose. None of that happens overnight, which is why gradual configuration drift is so easy to miss. Keeping private routing effective is mostly a matter of paying attention to those small changes before they accumulate. Reviewing firewall rules, checking routing policies, monitoring network logs, and removing access that no longer serves a purpose all contribute to a cleaner environment. The goal isn't to rebuild the network every few months. It's to make sure the documented design still matches what the infrastructure is actually doing. A well-segmented Linux network isn't defined by having the most firewall rules or the most restrictive configuration. It's defined by clarity. Administrators know which systems should communicate, which ones shouldn't, and the routing policies reflect those decisions instead of years of forgotten exceptions. That makes the environment easier to operate, easier to troubleshoot, and considerably easier to trust as it continues to grow. . Discover how to harden your Linux network by implementing private routing, managing traffic, and securing digital identities.. Linux network management, private routing, firewall best practices, application layer security, infrastructure protection. . Anthony Pell

Calendar%202 Jul 08, 2026 User Avatar Anthony Pell Network Security
76

Linux Foundation Announces OpenWallet Foundation for Digital Transactions

Linux Foundation Europe, an independent trusted supporter and vendor-neutral home for open source projects in Europe, today announced the official formation of the OpenWallet Foundation (OWF). This new, collaborative effort will develop open source software to support interoperability for a wide range of wallet use cases, including making payments, proving identity, storing validated credentials such as employment, education, financial standing, and entitlements — to enable trust in the digital future. . Inaugural Premier members sponsoring the OWF include Accenture, Gen, Futurewei and Visa. General members sponsoring the foundation include American Express, Deutsche Telekom / T-Systems, esatus AG, Fynbos, Hopae, IAMX, IDnow, IndyKite, Intesi Group, Ping Identity, SmartMedia Technologies (SMT), Spruce and Swisscom. Additionally, 20 leading nonprofits, academic and government entities have joined the foundation, including Customer Commons, Decentralized Identity Foundation (DIF), Digital Identification and Authentication Council of Canada (DIACC), Digital Dollar Project, Digital Identity New Zealand (DINZ), Digital Identity and Data Sovereignty Association (DIDAS), DizmeID Foundation (DIZME), Hyperledger Foundation, Information Technologies ics and Telematics Institute / Centre for Research and Technology Hellas (CERTH/ITI), Johannes Kepler University Linz, ID2020, IDunion SCE, Mifos Initiative, MIT Connection Science, Modular Open Source Identity Platform (MOSIP), OpenID Foundation, Open Identity Exchange (OIX), Secure Identity Alliance (SIA), Universitat Rovira i Virgili, and the Trust Over IP Foundation (ToIP). . The Linux Foundation reveals the establishment of the OpenPayment Alliance aimed at creating open-source solutions for electronic transactions.. OpenWallet Foundation, Digital Identity, Wallet Interoperability, Open Source Software, Digital Trust. . Brittany Day

Calendar%202 Feb 27, 2023 User Avatar Brittany Day Organizations/Events
81

France's Nationwide Facial Recognition Initiative Sparks Controversy

A nationwide facial recognition ID program is underway in France, in spite of a lawsuit and the data regulator's protests about lack of consent, data security and privacy. We'd love to hear your thoughts on this. Learn more: . France is creating – and speeding up the rollout of – a nationwide program using facial recognition to create legal digital identities for its citizens. The program is called Alicem – an acronym for “certified online authentification on mobile”. It was developed jointly by the Ministry of the Interior and the National Security Title Agency (ANTS), which maintain that it’s going to a) simplify getting online services while b) fighting identity theft, c) keeping the biometric data safe on the phone, making it disappear after validating identity, and d) not letting third parties get at the data. France had planned to launch the Android-only app by Christmas. But now, it’s greasing the wheels and plans to have it up and running in November 2019, Bloomberg reports. The link for this article located at NakedSecurity is no longer available. . Germany fast-tracks the rollout of a comprehensive biometric identification framework amid debates surrounding personal data security and individual rights.. facial recognition, digital identity program, biometric data security, identity verification. . LinuxSecurity.com Team

Calendar%202 Oct 08, 2019 User Avatar LinuxSecurity.com Team Privacy
83

60 Minutes to Secure Your Digital Identity Against Hacks

How's this for a digital nightmare? Your Twitter account hijacked; racist and homophobic tweets posted in your name. Your Apple account breached; data wiped from your iPhone, iPad and Mac laptop. Your Gmail password reset by hackers and your Google account deleted. . That's what happened to Wired journalist Mat Honan recently. And while news coverage of his "epic hack" may be easing, you can bet there's an army of would-be imitators who, as you read this, are trying to duplicate that attack.. Prevent online disasters such as data leaks. Discover methods to bolster your digital security in merely an hour.. Online Safety, Digital Identity Protection, Cybersecurity Strategies. . LinuxSecurity.com Team

Calendar%202 Aug 23, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

ThreatMetrix Cloud Device Fingerprinting for Transaction Fraud Protection

On Tuesday ThreatMetrix unveiled its new cloud-based transactional fraud network. Using its global database of device fingerprints. ThreatMetrix, a Los Altos, California-based company, has been working on its fraud network for four or five years, says Alisdair Faulkner, chief product officer at the company. What The link for this article located at Forbes is no longer available. . ThreatMetrix uses advanced device fingerprinting and cloud infrastructure to combat transaction fraud by identifying genuine users and flagging threats effectively. Transaction Fraud, Device Fingerprinting, Cloud Security, Fraud Detection, Digital Identity. . LinuxSecurity.com Team

Calendar%202 Mar 17, 2010 User Avatar LinuxSecurity.com Team Privacy
81

How The 10-Digit Rule Affects Privacy Rights and Digital Identity

Internet denizens and urban dwellers alike need to recognize that an era of anonymity is ending. The population of the world stands at about 7 billion. So it takes only 10 digits to label each human being on the planet uniquely.. This simple arithmetic observation offers powerful insight into the limits of privacy. It dictates something we might call the 10-Digit Rule: just 10 digits or so of distinctive personal information are enough to identify you uniquely. They're enough to strip away your anonymity on the Internet or call out your name as you walk down the street. The 10-Digit Rule means that as our electronic gadgets grow chattier, and databases swell, we must accept that in most walks of life, we'll soon be wearing our names on our foreheads. The link for this article located at CNET is no longer available. . Uncover the ways the 10-Digit Norm threatens our confidentiality and puts our distinct online personas at risk.. Digital Identity, Privacy Threats, Anonymity Loss. . LinuxSecurity.com Team

Calendar%202 Aug 17, 2009 User Avatar LinuxSecurity.com Team Privacy
67

Exploring HSPD-12 Influence on Public Key Infrastructure Standards

In 1995, when Tim Polk began working full time on developing standards and guidance for using public-key infrastructure applications, he figured it would be a two- or three-year project. But 11 years later, Polk, the National Institute of Standards and Technology. The link for this article located at Government Computer News is no longer available. . Explore the importance of HSPD-12 in strengthening the frameworks for public key infrastructure protocols.. Public Key Infrastructure, Digital Identity, Cryptography Standards. . LinuxSecurity.com Team

Calendar%202 Nov 27, 2006 User Avatar LinuxSecurity.com Team Cryptography
81

Understanding Password Security And Authentication Methods

While senior technology editor Curt Franklin was hard at work testing authentication tokens for this issue's cover story, I coincidentally ran into some questionable authentication policies and practices as a user. In lectures I've given and in classes I teach to network admins, I emphasize that people should never give their passwords to anyone. Your password and user name identify you to the network or servers. They are your digital ID and as such should be hidden through irreversible cryptography and protected from unauthorized alteration. But alas, as a customer I have dealt with two organizations, which will remain anonymous, that don't follow either principle. . . .. While senior technology editor Curt Franklin was hard at work testing authentication tokens for this issue's cover story, I coincidentally ran into some questionable authentication policies and practices as a user. In lectures I've given and in classes I teach to network admins, I emphasize that people should never give their passwords to anyone. Your password and user name identify you to the network or servers. They are your digital ID and as such should be hidden through irreversible cryptography and protected from unauthorized alteration. But alas, as a customer I have dealt with two organizations, which will remain anonymous, that don't follow either principle. Customer reps at my cell phone service provider always ask for my account password--the same password used to access my online account and authorize cell-phone plan, equipment and software purchases. I cringe every time I give it, fearing phone phreaks are tapping the call centers and gathering passwords. One of the banks with which I do business just completed a migration from one online account system to another, which required a re-enrollment of all users to synchronize credentials. Of course, my re-enrollment didn't go smoothly, so there I was, again, reading off my vitals over the phone. Only this time, anyone capturing my banking information could have had much more fun. The link for this article located at securitypipeline.com is no longer available. . While senior technology editor Curt Franklin was hard at work testing authentication tokens for this. while, senior, technology, editor, franklin, testing, authentication, tokens. . LinuxSecurity.com Team

Calendar%202 May 12, 2004 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200