Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
212

Exploit Risks of Misconfigured Azure Services in EmojiDeploy Attack Chain

Multiple misconfigurations in a service that underpins many Azure features could have allowed an attacker to remotely compromise a cloud user's system. . An attack chain exploiting misconfigurations and weak security controls in a common Azure service is highlighting how lack of visibility impacts the security of cloud platforms. The "EmojiDeploy" attack chain could allow a threat actor to run arbitrary code with the permission of the Web server, steal or delete sensitive data, and compromise a targeted application, Ermetic stated in its Jan. 19 advisory . An attacker could use a trio of security issues affecting the common Source Code Management (SCM) service — a cloud service used by many Azure applications without an explicit indication to the user, according to Ermetic. The issues demonstrate that the security of cloud platforms are undermined by the lack of visibility into what those platforms do under the hood, says Igal Gofman, head of research for Ermetic. The link for this article located at DarkReading is no longer available. . A vulnerability pathway leveraging insufficient configurations and lax defenses in a widely used Azure platform could present significant threats.. AzureService, CloudSecurity, MisconfigurationRisk, AttackChain. . Brittany Day

Calendar 2 Jan 26, 2023 User Avatar Brittany Day Cloud Security
83

Webcam Security Risks: Minor Bugs Create Major Cyber Threats

More insecure webcams! Inattention to IoT security! Who would have thought?. Unfortunately, cybersecurity still seems to sit way down in Nth place for many vendors when they start programming their latest and greatest Internet of Things (IoT) devices. In this case, the bugs are in a family of webcams – and not just any old webcams, but security webcams. The link for this article located at Naked Security/Sophos is no longer available. . The security of IoT gadgets frequently gets neglected, resulting in substantial risks stemming from trivial flaws in smart speakers and beyond.. IoT Devices, Webcam Security, Cyber Threats, Exploit Risks. . LinuxSecurity.com Team

Calendar 2 Jun 13, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Ubuntu: Unpatched Unix Flaw Exposes Risk After Official Fix

A security flaw in a common Unix software component remains unpatched in one of the most popular Linux distributions, more than a year after an official fix was published.. . An oversight in a Unix software module stays unresolved in widely-used Ubuntu, putting systems at potential hazards.. Unix Flaw, Ubuntu Security, OS Threats, Risk Exposure, Security Issues. . LinuxSecurity.com Team

Calendar 2 May 01, 2015 User Avatar LinuxSecurity.com Team Vendors/Products
83

Internet Explorer Heap Overflow Advisory: Serious Code Execution Threat

US-CERT on Wednesday warned of a fresh hole in Internet Explorer that could allow attackers to take control of a PC via an HTML e-mail message or a malicious Web page. The flaw is all the more serious because exploit code has been published on public mailing lists, according to security researchers. . . .. US-CERT on Wednesday warned of a fresh hole in Internet Explorer that could allow attackers to take control of a PC via an HTML e-mail message or a malicious Web page. The flaw is all the more serious because exploit code has been published on public mailing lists, according to security researchers. The flaw, a heap buffer overflow, is in the way IE handles two attributes of the "frame" and "iframe" HTML elements. An exploit currently circulating uses overly long SRC and NAME attributes to cause IE to execute an attacker's shell code, according to US-CERT. Users could be attacked via a malicious Web page viewed in an affected version of IE or possibly through an HTML e-mail viewed in an application such as Outlook, Outlook Express, AOL or Lotus Notes that relies on the WebBrowser ActiveX control, according to researchers. The bug has been confirmed in IE 6.0 on Windows XP with SP1 and all patches installed, as well as the same browser on a fully patched Windows 2000, according to an advisory from security firm Secunia. Microsoft Corp. has not yet released a patch. The link for this article located at eweek.com is no longer available. . US-CERT on Wednesday warned of a fresh hole in Internet Explorer that could allow attackers to take . us-cert, wednesday, warned, fresh, internet, explorer, allow, attackers. . LinuxSecurity.com Team

Calendar 2 Nov 05, 2004 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

RealNetworks: Media Players Security Flaws Affecting Exploit Risk

EEye Digital Security has uncovered new security holes affecting a wide range of RealNetworks' media players, the latest desktop-based bugs set to worry IT managers. The flaws could be exploited via a malicious webpage or a RealMedia file run from a local drive to take over a user's system or delete files, according to RealNetworks. . . .. EEye Digital Security has uncovered new security holes affecting a wide range of RealNetworks' media players, the latest desktop-based bugs set to worry IT managers. The flaws could be exploited via a malicious webpage or a RealMedia file run from a local drive to take over a user's system or delete files, according to RealNetworks. Researchers have turned up a myriad of serious security flaws in client software over the past few weeks, and such bugs can be difficult to patch because of the sheer number of desktops in use. Recently vulnerabilities have been revealed in WinAmp, WinZip, and Apple Computer's iChat messaging program. The link for this article located at Matthew Broersma is no longer available. The link for this article located at Matthew Broersma is no longer available. The link for this article located at Matthew Broersma is no longer available. The link for this article located at Matthew Broersma is no longer available. . Uncover significant vulnerabilities in RealNetworks media applications that may allow unauthorized access or data loss.. RealNetworks Media Players, Security Risks, Media Player Flaws. . LinuxSecurity.com Team

Calendar 2 Oct 04, 2004 User Avatar LinuxSecurity.com Team Server Security
78

Microsoft: Internet Explorer 5 Exploit Risk From Source Code Leak

We have not covered much about the Microsoft source code leak that has been inundating the computer security news-sites recently, mostly because its not very relevant to open-source security. However, an exploit has been found due to the leak already. This brings up one of the major bonuses of open-source code: it does not at all depend on obscurity. Defense-by-obscurity leads to sloppy coding habits and opens the door to massive security vulnerabilities should the code be leaked, especially if its no longer supported, but still widely used, like Windows 9x. Bear in mind that, according to the Microsoft EULA, no one else is technically allowed to patch the code, and Microsoft likely won't . They might even claim that the ruling against them on the Java VM issue with Sun means that they cannot, since that was the reason given for dropping support for legacy products in the first place. . . .. A security company on Monday alerted clients of a new vulnerability to Internet Explorer 5, one attributed to the recent leak of Microsoft Corp. Windows source code. Microsoft confirmed the problem late in the day. A security company on Monday alerted clients of a new vulnerability to Internet Explorer 5, one attributed to the recent leak of Microsoft Corp. Windows source code. The quick attack appears to contradict some optimistic expectations that the recent leak of Windows 2000 and NT code would not pose a significant opportunity for hackers. In a statement released late on Monday, the company said it was investigating the reported exploit, but added that "This exploit is a known issue that Microsoft had discovered internally and addressed with the latest release of Internet Explorer--Internet Explorer 6.0 Service Pack 1." According to a message posted by SecurityGlobal.net LLC's Security Tracker Web site, a vulnerability was reported in Microsoft Internet Explorer Version 5 that lets a "remote user execute arbitrary code on the target system." A hacked bitmap file can trigger an integer overflow and executearbitrary code, the security bulletin said. The author of the warning said that this flaw was uncovered by reviewing the recently leaked Windows source code. The link for this article located at eweek.com is no longer available. . An issue found in Explorer 5 discloses risks stemming from exposed Microsoft code, underscoring lingering security gaps.. Internet Explorer Exploit, Microsoft Source Code Leak, Legacy Software Security. . LinuxSecurity.com Team

Calendar 2 Feb 17, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
83

Sendmail And Snort Exploit Risks Reported: IT Threats Identified

Vulnerabilities have been uncovered in Sendmail and the Snort open source intrusion detection system IT departments suffered two serious vulnerabilities in enterprise-grade open source software systems last week. Top of the list was a newly reported vulnerability in Sendmail, which is a widely used mail transport agent (MTA). The second vulnerability was found in Snort, a popular open-source intrusion detection system (IDS). . . .. Vulnerabilities have been uncovered in Sendmail and the Snort open source intrusion detection system IT departments suffered two serious vulnerabilities in enterprise-grade open source software systems last week. Top of the list was a newly reported vulnerability in Sendmail, which is a widely used mail transport agent (MTA). The second vulnerability was found in Snort, a popular open-source intrusion detection system (IDS). Last week showed how quickly news of vulnerabilities can be exploited to produce software that wreaks havoc on the Net. Within 24 hours of the problems being made public, an easy-to-use exploit program for the Sendmail vulnerability was posted on the Bugtraq mailing list. According to Bugtraq, default installations of Sendmail and Red Hat Linux are not vulnerable to this particular exploit, but firms that have compiled Sendmail for use with Red Hat 7.1, 72 or 7.3 are vulnerable. The link for this article located at vnunet is no longer available. . Vulnerabilities have been uncovered in Sendmail and the Snort open source intrusion detection system. vulnerabilities, uncovered, sendmail, snort, source, intrusion, detection, system. . LinuxSecurity.com Team

Calendar 2 Mar 11, 2003 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Exploring Site Seal Misleading Facts And Real-World Security Threats

Secure site seals handed out to sites by certificate authorities and lock icons shown by browsers can often mislead consumers into believing that a site is more secure than it actually is, according to the latest Netcraft Web Server Survey.. . .. Secure site seals handed out to sites by certificate authorities and lock icons shown by browsers can often mislead consumers into believing that a site is more secure than it actually is, according to the latest Netcraft Web Server Survey. The survey said a recent dialogue between the two leading certificate authorities - Verisign and Geotrust has highlighted the fact that though the site seal and browser lock may look reassuring, there was no assurance at all that the site is not vulnerable to some well known exploit, and typically many are. It said the discovery of remote vulnerabilities in Microsoft Commerce Server and Microsoft-IIS published last month, had left many commerce and financial sites open to attack, and there was often no clear cut way in which a site's prospective customers can legally determine whether their transactions and data were likely to be safe or not. Due to these factors, Netcraft said it was likely that payment mechanisms on the Internet would increasingly become centralised. The survey also showed that IIS has made a gain of three percent in number of sites hosted on the Net due to the fact that register.com putting a Windows-based front end back in place on their domain parking system. It said register.com had alternated recently between a Windows and Linux front end, and this caused a fluctuation when it changed. All of article. . In today's digital landscape, website security is vital, yet consumers often misinterpret site seals as definitive proof of safety, which can be misleading and risky. Secure Site Seals, Consumer Protection, Exploit Risks, Web Security Standards. . LinuxSecurity.com Team

Calendar 2 Jul 29, 2002 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here