Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -3 articles for you...
215

GNOME Cuts Vulnerability Disclosure Window to 30 Days

GNOME is officially shortening its standard vulnerability disclosure window from 90 days to 30 days, a change that impacts upstream maintainers, downstream Linux distributions, and system administrators in how they handle software vulnerabilities. The policy shift, announced by long-time security coordinator Michael Catanzaro , addresses modern software patching realities and a growing influx of automated submissions. . Because GNOME is the default desktop environment on several major Linux distributions, changes to its security process can affect downstream maintainers and organizations that deploy GNOME-based workstations. The shorter disclosure window could reduce the time available for downstream distributions and organizations to prepare updates before vulnerability details become public. What Actually Changes on August 1? The new policy introduces strict operational guidelines for how incoming security issues are handled across GNOME projects: Effective Date: The 30-day disclosure window only applies to vulnerabilities reported on or after August 1, 2026. Automatic Public Disclosure: According to the policy of GNOME, if a vulnerability is not fixed after 30 days the report will not be confidential anymore. Existing Reports Unaffected: Any security reports filed before August 1 will still follow the old 90 day embargo timeline to avoid disruption of active investigations. Handling AI-Ban Projects: For upstream projects that do not explicitly accept contributions of AI-generated content, the GNOME security team will locally close incoming reports, instead of forwarding automated noise to developer issue trackers. Why GNOME Changed Its Security Policy To understand the timeline shift, it helps to know why disclosure embargoes exist in the first place. Coordinated disclosure policies aim to give developers and downstream maintainers a protected window of time to investigate flaws, write patches, and coordinate repository updates before technicalexploit details become public knowledge. Under the previous 90-day framework, however, that window no longer matched actual project behavior. In practice, GNOME maintainers typically resolve valid security issues within one to three weeks, or they leave them unaddressed entirely. Keeping unpatched reports confidential for a full 90 days created administrative delays without providing practical benefits for patch development. Moreover, the rise of automated tools had a dramatic impact on submission patterns. There are fewer reports that are written by humans, and more reports that are generated by AI. A large proportion of these automated submissions are of low quality, which significantly increases the triage burden on maintainers. Some open-source projects opted for immediate full disclosure for AI-generated reports, but GNOME opted for a more balanced 30-day window to ensure maintainers still have a reasonable window to fix legitimate issues. How the New Timeline Affects Linux Distributions When GNOME fixes a security issue, distribution maintainers package those changes, publish updates, and release security advisories. A shorter disclosure window gives each step in that process less time before vulnerability details may become public. Downstream maintainers across Fedora Workstation , Ubuntu Desktop , and Debian face tighter turnaround times to build and test patches. If an issue remains unresolved when the 30-day clock runs out, technical details enter the public domain, leaving downstream maintainers with less time to validate and distribute updates before technical details become public. What Linux Administrators Should Expect System administrators and enterprise IT teams managing GNOME-heavy environments should adjust their operational expectations to align with the new timeline. Rather than tracking upstream GNOME announcements directly, security teams should monitor security notices issued by their specific Linux distribution. Organizations must be prepared for technicalvulnerability details to become public sooner if upstream maintainers cannot reach a resolution within the 30-day window, meaning internal staging and QA windows for desktop updates may need to be streamlined. GNOME Begins Search for a New Security Coordinator Supporting this policy transition is an upcoming leadership change within the project. Catanzaro, who has managed GNOME security tracking largely alone since November 2020 with backing from Red Hat, announced plans to step down from coordinating security reports later this year. Catanzaro will stop tracking newly reported issues on November 1, 2026, aiming to clear the remaining pipeline by December. The departure initiates a search for an experienced community successor to manage incoming reports, oversee disclosure deadlines, and coordinate CVE assignments under the new 30-day framework. . As GNOME shortens its vulnerability disclosure window, organizations must adapt to the new 30-day policy to protect systems effectively.. GNOME Security Changes, Vulnerability Disclosure, Linux Distribution Guidance. . MaK Ulac

Calendar%202 Jul 21, 2026 User Avatar MaK Ulac Desktop Security
67

NSA TEMPEST Documents: Revealing Security Insights from FOIA Release

The first of several documents related to the US government's TEMPEST programme, obtained by Cryptome.org's John Young under a Freedom of Information Act (FOIA) request, have been posted on his Web site. His original request was denied, but the persistent Young . . . . The first of several documents related to the US government's TEMPEST programme, obtained by Cryptome.org's John Young under a Freedom of Information Act (FOIA) request, have been posted on his Web site. His original request was denied, but the persistent Young sought an appeal of that decision, which was recently granted in his favour. No one is quite sure what TEMPEST stands for (some say it's an acronym for: Telecommunications Electronics Material Protected From Emanating Spurious Transmissions". Others say it is a nothing more than a code word), but what it means is quite simple: electromagnetic and acoustic signals which can be remotely detected and interpreted by a spy. The link for this article located at TheRegister is no longer available. . The first of several documents related to the US government's TEMPEST programme, obtained by Cryptom. first, documents, related, government's, tempest, programme, obtained, cryptom. . LinuxSecurity.com Team

Calendar%202 Jan 02, 2001 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200