Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 18 articles for you...
82

CentOS Control Web Panel Critical Issue: Patch Required by February 7

The US government’s cybersecurity agency CISA is giving federal agencies an early February deadline to patch a critical -- and already exploited -- security vulnerability in the widely used CentOS Control Web Panel utility. . The agency added the CVE-2022-44877 flaw to its KEV (Known Exploited Vulnerabilities) catalog and set a February 7th deadline for federal agencies to test and deploy an available fix. Security researchers warned earlier this month that the publication of proof-of-concept code and a YouTube video demonstration would lead to live attacks. Soon after, threat-hunting outfits GreyNoise and Shadowserver spotted signs of exploitation in the wild. . CISA includes a critical vulnerability in CentOS Control Web Panel on its urgent patch list, requiring federal entities to rectify exploitation risks by February 7.. CentOS Patch, Control Web Panel Flaw, Cybersecurity Updates. . Brittany Day

Calendar%202 Jan 19, 2023 User Avatar Brittany Day Government
76

White House Summit: Addressing Log4j Security Issues With Tech Giants

Tech giants and federal agencies meet at the White House to discuss open-source software security, a response to the widespread Log4j vulnerability that’s worrying industry and cyber leaders. . Among the attendees are companies like Apple, Facebook and Google, as well as the Apache Software Foundation, which builds Log4j , a ubiquitous open-source logging framework for websites. “Building on the Log4j incident, the objective of this meeting is to facilitate an important discussion to improve the security of open source software — and to brainstorm how new collaboration could rapidly drive improvements,” a senior administration official said in advance of the meeting. . Top executives convene at the Pentagon to tackle the urgent privacy risks triggered by the new software vulnerabilities.. Open Source Security, Log4j Vulnerability, Tech Summit, Software Collaboration, Cybersecurity Initiatives. . Brittany Day

Calendar%202 Jan 14, 2022 User Avatar Brittany Day Organizations/Events
82

US Government Cybersecurity Struggles Amid White House Role Reductions

Amid a report today that the Trump White House plans to cut the administration's cybersecurity coordinator position altogether, new data shows how US federal government agencies continue to struggle to close security holes in their software.. Politico reported that the administration has eliminated the White House cybersecurity position, which was recently vacated by former head Rob Joyce, who has returned to the National Security Agency. Politico said it had obtained an email to the White House National Security Council staff from John Bolton aide Christine Samuelian: "The role of cyber coordinator will end," in an effort to "streamline authority" in the NSC, which includes two senior cybersecurity directors, she said in the email, according to Politico. The link for this article located at DarkReading is no longer available. . Politico reported that the administration has eliminated the White House cybersecurity position, whi. report, today, trump, white, house, plans, administration's, cybersecurity, coord. . Brittany Day

Calendar%202 May 16, 2018 User Avatar Brittany Day Government
82

CISA Data Sharing Act: Risks to User Privacy in Cybersecurity

A controversial draft law, which one senator called a "surveillance bill by another name," has passed the Senate. CISA, the Cybersecurity Information Sharing Act (S. 754), will allow private companies to share cyber-threat data with the federal government, including personal user data, in an effort to prevent cyberattacks, such as those on the scale of Target, Home Depot, and Sony. . Companies that share data with federal agencies, including the National Security Agency (NSA), will be given legal and liability protections from lawsuits relating to data sharing. . Companies that share data with federal agencies, including the National Security Agency (NSA), will . controversial, draft, which, senator, called, 'surveillance, another, passe. . Alex

Calendar%202 Mar 14, 2017 User Avatar Alex Government
76

Defcon 2023 Calls For Federal Agencies To Sit Out Due To Privacy Concerns

Since its founding in 1992, Defcon has been a venue where anarchists, geeks, and employees of three-letter federal agencies became unlikely comrades under a live-and-let-live credo that placed the love of computer tinkering above almost everything else. . No more. As tensions mount over the broad and indiscriminate spying of Americans and foreigners by the National Security Agency, Defcon organizers are asking feds to sit out this year's hacker conference. "For over two decades DEF CON has been an open nexus of hacker culture, a place where seasoned pros, hackers, academics, and feds can meet, share ideas and party on neutral territory," Jeff Moss, aka The Dark Tangent, wrote in a blog post published Wednesday night. "Our community operates in the spirit of openness, verified trust, and mutual respect.". In light of increasing concerns regarding civil liberties and monitoring, Defcon's planning committee urges federal law enforcement to refrain from attending this year's convention.. Defcon Conference, Hacker Culture, Federal Agencies. . Dave Wreski

Calendar%202 Jul 11, 2013 User Avatar Dave Wreski Organizations/Events
77

Study Reveals DNS Security Failures in U.S. Federal Websites

Half of U.S. government Web sites are vulnerable to commonplace DNS attacks because they haven't deployed a new authentication mechanism that was mandated in 2008, a new study shows.. The Office of Management and Budget (OMB) issued a mandate requiring federal agencies to deploy an extra layer of security The link for this article located at Network World is no longer available. . National bodies struggle with DNS protection as legacy verification techniques prevail, heightening vulnerability to cyber threats.. DNS Security, Federal Agencies, Cyber Attacks, Outdated Security, Website Security. . LinuxSecurity.com Team

Calendar%202 Jan 27, 2011 User Avatar LinuxSecurity.com Team Server Security
82

Federal Agencies Boost DNS Security Amid Implementation Challenges

In 2008, the Office of Management and Budget directed federal agencies to improve their domain name server (DNS) security by implementing DNS security extensions (DNSSEC), but 15 months later, many are still struggling to get there. The good news is that since OMB's December 2009 deadline passed, agencies are starting to catch up, taking advantage of both products and services coming on the market to make it easier to apply DNSSEC.. Agencies were "caught with their guard down because they were unprepared to deal with it," said Branko Miskov, director of product management at DNS appliance maker BlueCat Networks, which is working with several agencies on DNSSEC deployments. "We've made pretty good progress, especially from December until now," said Derek McUmber, chief executive officer of Data Mountain Solutions Inc., a subcontractor to the General Services Administration, which supports agencies in implementing DNSSEC. About a third of federal agencies now have digitally signed their dot.gov sub-domains, he said, up from only 20% six months ago. The link for this article located at Search Security is no longer available. . Government bodies are enhancing internet safety through DNSSEC deployment following early challenges resulting from insufficient readiness.. DNS Security,DNS Implementation,Federal Agencies,Network Protection. . Anthony Pell

Calendar%202 Jun 01, 2010 User Avatar Anthony Pell Government
67

Swift Data Protection Leveraging Itanium Framework for Government Entities

Linux kernel maintainer Linus Torvalds has charged that Itanium designers "threw out all the good parts of the x86." One emerging niche for Itanium, though, seems to be high-speed encryption and decryption. For instance, encryption and key management provider Eruces Inc. of Lenexa, Kan., is bullish on Itanium. Eruces devotes a large chunk of its business to federal intelligence agencies. The company's symmetric key management system encrypts documents, programs and databases, using a centralized KeyServer to generate and manage keys. . The link for this article located at GCN is no longer available. . The link for this article located at GCN is no longer available.. linux, kernel, maintainer, linus, torvalds, charged, itanium, designers, 'threw. . LinuxSecurity.com Team

Calendar%202 Sep 12, 2006 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200