Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 8 articles for you...
83

Addressing IPv6 Security Risks in Today’s Enterprise Networks

If your IPv6 strategy is to delay implementation as long as you can, you still must address IPv6 security concerns right now. If you plan to deploy IPv6 in a dual-stack configuration with IPv4, you're still not off the hook when it comes to security. And if you think you can simply turn off IPv6, that's not going to fly either. . The biggest looming security threat lies in the fact that enterprise networks already have tons of IPv6 enabled devices, including every device running Windows Vista or Windows 7, Mac OS/X, all Linux devices and BSD. The link for this article located at Network World is no longer available. . As organizations adopt IPv6, they face evolving security challenges due to its complexity and unique vulnerabilities. Enterprises must strengthen their defenses to mitigate risks.. IPv6 Security, Enterprise Networks, Network Configuration, Cybersecurity Threats, Dual-Stack Implementation. . LinuxSecurity.com Team

Calendar%202 Nov 28, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

WebGL Advisory: New Threats In 3D Graphics Exploits by Context

Context highlights additional WebGL vulnerabilities and raises more questions for Khronos. 16 June 2011: Researchers at Context Information Security who exposed security flaws in WebGL last month have identified further concerns about early implementations of the new technology that allows web pages to draw fast 3D graphics to deliver a much richer experience to web users. In one example, a vulnerability in the Mozilla Firefox browser made it possible for malicious web pages to capture any screenshot from a target PC . Cybersecurity analysts have revealed new vulnerabilities in WebGL, raising serious concerns about internet browser security and the dependability of 3D user interfaces. WebGL Security, Browser Threats, 3D Graphics Issues. . LinuxSecurity.com Team

Calendar%202 Jun 16, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
77

Improve DNS Security: Best Practices for Implementing DNSSEC

The Domain Name System (DNS) plays a critical part in Internet communications, as it's used to translate a human-readable computer hostname into an IP address -- such as searchsecurity.co.uk to 65.214.43.49 -- so that it can be understood and used by networking equipment, computers and software programs. . It's the world's largest distributed database, but when it was originally designed back in 1984, scalability and availability were the key goals and little attention was given to security. This lack of security has lead to a series of DNS-related vulnerabilities. For example, if attackers can change your DNS zone data -- the DNS namespace for which you're administratively responsible -- they can set up counterfeit Web servers, or cause email to be redirected to other servers. Cybercriminals are increasingly using false DNS servers to intercept legitimate Web addresses and redirect users to fake sites in order to capture personal information or install malware. A fix for the critical shortcomings of DNS server security has been a long time coming, in large part due to the problem of maintaining backwards compatibility. But Domain Name System Security Extensions (DNSSEC) has finally been rolled out, and this new security layer is a major step towards a more secure Web address The link for this article located at Search Security is no longer available. . Explore DNS security and the essential role of DNSSEC in fighting internet threats, enhancing the integrity of DNS data and boosting overall cybersecurity.. Dns Security,Dnssec Implementation,Internet Threats,Network Security,Cybersecurity Best Practices. . LinuxSecurity.com Team

Calendar%202 Oct 18, 2010 User Avatar LinuxSecurity.com Team Server Security
72

Firewalls and Security Strategy: Insights from Daniel Kennedy

This is the second of two parts of an interview with Daniel Kennedy, MSIA, who graduated from the Master of Science in Information Assurance program in the School of Graduate Studies of Norwich University in 2008. He has recently become a contributor to an interesting, thoughtful and valuable blog at Forbes Online and I interviewed him recently about his new project. . What do you think your focus will be in the coming months? I'm still finding my voice on this Web site, but my primary focus will be on what I think is most missing: fundamental security strategy within companies and its effective execution. I am very much in favor of the capabilities new and innovative products can provide, but I find their implementation in many organizations is haphazard; the products lead the implementation calendar rather than allowing internal teams to find the right products that fit into an overall, strategy that prioritize the rollout of its component parts. For example, there are organizations which provide privileged access to all users and have no Web filtering, yet they are asking about high end data leakage protection (DLP) products. Companies may have no patch management and no validation of their anti-virus, yet they want to discuss high end log review security information and event management (SIEM) products. Many companies are not doing intrusion detection at all, doing it in baffling ways, or outsourcing it to providers who aren't actually monitoring anything. In most cases all of these things should be part of a strategy, but more complex projects will only be successful if built on a foundation of getting the basics right. The link for this article located at Network World is no longer available. . Delve into essential perspectives on cybersecurity measures and firewall deployment shared by a Forbes expert in this captivating discussion.. Firewall Implementation, Security Strategy, Intrusion Detection, Access Control. . Alex

Calendar%202 Jun 01, 2010 User Avatar Alex Firewalls
67

Exploring Bruce Schneier's Cryptography Engineering for Practitioners

Bruce Schneier has updated Applied Cryptography. I have a new book, sort of. Cryptography Engineering is really the second edition of Practical Cryptography. Niels Ferguson and I wrote Practical Cryptography in 2003. Tadayoshi Kohno did most of the update work. Cryptography Engineering is a techie book; it's for practitioners who are implementing cryptography or for people who want to learn more about the nitty-gritty of how cryptography works and what the implementation pitfalls are. If you've already bought Practical Cryptography, there's no need to upgrade unless you're actually using it. The link for this article located at Bruce Schneier is no longer available. . Cryptography Engineering is a techie book; it's for practitioners who are implementing cryptography . cryptography, bruce, schneier, updated, applied, engineerin. . LinuxSecurity.com Team

Calendar%202 Mar 24, 2010 User Avatar LinuxSecurity.com Team Cryptography
74

VeriSign DNSSEC Implementation: Enhancing Internet Security By 2011

VeriSign has said a significant outstanding internet security vulnerability will be closed by 2011, after delays caused by technical aspects of the implementation. The problem is that DNS, the Domain Name System that translates internet addresses such as website URLs into numerical values, can be seeded with false values and used to misdirect users.. VeriSign told ZDNet on Friday that it will put in place DNSSEC, a protocol which will guarantee the origin and integrity of DNS data, for the .com and .net domains by the first quarter of 2011. "Both .net and .com are very large domains," said Pat Kane, VeriSign vice president of naming services. Kane added that ".net alone has more than 12 million domain names. Our first priority is to safely and securely implement DNSSEC, as it impacts the Domain Name System, one of the core building blocks of the internet". The link for this article located at ZDNet UK is no longer available. . The Internet Corporation plans to deploy DNSSEC by 2011 to bolster online security and safeguard against potential DNS threats.. DNS Integrity, VeriSign Update, DNSSEC Implementation. . Anthony Pell

Calendar%202 Nov 16, 2009 User Avatar Anthony Pell Network Security
67

Study: Low Encryption Implementation Among IT Managers Shows Urgency

While 66% of IT and business managers surveyed have "some type" of encryption strategy, only 16% have enterprise-wide strategies, the Ponemon Institute found. While IT and business managers say they know encryption is critical to safeguarding company information on laptops, not many are actually doing it. . While 66% of IT and business managers surveyed have "some type" of encryption strategy, only 16% have enterprise-wide strategies, the Ponemon Institute found. While IT and business managers say they know encryption is critical to safeguarding company information on laptops, not many are actually doing it. The link for this article located at Read this full article is no longer available. . While most IT leaders acknowledge the significance of data protection, actual deployment stands at just 16%, showing a considerable gap.. encryption strategy, IT security, data protection, business encryption. . LinuxSecurity.com Team

Calendar%202 Feb 14, 2007 User Avatar LinuxSecurity.com Team Cryptography
72

Understanding Firewall Implementation for Network Security

A firewall is an organizationally and technical concept for the separation of networks, its correct implementation and constant maintenance. One piece that's often used is a piece of hardware that connects to networks the way as it's allowed in the concept. This piece of hardware is often called firewall-system/computer or in short firewall. . How does a typical technical implementation of a firewall look like? First you put a packetfilter between the directly connected networks (network 1 -- packetfilter -- perimeter network -- packetfilter -- network 2). The packetfilters only allow traffic from the directly attached networks. A connection from one network to the not directly attached packetfilter or the other network is strictly forbidden. The perimeter network is also known as DMZ (Demilitarized Zone). In it there are switching computers for all protocols/services who should work from one net to the other net. Such a switching computer is also known as Proxy, because it works pro procurationem/by proxy (like a secretary). Proxies work on application level, means they understand the communi The link for this article located at Lutz Donnerhacke is no longer available. . How does a typical technical implementation of a firewall look like? First you put a packetfilter be. firewall, organizationally, technical, concept, separation, networks, correct. . Benjamin D. Thomas

Calendar%202 Feb 10, 2005 User Avatar Benjamin D. Thomas Firewalls
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200