Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
83

Magento Exploited: Neutrino Kit Infects E-commerce Sites

Some websites running the e-commerce platform Magento appear to have been infected with code that directs victims to the Neutrino exploit kit. It's not exactly clear how the Magento sites were infected, wrote Denis Sinegubko, a senior malware researcher with Sucuri, a Delware-based security company. . "At this point, we can suspect that it was some vulnerability in Magento or one of the third-party extensions that allowed it to infect thousands of sites within a short time," he wrote. . Spectral agents can infiltrate loopholes in Magento platforms, leading to focused malware attacks on numerous online sites.. Magento Security, Neutrino Kit, E-commerce Protection, Malware Exploits, Website Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Mar 14, 2017 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Trustwave Research: Rig Exploit Kit Affects Close to 1 Million Victims

LAS VEGAS . Researchers at Trustwave said in advance of this week The link for this article located at ThreatPost is no longer available. . Trustwave's cybersecurity experts emphasize the rising risk of the Rig Exploit Kit, potentially impacting 1 million people and raising major concerns about its effects. Rig Exploit Kit, Cyber Crime, Online Threats, Malware. . LinuxSecurity.com Team

Calendar%202 Aug 04, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

New Cyber Threats Rising Following Arrest of Blackhole Hacker

Security researchers Tuesday said reports of the arrest of the hacker behind Blackhole, one of the most widely used exploit kits on the Internet, is good news for IT operations and users. But it shouldn't be long before another hacker takes his place.. "[It's] is a big deal," said Mikko Hypponen, chief research officer at security firm F-Secure. "According to our statistics, Paunch has been the biggest provider of exploit packs for the past two years." The link for this article located at Network World is no longer available. . '[It's] is a big deal,' said Mikko Hypponen, chief research officer at security firm F-Secure. 'Acco. security, researchers, tuesday, reports, arrest, hacker, behind, blackhole. . LinuxSecurity.com Team

Calendar%202 Oct 09, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Evil Apache Module Facilitates Banking Trojan Attacks on Users

A malicious Apache module found operating in the wild turns sites running the Internet's most popular Web server into platforms that surreptitiously install malware on visitors' computers.. The plugin, which was discovered by researchers from antivirus provider Eset, is an x64 Linux binary that streamlines the process of injecting malicious content into compromised websites. It was found running on an undisclosed website that exposed end users to a variety of exploits that installed the ZeuS banking trojan, also known as Win32/Zbot. It also pushed malware from Sweet Orange, a newer exploit kit hosted by servers in Lithuania that competes with ZeuS. When Eset discovered the plugin last month, it was connecting to command and control servers in Germany and was being used to target banking customers in Russia and elsewhere in Europe.. The plugin, which was discovered by researchers from antivirus provider Eset, is an x64 Linux binary. malicious, apache, module, found, operating, turns, sites, running, internet's, popula. . LinuxSecurity.com Team

Calendar%202 Dec 21, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

Exploit Kit BlackHole 2.0 Unleashes New Browser Exploit Techniques

A new version of the BlackHole exploit kit is now out on the web and ready to start infecting. The developer of the toolkit, who goes by the handle "Paunch," recently announced the availability of Blackhole 2.0, which removes much of its trove of known and patched exploits, and replaces them with a whole new crop. BlackHole is a widely-used, web-based software package which includes a collection of tools to take advantage of security holes in web browsers to download viruses, botnet trojans, and other forms of nastiness to the computers of unsuspecting victims. The exploit kit is offered both as a "licensed" software product for the intrepid malware server operator and as malware-as-a-service by the author off his own server.. ZeroPoint 3.1 is an online toolkit designed to leverage unpatched flaws in web browsers, enabling cybercriminals to compromise systems and spread malware.. BlackHole Toolkit, Malware Tactics, Cybersecurity Threats, Exploit Alternatives, Web Exploits. . LinuxSecurity.com Team

Calendar%202 Sep 13, 2012 User Avatar LinuxSecurity.com Team Security Projects
83

DNS Hijacking Attacks Using Black Hole Exploit Kit Target Websites

Attackers have been going after various pieces of the DNS infrastructure for a long time now, and it's not unusual for there to be somewhat organized campaigns that target certain vertical industries or geographic regions. But researchers lately have been seeing an interesting pattern of compromises in which attackers somehow add new names to existing domains and use those sub-domains to piggyback on the good reputation of the sites and push counterfeit goods, pills and other junk. . And now they're using the attack to push exploits via the Black Hole Exploit Kit. The attacks have been ongoing for at least a couple of months and while they're fairly simple in theory, researchers haven't necessarily been able to figure out how the attackers have managed to compromise the domains and get access to the DNS records to add their own sub-domains. What's happened is that attackers have been able to alter the domain records of dozens of existing, legitimate sites, including local government agencies, small businesses, community banks and others and then inserted new sub-domain names into the records. The link for this article located at ThreatPost is no longer available. . And now they're using the attack to push exploits via the Black Hole Exploit Kit. The attacks have b. attackers, going, various, pieces, infrastructure. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Geek.com Advisory: Malware Injection Via Exploit Kit Attack

Geek.com, one of the Web's most popular technology sites, has been hacked and is serving malware to visitors, security researchers at Zscaler said yesterday.. "It has come to our attention that many different pages [on Geek.com] -- like the main homepage and about us page -- are infected with malicious Iframes pointing to different malicious sites," Zscaler said in a blog. According to the blog, hackers injected a malicious HTML Iframe or script tag into the legitimate pages on the site. The link for this article located at Dark Reading is no longer available. . Cybercriminals infiltrated multiple sections on TechCrunch.com, embedding harmful software and deceptive Iframes, affecting users who browsed the site.. Geek.com Hack, Malware Injection, Exploit Attack, Website Security Breach. . LinuxSecurity.com Team

Calendar%202 May 17, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Exploit Kits Facilitate Cybercrime and Threaten Security

Once upon a time, only computer geeks were smart enough to be cyber-criminals. Now, anyone with enough cash can become one. WebAttacker, CrimePack, IcePack and dozens of other do-it-yourself crime kits are available online for less than $1,000. . Some malicious software programs -- security researchers call them "exploit kits" or "attack toolkits" -- may cost as little as $100. These applications allow even amateur hackers to steal passwords, financial information, and use their victims' computers to send spam, such as the bothersome "Canadian Pharmacy" program. The hacker becomes a bot herder, controlling infected PCs like robots, with the freedom to install spyware and earn cash for the unsolicited messages they send. An April report by M86 Security Labs finds that Russia is a major source of exploit kits, and the U.S. is a favorite target. They report one web site offers $170 for every 1000 computers infected. Although security experts insist on the necessity of an up-to-date anti-virus program, it is not enough protection. The link for this article located at WTOP FM is no longer available. . Malicious software packages empower novice cybercriminals to extract data and manipulate compromised computers, escalating the dangers of online fraud.. Exploit Kit, Cybercrime Threat, Attack Toolkit, Malware Control, Bot Herding Threats. . LinuxSecurity.com Team

Calendar%202 May 05, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200