Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
81

Google G Suite Password Issue: Unhashed Passwords Stored For 14 Years

Google revealed that it recently discovered a bug that caused a subset of its enterprise G Suite customers to have their passwords stored in an unhashed — albeit encrypted — form for about 14 years. . “This is a G Suite issue users only — no free consumer Google accounts were affected — and we are working with enterprise administrators to ensure that their users reset their passwords,” Google said in a blog post disclosing the security lapse. The company failed to specify exactly how many customers were affected this way. However, it went on to stress that it didn’t find any evidence of improper access. The link for this article located at The Next Web is no longer available. . “This is a G Suite issue users only — no free consumer Google accounts were affected — and we . google, revealed, recently, caused, subset, enterprise, suite. . LinuxSecurity.com Team

Calendar%202 May 22, 2019 User Avatar LinuxSecurity.com Team Privacy
83

Sony Data Breach: Security Advisory On Insufficient Credit Card Encryption

Sony Co., in a blog post Thursday, announced that every single important record from the breached credit card database last week was encrypted. But, security experts say it was not enough to fully protect the Sony PlayStation users and that consumer data might still be used by the hackers.. On Friday, reports had been released saying the hackers may have obtained the consumer. On Friday, reports had been released saying the hackers may have obtained the consumer. thursday, announced, every, single, important, record, breached. . LinuxSecurity.com Team

Calendar%202 May 02, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Hackers Exploit Internet Design Flaw: Major Web Encryption Violation

A long-known but little-discussed vulnerability in the modern Internet's design was highlighted yesterday by a report that hackers traced to Iran spoofed the encryption procedures used to secure connections to Google, Yahoo, Microsoft, and other major Web sites.. This design, pioneered by Netscape in the early and mid-1990s, allows the creation of encrypted channels to Web sites, an important security feature typically identified by a closed lock icon in a browser. The system relies on third parties to issue so-called certificates that prove that a Web site is legitimate when making an "https://" connection. The problem, however, is that the list of certificate issuers has ballooned over the years to approximately 650 organizations, which may not always follow the strictest security procedures. And each one has a copy of the Web's master keys. The link for this article located at CNET is no longer available. . An investigation uncovers that cybercriminals capitalized on a longstanding vulnerability in internet security protocols, endangering numerous prominent platforms.. encryption flaws, web security issues, cyber threats. . LinuxSecurity.com Team

Calendar%202 Mar 24, 2011 User Avatar LinuxSecurity.com Team Cryptography
67

ASP.Net Cryptographic Flaws Impacting Online Banking Security

Flaws in the way web applications handle encrypted session cookies might leave online banking accounts open to attack. The security risk stems from a cryptographic weakness in web applications developed using Microsoft's ASP.Net framework. . ASP.Net uses the US government-approved AES encryption algorithm to secure the cookies generated by applications during online banking sessions and the like. However implementation flaws in how ASP.NET handles errors when the encrypted data in a cookie has been modified give clues to a potential attacker that would allow him to narrow down the possible range of the keys used in an online banking session. Attacks based on this weakness might allow a hacker to decrypt sniffed cookies or forge authentications tickets, among other attacks. The link for this article located at The Register UK is no longer available. . Weaknesses in ASP.Net’s management of encrypted cookies could potentially put online banking at risk of cyber threats.. AES Encryption, Online Banking Threats, Application Security, Cybersecurity Risks, Cryptographic Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Sep 14, 2010 User Avatar LinuxSecurity.com Team Cryptography
81

PGP Vulnerability Alert: Potential for Unauthorized Email Decryption

Snoopers on the Internet could decode sensitive e-mail messages simply by tricking recipients into hitting the reply button, computer security researchers warned Monday. The flaw affects software using Pretty Good Privacy, the most popular tool for scrambling. . .. Snoopers on the Internet could decode sensitive e-mail messages simply by tricking recipients into hitting the reply button, computer security researchers warned Monday. The flaw affects software using Pretty Good Privacy, the most popular tool for scrambling e-mail. Researchers at Columbia University and Counterpane Internet Security Inc. found that someone intercepting an encrypted message could descramble it by repackaging the message and passing it on to the recipient. The message would appear as gibberish, possibly prompting the recipient to request a resend. The link for this article located at DigitalMass is no longer available. . Snoopers on the Internet could decode sensitive e-mail messages simply by tricking recipients into h. snoopers, internet, decode, sensitive, e-mail, messages, simply, tricking, recipients. . LinuxSecurity.com Team

Calendar%202 Aug 12, 2002 User Avatar LinuxSecurity.com Team Privacy
74

Critical Flaws In IEEE 802.11 Wireless Standard And Encryption Threats

A cryptologist who discovered several gaping holes in the international standard governing the design of wireless network devices and the encryption algorithm meant to protect those networks last week detailed vulnerabilities that could be leaving corporate systems open to hackers.. . .. A cryptologist who discovered several gaping holes in the international standard governing the design of wireless network devices and the encryption algorithm meant to protect those networks last week detailed vulnerabilities that could be leaving corporate systems open to hackers. Ian Goldberg, a cryptologist at Montreal-based security and privacy software developer Zero-Knowledge Systems Inc., along with researchers at the University of California, Berkeley, uncovered flaws in the IEEE 802.11 standard. Goldberg published a paper () on the findings earlier this year and made one of his first public appearances about it at the annual Black Hat hacker conference here. The link for this article located at Computer World is no longer available. . A cryptologist who discovered several gaping holes in the international standard governing the desig. cryptologist, gaping, holes, international, standard, governing, desig. . Anthony Pell

Calendar%202 Jul 16, 2001 User Avatar Anthony Pell Network Security
67

Major Security Flaw In PGP Email Encryption Exposes User Data Risk

A GERMAN RESEARCHER has discovered a major security flaw in the latest versions of the PGP free e-mail encryption software that could allow someone to read another person's encrypted e-mail if he or she was able to intercept it. . . .. A GERMAN RESEARCHER has discovered a major security flaw in the latest versions of the PGP free e-mail encryption software that could allow someone to read another person's encrypted e-mail if he or she was able to intercept it. The flaw, discovered by Ralf Senderek and reported Thursday, highlights the technical difficulties in creating key-recovery systems, said Bruce Schneier, CTO of Counterpane Internet Security and author of Applied Cryptography. Schneier, and a group of other cryptographers predicted the exact type of problem that PGP now faces in a paper they wrote in 1997, when the U.S. government was pushing for key escrow, raising the ire of civil libertarians and many software firms in the process. The link for this article located at InfoWorld is no longer available. . A significant vulnerability has been revealed in the newest PGP email encryption application, exposing users to potential threats.. PGP Encryption, Email Security, Encryption Flaw. . LinuxSecurity.com Team

Calendar%202 Aug 25, 2000 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200