Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
67

768-Bit RSA Encryption Cracked By Researchers: Global Impact

Researchers have decomposed a 768-bit number with 232 decimal places into its two prime factors and published a paper with their results. The number is the string released as "RSA-768" under the now defunct RSA Challenge. As a result, RSA encryptions with 768-bit keys must, from now on, be considered cracked. . It took the team of researchers from Switzerland, Japan, Germany, France, the US and the Netherlands about two and a half years to perform the factorisation. The first step of the calculation, polynomial selection, required half a year on a cluster consisting of 80 PCs, while the second and considerably more labour-intensive sieving step took about two years on a cluster of several hundred computers. According to the researchers, a single Opteron processor with 2 Gbytes of RAM would have needed about 1,500 years to complete the sieving step. The link for this article located at H Security is no longer available. . It took the team of researchers from Switzerland, Japan, Germany, France, the US and the Netherlands. researchers, decomposed, 768-bit, number, decimal, places, prime, factors. . LinuxSecurity.com Team

Calendar%202 Jan 08, 2010 User Avatar LinuxSecurity.com Team Cryptography
67

RSA Algorithm Attack Analysis: Threats to DRM Software Development

Security researchers have developed a new approach to breaking the RSA algorithm that creates new problems for the development of effective rights management software. Cryptoanalysts already known the time taken to make different calculations using the same encryption key might, in theory at least, give attackers code-breaking clues in much the same way electro-magnetic leakage or power fluctuations can be used in so-called "side-channel" attacks on secure systems. The new so-called Branch Prediction Analysis (BPA) attack is a refinement on this approach that makes code breaking feasible on commodity PCs instead of expensive high-performance kit. . The link for this article located at TheRegister.co.uk is no longer available. . The link for this article located at TheRegister.co.uk is no longer available.. security, researchers, developed, approach, breaking, algorithm, creates. . LinuxSecurity.com Team

Calendar%202 Nov 27, 2006 User Avatar LinuxSecurity.com Team Cryptography
74

Understanding SSL Vulnerabilities and Their Effects on Network Security

The omnipresent SSL (Secure Socket Layer) which is supposed to offer a secure channel to transmit sensitive data across the Internet, may actually be opening up a gaping hole in your network security. This was the surprising bit of information was . . . . The omnipresent SSL (Secure Socket Layer) which is supposed to offer a secure channel to transmit sensitive data across the Internet, may actually be opening up a gaping hole in your network security. This was the surprising bit of information was delivered to the attending bankers on the second day of bank.net event here in Mumbai by Udi Segall, Marketing Product Manager Radwell. According to Segall, SSL does two things - one it authenticates the identity of the server, and optionally the client as well. And second, it creates a secure tunnel between the client and the server. The problem here is that once a secure link is created, it is assumed that the client connecting to the server is genuine (because he has been able to successfully login). Since the SSL traffic is encrypted, it cannot be analyzed by IDS and IPS (Intrusion Detection Systems and Intrusion Prevention System) system. The link for this article located at CXO Today is no longer available. . TLS may not offer the protection it once did, possibly revealing weaknesses in digital communications. Stay informed about the dangers!. SSL Security Risks, Network Encryption, Intrusion Detection. . Anthony Pell

Calendar%202 Nov 24, 2003 User Avatar Anthony Pell Network Security
74

Effective Solutions For Wireless Network Security Issues

Security managers need to be aware of the inherent weaknesses in wireless technology, which although similar to those in wired networking, add a few more headaches. According to security professionals, the IEEE wireless protocol 802.11 not only shares unlicensed frequencies with . . . . Security managers need to be aware of the inherent weaknesses in wireless technology, which although similar to those in wired networking, add a few more headaches. According to security professionals, the IEEE wireless protocol 802.11 not only shares unlicensed frequencies with other devices, including consumer-based Bluetooth devices, cordless phones, and baby monitors - which can, and do, interfere with each other - it also has weaknesses in its encryption structure. The link for this article located at VNUNET.com is no longer available. . Network administrators should acknowledge the fundamental vulnerabilities of mobile systems to safeguard against cyber intrusions successfully.. Wireless Security, Threat Mitigation, Encryption Solutions, Network Management. . Anthony Pell

Calendar%202 Jul 22, 2001 User Avatar Anthony Pell Network Security
67

OpenPGP Attack Insights and Vulnerability Analysis by Czech Researchers

The Czech group which recently found vulnerabilities in OpenPGP has released two documents outlining the attack. . .. The Czech group which recently found vulnerabilities in OpenPGP has released two documents outlining the attack : A PowerPoint presentation A PDF outlining the vulnerablity and the attack Both are a good read. I highly recommend them. . The Czech group which recently found vulnerabilities in OpenPGP has released two documents outlining. czech, group, which, recently, found, vulnerabilities, openpgp, released, documents, outlining. . LinuxSecurity.com Team

Calendar%202 Mar 22, 2001 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200