Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
83

USB Attack Code Heightens Security Risks And Exploit Potential

Rarely in security is anything an absolute, but in the case of the BadUSB research that emerged during this year. Over the weekend, the situation may have gotten a bit more desperate with the release of code by two independent security researchers that replicates some of what Karsten Nohl and Jakob Lell of SR Labs in Germany demonstrated this summer during the desert hacker fest. The link for this article located at ThreatPost is no longer available. . Escalating worries about USB vulnerabilities emerge as newly unveiled attack scripts by experts heighten the likelihood of threats and breaches.. USB Exploits, Malware Analysis, Security Threats. . LinuxSecurity.com Team

Calendar%202 Oct 06, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

LEET '11: Botnet Operations Insights From Brett Stone-Gross

A presentation at this week's LEET '11, a USENIX workshop on large-scale exploit and emergent threats, delves into the inner workings of the underground economy, specifically the rental and operation of spam botnets.. Brett Stone-Gross, a PhD student at the University of California, Santa Barbara, gave an overview of recently completed research he conducted with fellow researchers Thorsten Holz, Gianluca Stringhini and Giovanni Vigna. In August 2010, the team worked with contacts at various Internet Service Providers and were able to gain access to 13 Command & Control servers and three development servers used by botnet operators of the Cutwail spam engine, a botnet that has been around since 2007 and at one time was estimated to be the largest botnet in existence with the most infected hosts. Cutwail is also often referred to as Pushdo because of a separate Trojan component that installs the software. The link for this article located at Network World is no longer available. . Brett Stone-Gross, a PhD student at the University of California, Santa Barbara, gave an overview of. presentation, week's, usenix, workshop, large-scale, exploit, emergent, threat. . Alex

Calendar%202 Mar 30, 2011 User Avatar Alex Network Security
79

Local Privilege Escalation in Mac OS X Tiger Exploited by Researcher

Before his coffee was cold he had found a local privilege escalation vulnerability in Mac OS X Tiger, which could allow people to elevate from normal user to full super user, and had written code that could exploit the hole.. "I just think that I got lucky, but that's what I always think when I find a bug that quickly," he said in an interview on Wednesday. Dai Zovi has been exploiting Macs for a long time, publishing his first Mac OS X shellcode (code used as the payload in an exploitation of a vulnerability) for the PowerPC in July 2001. He said he has reported more than 10 vulnerabilities to Apple over the years and does so out of love for the platform. The link for this article located at CNET is no longer available. . Investigate a regional privilege escalation flaw within Mac OS X and understand how analysts take advantage of weaknesses to enhance security.. Local Escalation, Exploit Research, Security Flaws, Mac OS Techniques. . LinuxSecurity.com Team

Calendar%202 Aug 27, 2009 User Avatar LinuxSecurity.com Team Security Projects
76

Key Takeaways From Black Hat USA 2005: Database Security Insights

Rootkits. Zero-day exploits. Social engineering. Encryption cracking. Cryptography. File format fuzzing. Kernel exploitation. These are just some of the buzzwords making the rounds at the Black Hat USA 2005 security conference here, where some of the sharpest minds in the research community will congregate to share information on computer and Internet security threats. . The powwow, organized by Black Hat Inc., promises 60 new security research presentations, 13 hacking tools, 15 new exploits, the first-ever example of exploit shellcode in Cisco IOS, and numerous debates on privacy, defense mechanisms and industry trends. When the briefings start on Wednesday, all eyes—and ears—will be on David Litchfield's presentation on new zero-day vulnerabilities. Litchfield, a founder of Next Generation Security Software Ltd., is best known for his work on finding gaping security holes in Oracle Corp. database products, and his discussion is expected to shine the spotlight on a new range of unpatched vulnerabilities in several Internet-facing applications. At last year's Black Hat, it was Litchfield who blew the lid off Oracle's tardiness in patching highly critical Oracle database flaws. His research work prompted widespread criticism of Oracle's response to known vulnerabilities and forced the company to implement a quarterly patching schedule. The link for this article located at eWeek is no longer available. . The powwow, organized by Black Hat Inc., promises 60 new security research presentations, 13 hacking. rootkits, zero-day, exploits, social, engineering, encryption, cracking, cryptography, format. . Brittany Day

Calendar%202 Jul 27, 2005 User Avatar Brittany Day Organizations/Events
83

Identifying the Gap Between Security Holes and Exploited Threats

Experts who discover and report security holes seem to be far more industrious than the malicious hackers willing or able to exploit those holes. Despite the thousands of hackable holes that lurk in e-mail, on websites, in files and operating . . . . Experts who discover and report security holes seem to be far more industrious than the malicious hackers willing or able to exploit those holes. Despite the thousands of hackable holes that lurk in e-mail, on websites, in files and operating systems, most users' computers are never afflicted with more than the virtual version of a sniffle. Few of the ominous potential traumas reported in 2002 turned out to have any real impact on most computer users. The Klez virus infected some machines and spawned spam that continues to clutter many e-mail inboxes. And the Linux Slapper worm made more work for some systems administrators for a while. "I'd love to see people in the industry turn their attention to developing broad-reaching security tools that make a real difference rather than focusing on finding each and every little possible exploit," security consultant Richard Smith said. The link for this article located at Wired.com is no longer available. . Cybersecurity analysts identify weaknesses more swiftly than cybercriminals can leverage them, highlighting an ongoing security divide.. System Vulnerabilities, Security Holes, Cyber Threats, Digital Exploits, Security Tools. . LinuxSecurity.com Team

Calendar%202 Dec 30, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200