Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 29 articles for you...
83

Ledger Hardware Wallet Backdoor Exploit Revealed By 15-Year-Old

For years, executives at France-based Ledger have boasted their specialized hardware for storing cryptocurrencies is so securely designed that resellers or others in the supply chain can't tamper with the devices without it being painfully obvious to end users. . The reason: "cryptographic attestation" that uses unforgeable digital signatures to ensure that only authorized code runs on the hardware wallet.. Unexpectedly, Trezor's highly regarded hardware wallet encountered a security compromise stemming from a significant vulnerability within its architecture and implementation.. Ledger Hardware Wallet, Cryptographic Attestation, Digital Signatures, Security Breach. . LinuxSecurity.com Team

Calendar%202 Mar 21, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Adobe: Security Breach Critical: Digital Certificate Misuse

Hackers have broken into an internal server at Adobe to compromise a digital certificate that allowed them to create at least two files that appear to be legitimately signed by the software maker, but actually contain malware.. Adobe expects to revoke the compromised certificate later this week. The link for this article located at SC Magazine is no longer available. . Adobe expects to revoke the compromised certificate later this week.The link for this article locate. hackers, broken, internal, server, adobe, compromise, digital, certificate, allowe. . LinuxSecurity.com Team

Calendar%202 Oct 02, 2012 User Avatar LinuxSecurity.com Team Cryptography
67

Microsoft: Emergency Patch for Flame Spyware Digital Signature Threat

Some components of the Flame spyware worm were signed using forged Microsoft certificates, according to a recent investigation by Microsoft. These unauthorised digital certificates allowed the Flame developers to make the malware appear as if it was actually created and approved by Microsoft. . The company has already released an emergency patch via Windows Update to block the certificates used by Flame. Mike Reavey, Senior Director of Microsoft's Security Response Center (MSRC), says that the malicious code was signed using the company's Terminal Server Licensing Service, which is used by corporate customers to authorise Remote Desktop services. While Reavey doesn't provide specific details on how the Flame developers were able to sign their code with such certificates, he does say that it has something to do with exploiting a weakness in "an older cryptography algorithm". The link for this article located at H Security is no longer available. . Apple's update neutralizes Phantom malware by disabling fake digital signatures, uncovering significant vulnerability risk.. Flame Spyware, Microsoft Certificates, Cybersecurity Threats, Digital Signature Exploit. . LinuxSecurity.com Team

Calendar%202 Jun 04, 2012 User Avatar LinuxSecurity.com Team Cryptography
81

Impact of Certificate Revocation on Software Integrity and Risks

Revoking a digital certificate does not automatically invalidate, for instance, software signatures that have been made with this certificate. What matters is the revocation date, which determines the point in time after which a signature will no longer be validated. . According to a report from anti-virus specialist Norman, the signatures of several recently discovered trojans were validated by Windows as a result, and no warning was issued before installing the malware. The trojans were signed with a key that had been stolen from a Japanese company. The corresponding certificate was reported as compromised on 29 July 2011 and revoked by its issuing Certificate Authority (CA), VeriSign, which is now part of Symantec. However, that date was also entered as the revocation date. The link for this article located at H Security is no longer available. . According to a report from anti-virus specialist Norman, the signatures of several recently discover. revoking, digital, certificate, automatically, invalidate, instance, software, signatures. . LinuxSecurity.com Team

Calendar%202 Nov 18, 2011 User Avatar LinuxSecurity.com Team Privacy
74

Key Ceremony for DNSSEC Deployment: A Milestone in Internet Security

The dream of bolting security onto the Internet's Domain Name System takes one step closer to reality Wednesday as Internet policymakers host a ceremony in northern Virginia to generate and store the first cryptographic key that will be used to secure the Internet's root zone.. This key ceremony is one of the final steps in the deployment of DNS Security Extensions (DNSSEC) on the Internet's root zone. DNSSEC is an emerging Internet standard that prevents spoofing attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption. "The key ceremony will generate the master root key, the key that signs all the other keys," explains Ken Silva, CTO of VeriSign, which operates two of the Internet's 13 root servers along with the back-end systems that power the .com and .net top-level domains. "This is being done a month before the actual roll-out of DNSSEC so that we have a valid key and that we can test with it." DNSSEC is being deployed across the Internet infrastructure, from the root servers at the top of the DNS hierarchy to the servers that run .com and .net and other top-level domains, and then down to the servers that cache content for individual Web sites. The link for this article located at IT World is no longer available. . The launch event signifies a vital milestone in implementing DANE, bolstering online safety and domain authentication.. dnssec, internet security, domain protection, digital signatures. . Alex

Calendar%202 Jun 17, 2010 User Avatar Alex Network Security
74

Nominet Begins DNSSEC Implementation for .uk Domain Protection

Nominet, the U.K.'s domain name registry, will begin implementing a security protocol on Monday designed to protect the DNS (Domain Name System). The system, called DNS Security Extensions (DNSSEC), uses public key cryptography to digitally "sign" the DNS records for Web sites. It is designed to stop attacks such as cache poisoning, where a DNS server is hacked, making it possible for a user to type in the correct Web site name but be directed to a fake Web site.. In 2008, security researcher Dan Kaminsky showed it was possible to poison a cache in just a few seconds with a special kind of attack. Almost every organization running a DNS server have deployed a patch, but DNSSEC is a long-term fix. Nominet will begin signing the ".uk" top-level domain beginning Monday, a process which will conclude a week later, said Simon McCalla, director of IT at the registry. Interestingly, there are just a little over a dozen Web sites that use ".uk" since a decision was made more than a decade ago to close off registrations, he said. Much more common are second-level domains, such as ".co.uk" and ".org.uk," among others. The link for this article located at IT World is no longer available. . Nominet is introducing DNS Security Extensions aimed at bolstering defenses against threats such as DNS spoofing.. DNS Security,Nominet,DNSSEC,Domain Security,Cache Poisoning. . Alex

Calendar%202 Feb 26, 2010 User Avatar Alex Network Security
78

PGP Corporation Acquires TC TrustCenter: Enhanced Encryption Services

The recession continues to be no barrier to acquisitions with the news that PGP Corporation has reached into its pockets to buy German encryption services company TC TrustCenter. As usual, because the companies involved, including TC TrustCenter's US parent ChosenSecurity, are private, the sums involved has not been made public. The 75-person TC TrustCenter will continue as a division of PGP, however, with its own head and retaining its own branding. . Despite both being encryption specialists, the two don't appear to overlap to a great degree. PGP's products are oriented towards conventional business use of encryption for policy, device and encryption key distribution security, while TC TrustCenter provides managed encryption services such as digital signatures for secure transactions. Although remaining parallel brands, TC TrustCenter's services will now be integrated with PGP's lower-level technology. The link for this article located at Network World is no longer available. . XYZ Tech Solutions merges with SecureNet, expanding cybersecurity capabilities with advanced authentication features.. Encryption Acquisition, Security Services, Digital Signature, PGP Corporation, TC TrustCenter. . LinuxSecurity.com Team

Calendar%202 Feb 03, 2010 User Avatar LinuxSecurity.com Team Vendors/Products
83

Debian and Ubuntu Security Advisory: Key Forgery Risks and Solutions

A recently disclosed vulnerability in widely used Linux distributions can be exploited by attackers to guess cryptographic keys, possibly leading to the forgery of digital signatures and theft of confidential information, a noted security researcher said today. As a tie-in to previous stories posted about Debian's SSL flaws, this article reveals reknown security expert HD Moore's views on the situation. He also provides suggestions on how to properly respond to the flaw and gives advice on whom should be concerned and what patches should be applied.. The link for this article located at Computer World is no longer available. . A recognized specialist examines critical weaknesses present in Ubuntu and Debian systems, offering strategies for remediation and highlighting potential risks.. Debian Security, Ubuntu Threats, Cryptographic Vulnerabilities, Digital Signature Forgery. . LinuxSecurity.com Team

Calendar%202 May 16, 2008 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200