Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
83

Ashley Madison Hack: Impact Team Publishes Compromised User Data

The group responsible for the Ashley Madison hack published the compromised records on Tuesday, delivering on the promise made when the hack was announced in July. The compromised records include account profile information, personal information, financial records, and more. . In July, a group calling themselves Impact Team leaked a selection of files that they claimed originated form Avid Life Media (ALM), the company behind adult playgrounds of Ashley Madison, Cougar Life, Established Men, and others. The link for this article located at CSO Online is no longer available. . In July, a group calling themselves Impact Team leaked a selection of files that they claimed origin. group, responsible, ashley, madison, published, compromised, records, tuesday. . LinuxSecurity.com Team

Calendar%202 Aug 19, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Bitcoin Heist: Hackers Steal $12,000 From Brokerage Account

A Bitcoin transaction services company says that hackers broke into one of its brokerage accounts last week, nabbing more than $12,000 worth of the digital currency. . That attack knocked Bitinstant offline over the weekend. The company says that while it lost Bitcoins, no customers were affected by the hack. The link for this article located at Wired is no longer available. . A cryptocurrency exchange experienced a security incident, resulting in the loss of $15,000 in Ethereum from one individual wallet.. Bitcoin Heist, Digital Currency Theft, Cybersecurity Risk. . LinuxSecurity.com Team

Calendar%202 Mar 08, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Bit9 SQL Injection: Hackers Exploit Security Flaw For Attacks

Bit9 said a common Web application vulnerability was responsible for allowing hackers to ironically use the security vendor's systems as a launch pad for attacks on other organizations. . Based in Waltham, Mass., the company sells a security platform that is designed in part to stop hackers from installing their own malicious software. In an embarrassing admission, Bit9 said earlier this month that it neglected to install its own software on a part of its network, which lead to the compromise. The link for this article located at InfoWorld is no longer available. . Based in Waltham, Mass., the company sells a security platform that is designed in part to stop hack. common, application, vulnerability, responsible, allowing, hackers, ironically. . LinuxSecurity.com Team

Calendar%202 Feb 28, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Sony PlayStation 3 Major Hack Exposes Level 0 Security Issue

A hacker group finds a secret set of codes that can decrypt the PlayStation 3's Level 0 security layer -- the holy grail of secrecy within Sony's console.. Hackers have found a way to break down one of the toughest defensive walls in Sony's PlayStation 3 software security, ensuring that those who use custom firmware can run homebrew software and pirated games forever. The link for this article located at CNET is no longer available. . Explore the methods used by hackers to crack the security of Xbox 360, jeopardizing system reliability for unauthorized applications and cloned software.. PlayStation 3 Hack, Console Exploit, Homebrew Software, Custom Firmware. . LinuxSecurity.com Team

Calendar%202 Oct 25, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Reborn LulzSec: Hack Of MilitarySingles.com Exposes 160,000 Accounts

A group of hackers claiming to be the reborn Lulz Security (LulzSec) took credit for an alleged compromise of MilitarySingles.com, a dating website for military personnel, and the leak of over 160,000 account details from its database.. The group announced the MilitarySingles.com hack on Twitter and Pastebin on Sunday, using the name "LulzSec Reborn" and ASCII art previously associated with LulzSec, the hacker group that apparently disbanded and merged with the Anonymous hacktivist collective last year. The link for this article located at PC World is no longer available. . The group known as Reborn LulzSec has taken credit for breaching MilitarySingles.com, exposing the personal information of more than 160,000 users.. MilitarySingles, Reborn LulzSec, Cyberattack, Data Breach, Account Exposure. . LinuxSecurity.com Team

Calendar%202 Mar 27, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Digital Playground Data Breach: 73000 Users Exposed in Security Incident

Hackers claim to have stolen the details of more than 73,000 subscribers to porn site Digital Playground. . The data includes user names, email addresses and passwords. Also taken were the numbers, expiry dates and security codes for 40,000 credit cards. The attack is the second successful breach of a site run by website management company Manwin. The link for this article located at BBC News is no longer available. . Cybercriminals infiltrated Media Nexus, compromising the personal information and payment details of more than 50,000 members.. Digital Playground Breach, User Data Exposure, Credit Card Security. . LinuxSecurity.com Team

Calendar%202 Mar 12, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

TLS 1.0 Weakness Exposes PayPal Cookies to BEAST Attack

Researchers have discovered a serious weakness in virtually all websites protected by the secure sockets layer protocol that allows attackers to silently decrypt data that's passing between a webserver and an end-user browser.. The vulnerability resides in versions 1.0 and earlier of TLS, or transport layer security, the successor to the secure sockets layer technology that serves as the internet's foundation of trust. Although versions 1.1 and 1.2 of TLS aren't susceptible, they remain almost entirely unsupported in browsers and websites alike, making encrypted transactions on PayPal, GMail, and just about every other website vulnerable to eavesdropping by hackers who are able to control the connection between the end user and the website he's visiting. At the Ekoparty security conference in Buenos Aires later this week, researchers Thai Duong and Juliano Rizzo plan to demonstrate proof-of-concept code called BEAST, which is short for Browser Exploit Against SSL/TLS. The stealthy piece of JavaScript works with a network sniffer to decrypt encrypted cookies a targeted website uses to grant access to restricted user accounts. The exploit works even against sites that use HSTS, or HTTP Strict Transport Security, which prevents certain pages from loading unless they're protected by SSL. The link for this article located at The Register UK is no longer available. . The vulnerability resides in versions 1.0 and earlier of TLS, or transport layer security, the succe. researchers, serious, weakness, virtually, websites, protected, secure. . LinuxSecurity.com Team

Calendar%202 Sep 21, 2011 User Avatar LinuxSecurity.com Team Cryptography
83

LulzSec Attacks PBS Website Over Controversial Documentary

Hackers aligned with WikiLeaks broke into and defaced the website of US broadcaster PBS over the weekend shortly after it had aired a less than flattering documentary about the whistle-blowing site.. LulzSec took particular offence at the portrayal of presumed WikiLeaks source Bradley Manning during of an episode of PBS's Frontline news magazine programme. In response, the hackers broke into PBS website before swiping passwords and other sensitive information. The link for this article located at The Register UK is no longer available. . LulzSec took particular offence at the portrayal of presumed WikiLeaks source Bradley Manning during. hackers, aligned, wikileaks, broke, defaced, website, broadcaster. . LinuxSecurity.com Team

Calendar%202 May 31, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200