Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 6 articles for you...
83

Protecting Linux from Anubis Ransomware: Strategies and Best Practices

The Anubis ransomware group has emerged as a growing threat, targeting Linux environments, NAS devices, and ESXi systems. What sets Anubis apart is its novel ransomware-as-a-service (RaaS) model featuring lucrative affiliate programs offering high revenue share programs with financial rewards to encourage attacks with incentives for dissemination. . These dynamics are a challenge for us Linux security admins, as they open up more avenues for criminals to enter our networks, posing additional threats. Understanding this campaign's complex tactics will significantly reduce your chances of falling prey to Anubis ransomware threats. I'll explain how Anubis ransomware works, what makes it so dangerous, and practical measures you can take to safeguard your systems and critical data. Exploring Anubis's Cross-Platform Capabilities Anubis ransomware stands out among other variants by simultaneously targeting multiple platforms, particularly Linux ones. Ransomware attacks have traditionally focused only on Windows environments, but Anubis has expanded its attack surface significantly by targeting NAS devices and ESXi systems. This cross-platform capability dramatically expands Anubis' threat landscape for organizations using multiple operating systems. Anubis' developers have ensured their malicious software can exploit vulnerabilities across environments, making effective patching routines essential. Updating all systems regularly ensures vulnerabilities are quickly addressed so ransomware won't establish itself on vulnerable systems. Adopting endpoint protection solutions capable of detecting and mitigating ransomware behavior on all platforms is also a wise preventative measure against ransomware outbreaks. Understanding The Ransomware-as-a-Service Model Anubis's ransomware-as-a-service (RaaS) business model may not be unique, but its extensive affiliate program sets an unprecedented benchmark in this dark marketplace. By offering affiliates high revenue shares--up to 80% in someinstances--Anubis has decentralized ransomware deployment processes and provided access for cybercriminals with limited technical knowledge to purchase Anubis and use it in their attacks. This affiliate-driven model makes it even harder to anticipate and defend against potential threats, with traditional defenses such as firewalls and antivirus software no longer sufficing. Expanding network monitoring capabilities to detect unusual activities that could indicate breaches is of critical importance. Intrusion detection and prevention systems (IDS/IPS) play an invaluable role in detecting unauthorized access before significant damage is caused, while regular security audits help identify security flaws before attackers can exploit them. Anubis's Advanced Extortion Tactics Anubis employs sophisticated extortion techniques in addition to encrypting data and demanding ransom from victims to apply additional pressure. Using stolen information for "investigative articles", Anubis creates additional incentive by increasing the urgency and stakes associated with ransom negotiations, potentially subjecting victim organizations to regulatory scrutiny and suffering reputational damage. Linux administrators need more than data encryption alone to protect against modern extortion tactics, so implementing robust encryption practices to safeguard sensitive information at rest and during transit is crucial for keeping breaches to a minimum and mitigating extortion attacks. In addition, regular and secure backups provide essential protection. Through regular online backups, administrators can restore systems without engaging with cybercriminals for their restoration. Taking Proactive Security Measures Against Anubis Given the sophistication of Anubis ransomware attacks, Linux admins must take an aggressive stance regarding security. Doing so involves employing technical measures, regular maintenance, and employee training programs to stay one step ahead. Ensuring all systems are up-to-date withpatches is also key as vulnerabilities in outdated software provide entryways for ransomware to gain entry and cause havoc. Network monitoring tools are invaluable in spotting unusual activity that could signal a breach. Tools like intrusion detection and prevention systems (IDS/IPS) effectively flag suspicious behavior and block malicious attacks. Additionally, comprehensive log practices enable administrators to better track what's going on inside their network, making it easier for them to quickly detect and respond to potential threats in real time. Encryption is another key ransomware defense mechanism that protects sensitive information from being used for ransom schemes or by attackers to break into systems. Even if an attack does happen, encrypted data remains useless without its decryption keys. Secure backups must also be created regularly and stored offline to avoid ransomware infecting and infiltrating backup data. The Critical Importance of Employee Training Human factors play a pivotal role in security breaches. Ransomware attacks typically start through misleading emails that persuade employees to download potentially hazardous files or click harmful links, opening themselves up for ransomware attacks. Employee training programs can reduce this risk by teaching staff members to recognize and avoid attempts at fraud. Training employees with mock phishing attacks is an incredibly effective strategy. By giving employees hands-on practice identifying and responding to potential phishing threats, employees become less vulnerable against real attacks. Furthermore, creating an organizational culture of security awareness ensures employees understand why adhering to security protocols and reporting suspicious activities is imperative. Incident Response Planning Breach incidents happen despite our best efforts. Having an incident response plan (IRP) allows organizations to respond swiftly and efficiently when an attack hits, including isolating infected systems, assessing breachseverity and initiating recovery processes. Conducting periodic tests and updates of an incident response plan are vital. Simulated attack exercises can help pinpoint weaknesses while assuring all team members understand their roles and responsibilities during an incident. Clear communication channels guarantee that all relevant stakeholders receive timely notifications to facilitate coordinated response efforts. Our Final Thoughts on Mitigating the Anubis Ransomware Threat Anubis ransomware presents us Linux security admins with an immense challenge. Capable of targeting multiple platforms simultaneously and with lucrative affiliate programs as well as advanced extortion tactics, Anubis poses a formidable and sophisticated threat. However, by adopting comprehensive security measures, they can safeguard both systems and data against an attack. Vigilant monitoring and encryption practices can drastically reduce the risk of suffering an Anubis ransomware attack. Employee training and an effective incident response plan will further fortify your organization against this sophisticated threat. Anticipating and understanding the tactics of groups like Anubis allows us to remain one step ahead and protect our systems against the most advanced ransomware threats. . Discover proactive strategies to combat the Anubis ransomware menace specifically aimed at Linux platforms and techniques to bolster overall cybersecurity.. Anubis Ransomware, Ransomware Strategies, Linux Threat Protection. . Brittany Day

Calendar%202 Feb 28, 2025 User Avatar Brittany Day Hacks/Cracks
79

Key Elements for Cultivating a Successful Security Culture

When we were asked to keynote a recent CSO event, it was a pleasant surprise that the top concern of the CSOs was "security culture." From performing many security assessments and penetration tests, it is sadly obvious that even the best technical security efforts will fail if their company has a weak security culture. . It is heartwarming that CSOs are now moving past straight technological solutions and moving towards instilling a strong security culture as well. To determine the components of a truly successful security awareness program, we performed a study to identify critical success factors for building one. We interviewed security awareness practitioners at Fortune 500 companies and surveyed the security staff and general employees at the companies. Additionally, we validated the results and gathered additional information at a security executive event in the United Kingdom with more than 150 security executives participating. The link for this article located at CSO Online is no longer available. . Uncover essential components that fuel effective security awareness initiatives and enhance the security culture within organizations.. Security Culture, Awareness Program, Success Factors, Employee Training. . LinuxSecurity.com Team

Calendar%202 May 03, 2013 User Avatar LinuxSecurity.com Team Security Projects
83

Protecting Employees From Cyber Threats In Social Engineering Attacks

Attackers are taking aim at the weakest point in your network: human beings. Do you know how to protect your data?. Pop quiz time: Which endpoint vulnerability is a hacker most likely to exploit to gain access to your enterprise network resources? It's not some unpatched Windows flaw or browser vulnerability. It actually isn't any technology at all. Your most vulnerable endpoint is the technology user a few cubes over. The link for this article located at Dark Reading is no longer available. . Uncover the tactics employed by cybercriminals who exploit staff as the most vulnerable point in a security framework, alongside strategies to enhance digital security protocols.. Cyber Threats, Employee Training, Data Protection, Social Engineering. . LinuxSecurity.com Team

Calendar%202 Apr 16, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Stanford Hospital: 20000 Patient Records Exposed Due To Privacy Lapse

The ongoing furor over fake SSL certificates continued to dominate security headlines, while increasing SpyEye botnet activity and leaked patient health information also drew attention the week of Sept. 5.. The week's biggest data breach news had nothing to do with Anonymous or any other online group. Instead, Stanford University's hospital confirmed that a spreadsheet containing 20,000 patient records had been posted onto a commercial Website. In this incident, an employee of a third-party service provider to the hospital posted the entire patient information spreadsheet to a Website in search of help on creating bar graphs. This is a remarkable, yet telling example of what can go wrong if employees are not trained to be privacy conscious. The link for this article located at eWeek is no longer available. . The latest data security headlines shifted focus from the usual suspects, revealing significant vulnerabilities that have led to alarming breaches in sensitive information.. Data Breach, Healthcare Security, Patient Records, Privacy Training, SSL Security. . LinuxSecurity.com Team

Calendar%202 Sep 12, 2011 User Avatar LinuxSecurity.com Team Cryptography
79

Combatting Social Engineering: Employee Training Strategies for Success

In the enterprise data security chain, human beings often prove to be the weakest link. Using social engineering tactics, thieves can frequently gain secret information about a company's systems simply by asking. To prevent this, not only must employees be trained, but systems must be changed to reinforce the policies employees have learned.. Imagine this situation: A coworker calls you in a panic. He's facing a fast-approaching deadline, and you are the only person who can help him succeed in getting some critical task done. This hypothetical coworker explains to you what he's working on and how it's critical to the success of the organization in some way; he's at his wits' end in trying to accomplish a portion of that task (say, downloading a critical file from an internal file server), and he's asking you in desperation to help him out. Would you help him? Of course, right? Most of us wouldn't even stop to think about it. And most of the time, helping out a coworker like this would be the right thing to do. Not only would it benefit the person asking for help, but it would benefit the organization as well. It's no question why: Our success as a species has always been made possible by our natural proclivity to assist each other in a pinch. For eons, we've helped each other till the fields, build shelters, herd animals, fight off invaders and so forth. The desire to help our neighbors and community members is a powerful driving force that's arguably hard-wired in to our psyche -- by helping our communities succeed, we help ourselves. The link for this article located at Tech News World is no longer available. . In the digital age, social engineering poses a serious risk to employees, using psychological manipulation to compromise security and access sensitive data. employee training, social engineering, data security awareness. . LinuxSecurity.com Team

Calendar%202 Aug 17, 2010 User Avatar LinuxSecurity.com Team Security Projects
83

Fortune 500 Exposed: Social Engineering Contest Reveals Security Gaps

A few companies in the Fortune 500 need to upgrade their Web browsers. And while they're at it, a little in-house training on social engineering wouldn't be a bad idea, either.. Social engineering hackers -- people who trick employees into doing and saying things that they shouldn't -- took their best shot at the Fortune 500 during a contest at Defcon Friday and showed how easy it is to get people to talk, if only you tell the right lie. Contestants got IT staffers at major corporations, including Microsoft, Cisco Systems, Apple and Shell, to give up all sorts of information that could be used in a computer attack, including what browser and version number they were using (the first two companies called Friday were using IE6), what software they use to open pdf documents, their operating system and service pack number, their mail client, the antivirus software they use, and even the name of their local wireless network. The link for this article located at Network World is no longer available. . Social engineering hackers -- people who trick employees into doing and saying things that they shou. companies, fortune, upgrade, their, browsers, while, they're. . LinuxSecurity.com Team

Calendar%202 Aug 02, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Importance of Employee Awareness in Corporate Network Security

Analysts, law enforcement agents and corporate IT managers focused on surprisingly nontechnical security solutions Tuesday as they discussed the latest risks to corporate networks as part of Ziff Davis Media's online "virtual" tradeshow on security. . "Management support at the highest levels of an organization is critical to the success of any security initiative," said panelist Stephen Doty, a manager at BearingPoint, a systems integration services firm based in McLean, Va. "You need to look at policies and prevention that support the organization's IT and information security needs." Bill Mallick, a vice president at analyst firm Aberdeen Group, agreed, stressing the need for senior management buy-in and understanding of security issues, as well as an increase in employee training on both awareness and reporting of security threats. "A big portion of getting information security out there is really informing your employees," Mallick said. "If they know how to respond to and report security issues, then you've already won." The link for this article located at Michael Myser is no longer available. . 'Management support at the highest levels of an organization is critical to the success of any secur. analysts, enforcement, agents, corporate, managers, focused, surprisingly, nontechnical. . Joe Shakespeare

Calendar%202 Dec 01, 2004 User Avatar Joe Shakespeare Network Security
78

Ernst & Young 2004 Survey: Irish Firms' Focus on Security Strategies

Irish companies are aware of internal threats to security, but give higher priority to technological safeguards than they do to employee training.The 2004 Ernst & Young Global Information Security Survey found that Irish . . .. The 2004 Ernst & Young Global Information Security Survey found that Irish companies are more aware of security threats than their international counterparts. More than 70 percent of the 1,233 organisations surveyed in 51 countries failed to list training and employee awareness of security issues among their top five security initiatives. In contrast, Irish companies listed employee misconduct as a fourth priority, while viruses, Trojans and worms were collectively listed as the number one security priority. Spam and loss of customer data were the second and third priorities for Irish businesses. "There are a number of reasons why Irish companies might be more aware of internal security issues than other companies; part of it is the fact that regulatory requirements have become more important in recent years," said Mike Harris, manager of Ernst & Young's technology security risk service, speaking to ElectricNews.net. "Also, a lot of the companies surveyed would be subsidiaries of international companies, which makes them more aware of these issues than would be the case in other countries." The link for this article located at Ciaran Buckley is no longer available. . A study involving 1,500 companies indicates that British businesses prioritize cybersecurity education and recognize emerging technological risks.. Irish Business Security, Employee Awareness, Ernst & Young Survey. . LinuxSecurity.com Team

Calendar%202 Sep 23, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200