Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
76

Insights from Intel's Open Source Technology Summit 2019

We've had a number of articles covering the interesting news out of Intel's 2019 Open-Source Technology Summit (OSTS) held at Skamania Lodge in Stevenson, Washington. Here's a look back at the news out of the open-source event as well as some other smaller bits of information shared during the event. . Some of the interesting news and insights from OSTS 2019 included: - Intel announced a new hypervisor based on Rust-VMM that is already seeing industry support from multiple key players. - There's now a Cloud Linux Developer Edition that includes the new GUI installer and store. - Clear Linux is seeing industry adoption ranging from Alibaba to deployments in Microsoft's Azure cloud to MontaVista now offering commercial support for Clear Linux. The link for this article located at Phoronix is no longer available. . Uncover significant updates and revelations from OSTS 2019, featuring Intel's latest hypervisor innovations and the growing adoption of Clear Linux across various sectors.. Intel Rust Hypervisor, Clear Linux Adoption, Open Source Technology Summit, Cloud Developer Edition, OSTS 2019. . Brittany Day

Calendar%202 May 18, 2019 User Avatar Brittany Day Organizations/Events
78

VMware ESXi 5.0: Security Advisory for Hypervisor Bypass Threat

Security experts from ERNW have demonstrated the ability to break out of the virtualisation hypervisor of VMware ESXi 5.0 using crafted VMware images. If a provider offers customers the ability to run customer-supplied VMware images on its servers as part of an infrastructure as a service (IaaS) offering, a malicious user could access all data on the server, including other customers' user passwords and virtual machines.. The security experts were able to manipulate the virtual disk images in a way that caused host disks to be mounted in the guest system after launching the VM. Successful attacks have been mounted in this way against fully patched copies of ESXi 5.0, but the researchers point out that, as far as they are aware, this has so far only happened under laboratory conditions. [All of article] The link for this article located at H Security is no longer available. . Cybersecurity researchers exploited vulnerabilities in VMware images, putting underlying host disks at risk. This poses a serious threat for IaaS users to recognize.. VMware Security Risk,IaaS Vulnerability,Hypervisor Exposure,Virtualization Attack,ESXi Threat. . LinuxSecurity.com Team

Calendar%202 May 30, 2012 User Avatar LinuxSecurity.com Team Vendors/Products
83

PS3 Hacker Releases Hypervisor Insights After Sony Raid

A Playstation 3 hacker says he has released information about reverse engineering hypervisor technology used in the PS3 after his home in Germany was raided earlier this week, reportedly at Sony's request.. In a comment to a post on his PS3 Linux and Hyper Reverse Engineering Blog, Graf-chokolo writes in the comments section: "Guys, SONY was today at my home with police and got all my stuff and accounts. So be careful from now on." After several readers expressed doubt about the legitimacy of the post, he says in another comment: "Guys, I don't joke, it's serious. And to prove it, I kept my word and uploaded all my HV reversing stuff. Upload it everywhere so SONY couldn't remove it easily. Grab it guys, it contains lots of knowledge about HV and HV procs." The link for this article located at CNET is no longer available. . In a comment to a post on his PS3 Linux and Hyper Reverse Engineering Blog, Graf-chokolo writes in t. playstation, hacker, released, information, about, reverse, engineering, hypervisor, technol. . LinuxSecurity.com Team

Calendar%202 Feb 25, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Understanding Virtualization Security: Strategies for Hypervisors and Hosts

Virtualization platforms are software. All software has flaws. Therefore, virtualization platforms have flaws. Simple logic,right? The major virtualization platform vendors, VMware, Xen (now Citrix), and Microsoft, have all had several vulnerabilities over the last few years. However, the major components of a virtualization infrastructure and the IT strategy related to deployment and maintenance of virtualization technologies can be planned and secured fairly well. The following sections will explore the major areas of concern for security professionals.. I. Hypervisor security The hypervisor is a piece of software, in many cases, unless integrated directly with the host platform (see the next section). The major virtualization vendors release patches for their products like any other software providers, and the key to mitigating the risk of hypervisor vulnerabilities is a sound patch management process. Examples of sound patch management practices include maintaining the latest service packs for both guests and hosts, alleviating any unnecessary applications that have a history of vulnerabilities, and applying the latest security rollup patches if and when they are supplied by the virtual software vendor. II. Host/Platform Security The host platform, which connects the VMM and virtual guests to the physical network, can vary widely in the type of configuration options available. This is largely dependent on system architecture; for example, VMware's ESX Server platform has a number of similarities to Red Hat Linux. Given that many of these systems are able to be hardened considerably, a number of The link for this article located at DataCenter Journal is no longer available. . Virtualization security ensures the integrity and availability of virtual environments, focusing on hypervisor protection, host safeguards, network security, compliance, and recovery. Virtualization Security, Hypervisor Best Practices, Security Risks. . LinuxSecurity.com Team

Calendar%202 Mar 16, 2010 User Avatar LinuxSecurity.com Team Server Security
77

Exploring Security Risks of Virtualization on Shared Platforms

A few years ago I wrote a paper for SANS titled . The original intent for that paper was to serve as the first in a series that dug into all facets of virtsec. Starting with the basic threat analysis of moving systems from hardware to software, that paper dealt with security risks like attacking the host platform, attacking individual guests, and using a shared filesystem. These attacks were all examples of exploiting the nature of running virtual machines in a shared environment with shared resources on the virtual platform; they specifically did not delve into security of the hypervisor. We The link for this article located at TMC Net is no longer available. . Exploring the complexities of cloud architecture safety and the threats associated with overseeing communal infrastructures and assets.. virtualization security, shared resources management, hypervisor security. . LinuxSecurity.com Team

Calendar%202 Mar 13, 2010 User Avatar LinuxSecurity.com Team Server Security
77

Security Risks in Hypervisors: Impacts Across Technology Sectors

The basic idea/thesis of this article (and the previous, unfinished draft) is this: hypervisors are getting more and more common, and are growing in deployment in everything from datacenter systems to embedded consumer electronics. But, as their deployment increases, more and more security concerns come into play, including a variety of attack methods and the dire consequences of a compromised hypervisor.. If you know what a hypervisor is, then skip this paragraph: A hypervisor is basically a very minimalist operating system designed with the purpose of abstracting real, physical computer hardware from one or more virtual machines running The link for this article located at The Coffee Desk is no longer available. . As virtualization expands across cloud computing and enterprise IT, security concerns tied to hypervisors are rising, necessitating robust measures for protection. Hypervisor Security, Virtualization Risks, Cloud Infrastructure Security. . LinuxSecurity.com Team

Calendar%202 Dec 03, 2009 User Avatar LinuxSecurity.com Team Server Security
77

Gartner Report Warns About Security Issues In Virtualization Technologies

Companies in a rush to deploy virtualization technologies for server consolidation efforts could wind up overlooking many security issues and exposing themselves to risks, warns research firm Gartner. . Virtualization software offers the ability to run multiple operating systems, or multiple sessions of a single operating system, on a single physical machine, whether server or desktop. But virtualization software, such as hypervisors, present a layer that will be attacked and security strategies need to be put in place in advance, Gartner warns. The link for this article located at Network World is no longer available. . Cloud technologies enable diverse operational systems, but organizations must prioritize mitigating security vulnerabilities, cautions Forrester.. Virtualization Security, Hypervisor Risks, Risk Management, Security Strategies. . LinuxSecurity.com Team

Calendar%202 Apr 10, 2007 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200