Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
78

Intel CPU Microcode Update: Gen8 To Gen 13 Raptor Lake Security Advisory

Well, this is a bit strange... Intel just published Friday afternoon CPU microcode updates for all supported processor families back to Coffee Lake "Gen 8" for undisclosed security updates. . Earlier this week was Patch Tuesday and Intel issued a round of new security advisories for various -- mostly software -- security issues. Of this month's security advisories, there was nothing pertaining to CPU microcode explicitly nor any "Intel Processor" advisories this month. But hitting this Friday afternoon now for the Intel Linux CPU microcode repository are a new set of firmware binaries... The mentioned change is "Security updates for [INTEL-SA-NA]." The ID format is for the Intel Security Advisory (SA) and presumably NA is for "Not Available." Given it's dropping a few days past Patch Tuesday, it would appear to be for some new and not publicly disclosed issue. Concerning as well is the scope of the new CPU microcode for the security update(s) are basically all supported CPU families. From Gen8 Coffee Lake and Whiskey Lake Mobile up through the latest Xeon Scalable Gen 4, Xeon Max, and Gen 13 Raptor Lake are all updated. Plus this is the first time seeing updated CPU microcode published for Alder Lake N CPUs as well as Atom C1100 "Arizona Beach" platforms. The link for this article located at Phoronix is no longer available. . Intel's latest firmware enhancements, spanning from Generation 8 through current processors, tackle unidentified vulnerabilities; learn additional insights.. Intel CPU Microcode, Microcode Updates, Processor Security. . LinuxSecurity.com Team

Calendar%202 May 15, 2023 User Avatar LinuxSecurity.com Team Vendors/Products
79

Fwupd 1.8.6 New Hardware Support And 30% Smaller Package Size

Fwupd 1.8.6 is out as the newest stable release of this open-source firmware updating tool most notably used by Linux systems but also supported on various BSDs and even Windows. . New hardware support with Fwupd 1.8.6 includes supporting Focaltech touchpads, FPC fingerprint readers, and support for Supermicro servers running Redfish. This Supermicro support comes from Kai Michaelis with 9elements Security, sadly not from Supermicro itself, and limited in scope to updating the BIOS using the Redfish API. Fwupd 1.8.6 is also notable in that its install package size has been optimized and is now about 30% smaller than prior releases. This ~30% reduction comes via compressing some data files, building some plugins into the binary, and splitting out common code in tools. The link for this article located at Phoronix is no longer available. . Explore the latest in Fwupd 1.8.6, introducing enhanced device compatibility and achieving a 30% reduction in package size for streamlined updates.. Firmware Update, Hardware Support, Package Optimization. . LinuxSecurity.com Team

Calendar%202 Oct 10, 2022 User Avatar LinuxSecurity.com Team Security Projects
79

Exploring Coreboot Firmware Transition for End-of-Life Devices by LVFS

The Linux Vendor Firmware Service (LVFS) with Fwupd for firmware updating on Linux could soon be making it easier to transition older, end-of-life devices off official firmware packages and onto the likes of open-source Coreboot for capable aging PC hardware. This not only would make the system run on more free software but would extend the life of the hardware with firmware updates where the vendor has ceased their support. . Lead LVFS/Fwupd developer Richard Hughes of Red Hat stoked a community question , "Hypothetically, if a legal entity (like the LVFS) started distributing Coreboot firmware security updates for EOL hardware like the ThinkPad X220 (with the vendors blessing) how does that feel? You'd have to explicitly opt-in and it would be clear all OEM warranty is gone." Obviously there are some legal issues involved and such a move may not be endorsed by the hardware vendor, but the affected hardware is end-of-life after all. It is an interesting avenue since right now Coreboot can run on a lot of other Intel laptops / desktop motherboards / server motherboards but generally isn't very easy for inexperienced users to flash and transition to with usually quite involved steps for building and flashing. LVFS/Fwupd could make it much easier to switch off the proprietary firmware of your system and onto libre firmware where supported. The link for this article located at Phoronix is no longer available. . The Linux Vendor Firmware Service (LVFS) transforms open-source firmware for older devices, enabling essential updates from Coreboot to enhance longevity and performance. Firmware Updates, Open Source Solutions, LVFS Deployments, Coreboot Integration, End of Life Devices. . LinuxSecurity.com Team

Calendar%202 Jan 26, 2022 User Avatar LinuxSecurity.com Team Security Projects
209

LVFS Experiences High Activity Ahead Of Potential Security Issues

The Linux Vendor Firmware Service (LVFS) that integrates with Fwupd for delivering firmware updates primarily to Linux users is surging with around three times the normal traffic volume. Unfortunately, this boost in traffic appears to be due to vendor(s) releasing new system firmware updates ahead of disclosing a presumptive security issue. . Last summer LVFS shot up with activity and when that huge uptick in LVFS activity occurred it ended up being due to Dell BIOS/UEFI updates due to new security vulnerabilities. The sudden surge in LVFS/Fwupd activity at around three times its usual volume does seem to point to another imminent security vulnerability being disclosed around system firmware. The link for this article located at Phoronix is no longer available. . An upsurge in activity has been noted on LVFS, suggesting imminent security vulnerabilities that may necessitate forthcoming firmware patches.. LVFS Activity, Firmware Update Alerts, Linux Security Notice, Fwupd Updates. . Brittany Day

Calendar%202 Jan 19, 2022 User Avatar Brittany Day Security Trends
214

Identifying Risks From Unsupported IoT Devices in Your Network

Imagine reading a headline in tomorrow’s news stating that your neighbor’s identity was stolen and their life savings cleaned out by criminals who entered through their ‘smart’ washing machine. Sound ridiculous? Well, have you checked your own home Wi-Fi network lately? . You might have several connected household gadgets and other internet of things (IoT) devices tethered wirelessly through a misconfigured router with no firewall settings. Is the firmware current? Are security patches up to date? Still not convinced this is a serious problem? Then consider this glaring example of how dangerous an outdated device can be. . With increasing smart devices at home, unsupported IoT risks rise. They lack updates, making them vulnerable to attacks and undermining network reliability.. IoT Devices, Cybersecurity Risk, Network Protection, Firmware Updates, Security Challenges. . Brittany Day

Calendar%202 Aug 30, 2021 User Avatar Brittany Day IoT Security
83

Dangers of Wireless Routers: Enhance Your Home Network Security

You've installed antivirus software on your computers, configured your operating system to update its security automatically and password-protected your Wi-Fi. So your home network is safe against hackers, right?. Guess again. And then take a long look at your wireless router. For years, manufacturers of home routers have all but ignored security issues, at least when it comes to making sure that consumers update their firmware to close exploitable vulnerabilities. Let's put it this way: Have you ever updated the firmware on your router? If not, odds are good that it's got one or more security holes through which a properly motivated hacker could slip. The link for this article located at Read Write Hack is no longer available. . Residential networks carry inherent security risks. Understand the threats posed by Wi-Fi routers and the critical need for regular firmware upgrades.. Wireless Router Risks, Home Network Safety, Firmware Update Best Practices. . LinuxSecurity.com Team

Calendar%202 Apr 18, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

PlayStation 3 Firmware Update: Other OS Disabled Over Security Issues

Sony has announced that its latest firmware update will disable the "Other OS" option on the PS3. This means that the PS3 will no longer support the Linux OS.. The decision to drop the Other OS option ultimately comes down to security, according to Sony. Noted PS3 hacker George Hotz released an exploit last month that allowed read/write access to the PS3 through Linux and the Other OS option. Sony estimates that only a small percentage of PS3 owners use the Other OS option, but the Playstation Blog is being overrun by complaints by fans who hope this is just an April Fools prank by Sony. The post on the update at the Playstation Blog has this to say as a rebuttal. "For most of you, this won The link for this article located at The Examiner is no longer available. . Microsoft restricts Xbox 360's Linux functionality for safety reasons, impacting user options and access.. PlayStation 3,Firmware Update,Other OS Security. . LinuxSecurity.com Team

Calendar%202 Mar 30, 2010 User Avatar LinuxSecurity.com Team Vendors/Products
74

Enhance 802.11 Network Security With WPA Firmware Downloads

If you've delayed setting up a wireless network because of security concerns, help is at hand. Around the time you read this, improved security technology for all variants of 802.11 should be available as free firmware downloads from most equipment vendors. . . . . If you've delayed setting up a wireless network because of security concerns, help is at hand. Around the time you read this, improved security technology for all variants of 802.11 should be available as free firmware downloads from most equipment vendors. The new technology--known as Wi-Fi Protected Access (WPA)--replaces the existing and largely discredited Wired Equivalent Privacy (WEP) security algorithm that is part of the 802.11a, 802.11b, and 802.11g standards. WEP became an obstacle to widespread business adoption of Wi-Fi when security experts showed that hackers equipped with off-the-shelf tools could easily break it. The relatively robust WPA supports user authentication by a dedicated server on a corporate network, while being versatile enough to work well on simple home and small-office networks. The Institute of Electrical and Electronics Engineers, which develops 802.11 and other technical standards, was already working on 802.11i, a version with improved security. But that standard probably won't be implemented for a year or more, and it may require hardware upgrades. So the Wi-Fi Alliance--the trade group that certifies the interoperability of its members' products--decided to step in with interim technology that works with existing hardware. The link for this article located at PCWorld is no longer available. . If you've delayed setting up a wireless network because of security concerns, help is at hand. Aroun. you've, delayed, setting, wireless, network, because, security, concerns, aroun. . Anthony Pell

Calendar%202 Jul 03, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200