Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 55 articles for you...
210

Google's OSS-Fuzz Initiative: Critical OpenSSL Flaws and AI Role

Google has long been at the forefront of innovation in cybersecurity, yet security vulnerabilities in its widely used products like Chrome browser and Gmail are frequently uncovered. While Google faces widespread criticism over security flaws in these popular products, its defensive security research efforts cannot be ignored. Google recently confirmed critical security flaws through AI by their OSS-Fuzz team, demonstrating their dedication to protecting digital infrastructure. . In this article, I'll explore the vulnerabilities recently discovered by Google, potential impacts, and at-risk parties, as well as how AI has played a pivotal role in helping them make these important discoveries. Google Uncovers Critical Vulnerabilities with AI Google's OSS-Fuzz team recently unveiled the discovery of 26 vulnerabilities in open-source projects, including CVE-2024-9143 in the OpenSSL Library , a critical element of internet security infrastructure. The out-of-bounds memory issue could potentially cause application crashes and remote code execution, creating severe risks. Unfortunately, this vulnerability likely escaped detection for two decades using conventional fuzz targets, underscoring latent threats lurking within popular software components. OpenSSL vulnerabilities represent a severe and widespread threat to global internet security since this program plays an essential role in encryption and protection across numerous systems and applications. Any potential vulnerability within its code represents a severe and widespread threat. Potential impacts could include application crashes that disrupt service and remote code execution, leading to data breaches , unauthorized system access, and more. Entities at risk include organizations using OpenSSL, software developers and maintainers responsible for software updates, as well as end users relying on these systems whose security may depend on them. Successful exploits could cause severe economic and personal harm. Understanding ArtificialIntelligence's Role in Identifying Security Flaws Source: Forbes Google's AI-powered Fuzz testing by its OSS-Fuzz team on August 16, 2023, marked a significant step forward for security testing. This initiative sought to use large language models (LLMs) capabilities for fuzz target creation, thus expanding coverage and automating the detection of vulnerabilities. Fuzzing typically involved manually creating targets to test different parts of software, an effort that was both time-consuming and less comprehensive than anticipated. With AI playing an instrumental role in automating target creation and development processes, the goal was to move away from manual target development towards full automation, with AI playing a crucial part in this. Fuzzing involves injecting invalid or random data into a system to discover vulnerabilities, while AI-generated fuzz targets serve similar functions to unit tests by probing specific functionalities for vulnerabilities. AI-powered fuzzing has provided more accurate and efficient detection of vulnerabilities, leading to preemptive identification before they can be exploited by malicious actors, thus improving overall security measures. Examining the Future of Google's AI-Powered Fuzz Testing Initiative Google's AI-fuzzing initiative has proven significant success by uncovering critical vulnerabilities in software like OpenSSL and SQLite. They hope to improve both the accuracy and coverage of AI-generated fuzz targets, expanding their ability to generate relevant context across projects and reducing developer workload. Fuzzing process automation will also be a priority. AI already plays an integral part in this lifecycle, from drafting to fixing issues to triaging crashes—eventually, fully automating it will decrease developer workload while increasing efficiency. Additionally, Google is committed to improving developer experiences by better incorporating AI into workflows. This involves using AI to simulate developer tasks, ensuring AI-generatedfuzz targets are as effective as those manually created. Providing project-specific context through AI should increase accuracy and quality as the initiative matures. It could offer substantial security benefits by quickly uncovering hidden vulnerabilities, making software ecosystems more secure. Our Final Thoughts on AI's Growing Role in Combating Security Bugs Google's successful use of Artificial Intelligence-powered fuzzing to identify critical security flaws underlines its transformative potential for cybersecurity. The discovery of an OpenSSL vulnerability highlights latent threats in widely trusted software and the necessity of consistently strengthening security practices and developing innovative approaches. AI technology will continue to advance, and AI's role in preemptively identifying vulnerabilities will only become more essential. Organizations, developers, and end-users must remain informed and proactive to mitigate risks and secure digital infrastructure. A more secure digital future may soon emerge with continued advancements in AI and collaborative efforts among the cybersecurity community. . Explore the latest AI-identified security flaws at Google, examining how these vulnerabilities could impact the integrity of digital systems and pose risks to cybersecurity frameworks.. AI Vulnerability Detection, Google Security Innovations, OpenSSL Threats, Fuzz Testing Advances. . Brittany Day

Calendar%202 Nov 22, 2024 User Avatar Brittany Day Security Vulnerabilities
81

Surprising Privacy Statistics Impacting Online Security Today

Not all Internet users are careless about their digital security - but many are still victims of cybercriminals and stalkers due to mistakes online. Here are ten online privacy statistics that may surprise you. . The online world sometimes feels like a mysterious place where we don't know people yet communicate with them and we can vent out our frustrations and thoughts without disclosing our identity. We feel we are safe under the mask of an online identity . The feeling of not being known gives us the confidence to share a huge part of our life on the internet. We feel secured as no one knows us in person. Our audience is unaware of our past and can only sneak into what we portray about ourselves, that is, the fabricated reality. But is this true? Are we really safe online? Does the internet provide us complete anonymity? The link for this article located at Security Today is no longer available. . Over 80% of data breaches occur from weak passwords, while 59% of users admit to reusing them, raising serious security concerns for all.. Privacy Awareness, Cyber Threats, Digital Security, Online Privacy, User Behavior. . LinuxSecurity.com Team

Calendar%202 May 19, 2020 User Avatar LinuxSecurity.com Team Privacy
81

Explore Techniques For Online Anonymity And Digital Security

One year after the first revelations of Edward Snowden, cryptography has shifted from an obscure branch of computer science to an almost mainstream notion: It. But it The link for this article located at Wired is no longer available. . But itThe link for this article located at Wired is no longer available.. first, revelations, edward, snowden, cryptography, shifted, obscure. . LinuxSecurity.com Team

Calendar%202 Jun 17, 2014 User Avatar LinuxSecurity.com Team Privacy
79

Exploring The Evolution Of Hacking Culture And Cyber Threats

Wow. It. Some of you will say The link for this article located at Shack Foo is no longer available. . Some of you will say The link for this article located at Shack Foo is no longer available.. article, located, shack, longer. . LinuxSecurity.com Team

Calendar%202 Jun 03, 2014 User Avatar LinuxSecurity.com Team Security Projects
83

Jake Davis's Journey From Teenage Hacker To Convicted Criminal

As . It all ended for Jake Davis two years ago when he was arrested in his home in the Shetland Islands on suspicion of more than 80 charges of conspiracy. He eventually pleaded guilty to two counts ( The link for this article located at Independent UK is no longer available. . Emma Carter's transformation from a budding programmer to a notorious cybercriminal underscores the intricate challenges of online security and digital offenses.. Jake Davis, Cybersecurity Threats, Digital Crime Case, Security Breach Insights. . LinuxSecurity.com Team

Calendar%202 Oct 18, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Mat Honan Hack: Security Wake-Up Call from a Disturbing Incident

If I've seemed a little bleary-eyed and inattentive this week you can blame Jim Fallows. Late on Tuesday night I read his post about gmail, which linked to Mat Honan's piece for Wired about the destruction of his (Honan's) digital life. I was then up most of the night implementing Jim's advice about improving my computer security. This is by no means the first warning Jim has issued. . (His wife's gmail was hacked a while back and he did a memorable article for the magazine about it.) For some reason this latest episode, unlike the others he's related, finally pierced my complacency and I resolved to do something about it. I don't think I'm an easy person to shock but I was stunned by what happened to Honan--to be more precise, by how it happened. All his devices were remotely wiped and he lost his entire gmail archive. (In fact the hacker could have done much more damage than he evidently did. He seems not to have wanted Honan's money so much as his Twitter account, mainly for bragging purposes.) But the amazing thing was the hacking method. "Phobia" didn't have to steal or break a password. He didn't need to plant spyware. He started with a phone--as in an actual telephone, not a smartphone--and Honan's name, email address and billing address. Incredibly, that was enough to persuade Amazon to invite him into Honan's account. There the hacker found another piece of information (the last four digits of a credit-card number) which in turn was enough for Apple to extend its own welcome. What the hacker did was smart, all right--but it was grifting not code-work. And it was Amazon and Apple, for heaven's sake, that fell for it.. (His wife's gmail was hacked a while back and he did a memorable article for the magazine about it.). seemed, little, bleary-eyed, inattentive, blame, fallows. . LinuxSecurity.com Team

Calendar%202 Aug 13, 2012 User Avatar LinuxSecurity.com Team Server Security
83

Olympics Digital Security Risks From Hacktivism And Cyber Crime

Analysts say infiltrating the scoring and timing systems at one of the 35 competition venues around Britain, especially the Olympic stadium in east London, is a target for hackers looking to spread political messages, known as 'hacktivists', and criminal gangs looking to cash in on the Games. . "The digital systems recording scores and timings are susceptible to attack and will be targeted by hacktivists wanting to make a statement and by organized crime groups looking to profit from betting on events," said a former UK government cyber security boss who wished to remain nameless. The link for this article located at Yahoo Sports is no longer available. . Cybersecurity frameworks for sports analytics are increasingly under threat from malicious actors seeking to exploit vulnerabilities for financial gain amidst the Olympic Games.. Olympic Security, Hacktivist Threats, Digital Systems, Cyber Crime, Betting Fraud. . LinuxSecurity.com Team

Calendar%202 Jul 24, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

FBI's Surveillance Push: Legislation For Backdoor Access In Messaging Apps

The FBI has been lobbying top internet companies like Yahoo and Google to support a proposal that would force them to provide backdoors for government surveillance, according to CNET. . The Bureau has been quietly meeting with representatives of these companies, as well as Microsoft (which owns Hotmail and Skype), Facebook and others to argue for a legislative proposal, drafted by the FBI, that would require social-networking sites and VoIP, instant messaging and e-mail providers to alter their code to make their products wiretap-friendly. The link for this article located at Wired is no longer available. . The Bureau has been quietly meeting with representatives of these companies, as well as Microsoft (w. lobbying, internet, companies, yahoo, google, support, proposal. . LinuxSecurity.com Team

Calendar%202 May 07, 2012 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200