Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 6 articles for you...
77

Zero Trust for Email: Implementing Advanced Protections on Linux

Email threats have long outgrown spamming and obvious phishing. Attackers now exploit trust itself. They impersonate internal users, hijack legitimate threads, and abuse misconfigured configurations. Defenses like perimeter filtering or static rules are not adequate any longer. A Zero Trust model redefines the issue by eliminating implicit trust at all phases of email processing. This shift is especially important in modern Linux mail environments where services are often modular, network-exposed, and heavily dependent on correct configuration across multiple components. . Redefining Trust at the Protocol Level On Linux mail servers, Zero Trust starts with the rigid implementation of authentication protocols. Correctly configured SPF, DKIM, and DMARC make sure that any incoming message is authenticated against policy at the domain level before being accepted. However, implementation alone is not enough. The policy needs to be set to enforcement mode as opposed to passive monitoring, and logs should be checked on a regular basis to detect anomalies. In practical deployments, this means moving DMARC policies toward “quarantine” or “reject” rather than “none.” This ensures that spoofed messages are actively blocked instead of only observed. Outbound validation is equally important. Preventing unauthorized messages from leaving your infrastructure protects both your reputation and your users. This two-fold verification makes a closed circle where trust has to be created on both sides. This includes restricting SMTP submission to authenticated sessions only and preventing unauthenticated relaying, which is a common misconfiguration in exposed mail servers. Hardening the Mail Stack A Zero Trust approach requires a hardened foundation. Mail transfer agents such as Postfix and mail delivery agents like Dovecot should be configured with minimal exposure. Turn off unneeded services, use TLS in all connections and limit access with firewall rules and network segmentation.Additional hardening should include: Disabling legacy authentication mechanisms Enforcing modern TLS versions Restricting administrative interfaces to trusted internal networks or VPN-only access The principles presented in the Linux hardening guide will reinforce this further by minimizing the attack surface and implementing stringent access controls. Combined with regular patching and long-term Linux support, systems are resilient to known vulnerabilities and new threats. Applying system-level hardening practices such as least privilege access, secure file permissions for mail configurations, etc., prevents the underlying operating system from becoming the weakest link in the mail security chain. Zero Trust Email Architecture Design Considerations A Zero Trust email system on Linux should be designed as a layered architecture rather than a single server handling all responsibilities. Separating roles such as mail transfer, authentication, filtering, and storage reduces blast radius and improves fault isolation. For example, Postfix can handle SMTP routing while a separate filtering layer processes content before delivery to Dovecot. This segmentation ensures that even if one component is compromised, the entire mail flow is not immediately exposed. Continuous Verification Over Static Rules Zero Trust is not a one-time configuration; it is an ongoing process of validation. Email content should be scanned dynamically using multiple layers, including: Heuristic analysis Reputation checks Sandboxing for suspicious attachments These layers are often chained together in mail pipelines so that each message is evaluated at multiple stages rather than relying on a single pass filter. Open-source security tools are essential in this regard. Adaptive filtering can be installed in Linux environments with solutions like: SpamAssassin ClamAV Rspamd These tools must be regularly tuned according to the threat intelligence instead of the defaultsettings. Static defenses fade away, whereas systems that are constantly updated remain effective. For example, rule sets should be updated based on live threat feeds, and scoring thresholds should be adjusted to reduce false negatives in high-risk environments. Identity and Access Controls Matter Compromised credentials remain a leading cause of email-based attacks. This risk is mitigated by enforcing strong authentication systems like multi-factor authentication on all mail users. In Linux, email services can be integrated with a centralized identity management system to enable a stricter access policy. Integration with PAM-based authentication or centralized directory services allows consistent enforcement of authentication policies across all mail-related services. Service accounts and administrative access should also be under least privilege principles. Restricting the number of people configuring or accessing the mail system curtails the possibility of misuse or escalation. Administrative SSH access and mail configuration privileges should be separated, ensuring that operational accounts cannot directly modify mail routing or authentication rules. Monitoring, Logging, and Response A Zero Trust model requires visibility. Full logging of SMTP transactions, authentication attempts, and system modifications can help quickly identify anomalies. Logs need to be proactively analyzed and not stored. Centralized log aggregation using syslog pipelines or SIEM-style tooling improves correlation between authentication events, mail delivery patterns, and system changes. Automated alert systems are capable of detecting abnormal patterns, including outbound mail spikes or failed logins. Organizations can swiftly transition to containment when a clear incident response plan combines with detection. When integrated properly, these systems can automatically throttle or block suspicious accounts based on behavioral thresholds, reducing response time during active attacks. Organizations operatinginternet-facing mail infrastructure should also consider DDoS protection solutions that can detect and mitigate large-scale traffic floods targeting SMTP gateways, authentication services, and other externally exposed communication systems before availability is disrupted. Endnote Organizations implementing a Zero Trust approach to email will be in a more favorable position to protect their systems as attackers continue to improve their methods. They do not respond to the threat when it manifests, but create a space where trust is constantly tested and never presumed. . Implement Zero Trust in Linux email systems by reinforcing security through authentication protocols and layered architecture.. Linux Email Security, Zero Trust Model, Threat Mitigation, Email Protocols, Security Architecture. . MaK Ulac

Calendar%202 Apr 17, 2026 User Avatar MaK Ulac Server Security
81

Exponential Spam Growth and Economic Effects Impacting Email 2002

The growth of the spam problem in 2002 has been exponential. Companies that sell spam filtering software say currently the percentage of email that is spam could be 20%, 33%, or even up to 50%, compared to less than 10% a year ago. While the rise in spam is easy to notice, it is hard to quantify. Spam is by definition "unsolicited commercial email", and often. . . . The growth of the spam problem in 2002 has been exponential. Companies that sell spam filtering software say currently the percentage of email that is spam could be 20%, 33%, or even up to 50%, compared to less than 10% a year ago. While the rise in spam is easy to notice, it is hard to quantify. Spam is by definition "unsolicited commercial email", and often spamees cannot remember signing up to have their email addresses added to lists, or were not aware they were doing so. BrightMail Inc, the market leader in anti-spam services, says emails sent to its honey-pot email addresses are by definition unsolicited, and that it has seen spam on its customers' networks increase from 8% of mail to 41% of mail in the last 14 months. Wasting time deleting UCE can be a productivity concern for enterprises. A survey by SurfControl Plc said 25% of enterprise email is spam and that each message costs up to a dollar. CloudMark Inc said 10 spams per day could cost a company $86 per employee per year. Even if getting spam was free, there's a general consensus it's still annoying enough to want to filter. But why has it become so much of a problem this year? We asked executives from companies that provide anti-spam software and services to explain. "Now anyone can do it," said Pavni Divanji, CEO of MailFrontier Inc. "The process is so streamlined. You can buy a CD of email addresses, buy mailing software, find an open relay and start doing it. People think it's easy and that they can make a few dollars off it." The economics of spam are attractive for both the spammers and the companies that pay them to spam, particularly given the macroeconomy in the US. Email marketing has low response rates, typically less than half a percent, but is very, very cheap. Growing numbers of e-businesses can't blow $50m of IPO money on TV and direct mail campaigns any more, and all the people they laid off into a depressed job market are looking for new sources of income. Enrique Salem, CEO of BrightMail, said he talked to a spammer last week who was paid $1,500 to send one million spams. Even with a response rate of just one tenth of a percent, that's 1,000 likely customers reached for $1.50 a head. For the spammer, the cost was negligible. "A lot of the Chinese, Korean and Latin American spam originates in the US ... People are looking at alternate ways to make money. It's a way to augment their income," said Salem. "Companies are looking at alternative ways to market and reach customers." It's also exceptionally easy to get started as a spammer. CDs of 150 million email addresses can be bought for as little as $100 online. Web sites maintain lists of open email relays, many in Asia, which can be used to push mail through. "The social stigma has gone," said MailFrontier's Divanji. "People don't think twice about doing it." This point is debatable. While spammers think as long as no laws are broken they are not doing anything wrong, recent published interviews with spammers tell stories of harassment from irate spamees, both online and off. But, just as finding people who respond to spam is a numbers game, finding people who have no ethical qualms with eating the bandwidth of millions of people and giving them headaches every morning should be easy. "If this trend continues unchecked, it's going to make email unusable," said Salem. . The growth of spam in 2002 shows a significant rise impacting companies and email users alike, leading to productivity concerns.. spam growth, email threats, spam filtering, economic impact. . LinuxSecurity.com Team

Calendar%202 Nov 03, 2023 User Avatar LinuxSecurity.com Team Privacy
74

Examining PDF And Image Spam Risks In Email Security Protocols

The spam landscape has changed quite a lot in the last year or so with image spam and now the latest tactic is PDF and .zip attachments. PDF. Of course there was some nasty exploits in PDF recently aswell with some other XSS issues associated. The link for this article located at DarkNet is no longer available. . Unveil new risks posed by PDF and image-based attachment spam, highlighting recent XSS vulnerabilities and evolving spam strategies.. Email Malware, Image Spam Risks, PDF Exploits, Cyber Threats. . Bill Locke

Calendar%202 Aug 17, 2007 User Avatar Bill Locke Network Security
74

Exploring Insider Risks And Email Threats In Organizations

Most security breaches by insiders are unintentional. They come from employees who make ill-advised or uninformed choices regarding storage of their passwords, the Web sites they visit, and the E-mails they send. The Computing Technology Industry Association's annual survey on IT Security and the Workforce trends, to be published in March, indicates that nearly 80% of corporate security breaches are caused by computer-user error. . One in four outbound E-mails poses a legal, financial, or regulatory risk to the sending company, according to a 2005 survey conducted by Forrester Research and messaging security software maker Proofpoint Inc. of 332 IT executives and managers. Companies expect insider risks to grow, and nearly half of survey respondents plan to deploy technology to monitor Web mail or instant messaging to combat these threats. The link for this article located at Information Week is no longer available. . A significant fraction of emails sent externally—about a quarter—harbors potential legal, financial, or compliance risks for the originating organization, exposing concealed dangers.. Insider Risks, Email Threats, Monitoring Tools, Security Breaches, Password Safety. . Benjamin D. Thomas

Calendar%202 Jan 23, 2006 User Avatar Benjamin D. Thomas Network Security
74

2004 DTI Survey Reveals Critical Insights On Network Safety

The DTI Information Security Breaches Survey 2004 (ISBS) is the UK's leading source of information on security incidents suffered by businesses, both large and small. One of the most surprising statistics to emerge from this year's DTI survey is that 7% of UK organizations are yet to implement any form of anti-virus software. Almost equally disconcerting is the fact that 41% of businesses do not immediately update their anti-virus software when a new virus signature is identified. . . .. The World Wide Web is lauded for its ability to deliver instant communications and connectivity. However, the web's speed and convenience brings with it the threat of both targeted and indiscriminate malicious attacks. The DTI Information Security Breaches Survey 2004 (ISBS) is the UK's leading source of information on security incidents suffered by businesses, both large and small. One of the most surprising statistics to emerge from this year's DTI survey is that 7% of UK organizations are yet to implement any form of anti-virus software. Almost equally disconcerting is the fact that 41% of businesses do not immediately update their anti-virus software when a new virus signature is identified. ISBS illuminates the ever-present danger of viruses, unauthorized access, systems misuse, fraud and theft. With 90% of UK computer users frequently sending emails and browsing the web as a normal part of their working day, this increased connectivity to `the outside world' is also attracting a deluge of unsolicited email or spam that is undermining the efficiencies of electronic communication. Two-thirds of large companies with sophisticated IT security systems admitted that their defenses were breached by an email-borne virus at least once in the last year. The link for this article located at net-security.org is no longer available. . The Internet facilitates connection; however, it also poses dangers such as phishing. Explore findings from a notable study in 2005.. Network Security Insights, Anti-Virus Adoption, Email Threats. .Anthony Pell

Calendar%202 Aug 24, 2004 User Avatar Anthony Pell Network Security
81

Phishing Threats: Essential Prevention Strategies for Email Users

By now just about every person with an email inbox has been exposed to a phishing scam. Spoofs are showing up with alarming frequency and to make matters worse, criminals have upped the ante with increasingly sophisticated coding and graphics. Gone are the childishly misspelled emails from the High Prince of the Sudan. Advanced techniques leveraging secure phishing servers and high-quality reproductions have contributed to a lucrative criminal enterprise. . . .. By now just about every person with an email inbox has been exposed to a phishing scam. Spoofs are showing up with alarming frequency and to make matters worse, criminals have upped the ante with increasingly sophisticated coding and graphics. Gone are the childishly misspelled emails from the High Prince of the Sudan. Advanced techniques leveraging secure phishing servers and high-quality reproductions have contributed to a lucrative criminal enterprise. The Anti-Phishing Working Group (APWG) is an industry association focused on eliminating the identity theft and fraud that result from the growing problem of phishing and email spoofing. The organization provides a forum to discuss phishing issues, define the scope of the phishing problem in terms of hard and soft costs, and share information and best practices for eliminating the problem. According to the APWG, the average phishing operation nets a 5% return on email spoofs. The percentage is alarming considering millions of addresses are included in a single phishing expedition. If a phisher gets 100 answers to his spoof and successfully scams each one for $100, it's $100,000 easily made. The demographic responding to phishing scams run the gamut from the overly trusting elderly to college professors too busy to think twice. As Dave Jevans, Chairman of the APWG explains, many instances of phishing victimization are the result of sheer coincidence. He uses the example of a consumer applying for credit with the local bank. The next day the consumer finds a spoofed email in his inbox and thinks it isrelated to his credit application. Acting dutifully, he provides his personal information. The link for this article located at net-security.org is no longer available. . By now just about every person with an email inbox has been exposed to a phishing scam. Spoofs are s. about, every, person, email, inbox, exposed, phishing, spoofs. . LinuxSecurity.com Team

Calendar%202 Aug 11, 2004 User Avatar LinuxSecurity.com Team Privacy
74

Challenges in Network Security: Defense Strategies Against Intrusions

Day and night, the war of attrition rages in the beleaguered world of network security. Defenders throw up firewalls, download patches, and scramble to fend off the hundreds of thousands of attempted intrusions into worldwide enterprise data. . . .. Day and night, the war of attrition rages in the beleaguered world of network security. Defenders throw up firewalls, download patches, and scramble to fend off the hundreds of thousands of attempted intrusions into worldwide enterprise data. The siege, a deep drain on corporate budgets, has been largely invisible to the general public and, until recently, even to the legions of employees who work outside information technology. But with the rising volume of spam, and the spread of inbox-clogging worms like MyDoom and Sobig, even noncombatants have begun to grasp some of the dimensions of the business security challenge. "You go back 10 years and there might have been a hundred viruses a year," said Randy Breault, manager of information security services for Hannaford Brothers Co. in Portland, Maine. "Now there are several hundred a month." The link for this article located at Boston.com is no longer available. . Morning and evening, the battle of endurance unfolds in the troubled realm of data protection. Guardians strive to repel breaches.. Network Protection, Cyber Defense, Intrusion Prevention, Organizational Security, Email Threats. . Anthony Pell

Calendar%202 Feb 11, 2004 User Avatar Anthony Pell Network Security
74

Examining the Sobig Worm's Role in the Rise of Spam in 2003

The Sobig worm is to thank for a massive increase in spam e-mail during 2003 and the problem of unsolicited commercial junk e-mail is set to get worse in 2004.. . .. The Sobig worm is to thank for a massive increase in spam e-mail during 2003 and the problem of unsolicited commercial junk e-mail is set to get worse in 2004. That is according to UK-based e-mail filtering company MessageLabs, which claims that there was a 77 percent increase in global spam volumes this year. The firm said that in May, the global spam to e-mail ratio exceeded 50 percent for the first time, with the average ratio for the year being one spam for every 2.5 normal e-mails received. This compared to 1 in 11 during 2002. But possibly the most worrying statistic in the report was a claim that more than two-thirds of all spam was sent through hijacked computers, thanks in part to malware like the Sobig worm which represents a new breed of cyber-pest that blends spamming with viruses. "Sobig.F, the pre-eminent example of this convergence, sought not only to infect a machine and propagate further through mass mailing techniques, but to compromise systems by exploiting open proxies," commented Mark Sunner, chief technology officer at MessageLabs "This backdoor route turns infected PCs into spam relay engines -- causing individual users concern, as well as security breaches and lost bandwidth and productivity for organisations." The link for this article located at ElectricNews.net is no longer available. . The Sobig worm is to thank for a massive increase in spam e-mail during 2003 and the problem of unso. sobig, thank, massive, increase, e-mail, during, problem. . Anthony Pell

Calendar%202 Dec 16, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200