Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 18 articles for you...
83

LightBasin's Cyber Espionage: Targeting Linux Servers in Telecoms

The stealthy LightBasin hacking group (also known as UNC1945) is infiltrating telecommunications companies around the world in a campaign that researchers have linked to intelligence gathering and cyber espionage. LightBasin's primary focus is on Linux and Solaris servers that are critical for running telecommunications infrastructure – and are likely to have less security measures in place than Windows systems. . The campaign, which has been active since at least 2016, has been detailed by cybersecurity researchers at CrowdStrike , who've attributed the activity to a group they call LightBasin – also known as UNC1945. It's believed that, since 2019, the offensive hacking group has compromised at least 13 telecommunication companies with the aim of stealing information about mobile communications infrastructure, including subscriber information and call metadata – and in some cases, direct information about what data smartphone users are sending and receiving via their devices. . Cunning cybercriminals exploit vulnerabilities in Unix systems used in finance, siphoning critical data since 2017. Discover the details today.. LightBasin Hackers,Cyber Espionage Techniques,Linux Threats,Telecommunications Security. . LinuxSecurity.com Team

Calendar%202 Oct 22, 2021 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

US Indictment Of Two Individuals In Anthem Data Breach Case

The US thinks it knows who’s behind the vast breach that siphoned off 78.8 million customer and employee records from US health insurer Anthem between 2014 and 2015. . On Thursday, the Justice Department unsealed an indictment against two people who prosecutors say are part of a sophisticated hacking group, based in China, that was behind not just the Anthem attack, but also attacks against three other US businesses. The DOJ didn’t name the other businesses but did say they were data-rich. One was a technology business, one was in basic materials, and the third was in communications: all businesses that have to store and use large amounts of data – some of it confidential business information – on their networks and in their data warehouses. The link for this article located at NakedSecurity is no longer available. . The Attorney General announced a formal charge against a pair of suspects associated with the significant Anthem health information leak that occurred in 2014-2015.. Anthem Data Breach,Hacking Group,Healthcare Cybersecurity,Data Security Incident. . LinuxSecurity.com Team

Calendar%202 May 13, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Turla Group's Custom Backdoor Threats to Microsoft Exchange Servers

A well-known Russian nation-state hacking group has been infiltrating the Microsoft Exchange email servers of its targeted victims since at least 2014 via a custom backdoor. . Researchers at ESET say the so-called Turla group, aka Snake, has been hacking into victims' Microsoft Exchange servers and planting its sophisticated LightNeuron backdoor malware for cyber espionage purposes. Turla accesses the email systems by abusing Exchange Server's legitimate Transport Agent feature, which lets other software from Microsoft as well as third parties to operate with Exchange, including spam-filtering tools. The feature lets these other applications process email messages coming and going from Exchange. The link for this article located at DarkReading is no longer available. . Researchers at ESET say the so-called Turla group, aka Snake, has been hacking into victims' Microso. well-known, russian, nation-state, hacking, group, infiltrating, microsoft, exchange, email. . LinuxSecurity.com Team

Calendar%202 May 07, 2019 User Avatar LinuxSecurity.com Team Server Security
83

NCA Under Cyber Attack By Lizard Squad After Recent Arrests

Cyber-attackers have taken down the website of the National Crime Agency (NCA) in apparent revenge for arrests made last week. . The NCA website was temporarily down on Tuesday morning, four days after six teenagers were released on bail on suspicion of using hacking group Lizard Squad The link for this article located at The Guardian is no longer available. . A cyber assault attributed to Lizard Squad caused the National Crime Agency's site to become unavailable following the recent detainment of several of its associates.. Lizard Squad, National Crime Agency, Cyber Attack, Hacking Group, Website Disruption. . LinuxSecurity.com Team

Calendar%202 Sep 01, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Black Vine's Sophisticated Attacks on High-Profile Organizations Revealed

An attack in early 2014 on Anthem, the No. 2 US health insurer, was by most measuring sticks a historic hack, leading to the biggest healthcare data breach ever. New evidence unearthed by researchers from security firm Symantec, however, shows it was business as usual for the hacking group, which over the past three years has carried out more than a dozen similar attacks.. Dubbed Black Vine, the group is well financed enough to have a reliable stream of weaponized exploits for zero-day vulnerabilities in Microsoft's Internet Explorer browser. Since 2012, the gang has brazenly infected websites frequented by executives in the aerospace, energy, military, and technology industries and then used the compromises to siphon blueprints, designs, and other intellectual property from the executives' organizations. . Dubbed Black Vine, the group is well financed enough to have a reliable stream of weaponized exploit. attack, early, anthem, health, insurer, measuring, sticks, histo. . LinuxSecurity.com Team

Calendar%202 Jul 29, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Facebook Privacy Vulnerability Threat by Bug Lab Hackers

The Bug Lab hacking group which can be found on 1337day.com, is selling a Facebook Privacy Vulnerability which allows the hacker to send messages via any Facebook account.. The Bug Lab hackers have made a proof of concept video, which shows how they are able to send messages via any account. The link for this article located at Cyber War Zone is no longer available. . The Bug Lab hackers have made a proof of concept video, which shows how they are able to send messag. hacking, group, which, found, 1337day, selling, facebook, privacy, vulnerabi. . LinuxSecurity.com Team

Calendar%202 Jul 14, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Social Engineering Strategy: Clandestine Fox Targets Energy Employee

A hard-to-tracking hacking group, known to use zero-day attacks, changed tack to use social media in an attempt to compromise an employee of an energy company, according to new research from FireEye.. FireEye declined to say who conducted the attack other than it was the same group that ran a campaign it dubbed "Operation Clandestine Fox," which it described in April and early May. It also did not identify where the employee works. The link for this article located at TechWorld is no longer available. . FireEye declined to say who conducted the attack other than it was the same group that ran a campaig. hard-to-tracking, hacking, group, known, zero-day, attacks, changed, social, media. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Hidden Lynx Group: Government Hackers Exploit Financial Services

An elite group of nation-state hackers running roughshod through the financial sector and other industries in the U.S. has pioneered techniques that others are following, and has used sophisticated methods to go after hardened targets, including hacking a security firm to undermine the security service the company provided its clients.. The highly professional group, dubbed Hidden Lynx, has been active since at least 2009, according to security firm Symantec, which has been tracking the group for some time. Hidden Lynx regularly uses zero-day exploits to bypass countermeasures they encounter. And, unusually for a government-sponsored effort, the gang appears to have a sideline staging financially motivated attacks against Chinese gamers and file-sharers. The link for this article located at Wired is no longer available. . A specialized team of state-sponsored cyber operatives infiltrates economic systems and employs advanced techniques to breach protective measures.. Hidden Lynx, State-Sponsored Hacking, Financial Cyber Threats. . LinuxSecurity.com Team

Calendar%202 Sep 18, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200