Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 38 articles for you...
83

Long-Term Hacking Campaign Targeting Linux Servers: Risks and Threats

Have you heard about the newly uncovered hacking campaign which has been operating successfully against unpatched Linux servers for almost a decade? . Hacking campaigns linked to China have been exploiting vulnerabilities in Linux servers in an operation which successfully stayed under the radar for almost a decade. Detailed by researchers at BlackBerry , the operation, linked to the interests of the Chinese government, is conducting hacking and cyber espionage against a wide array of industries for the purposes of intellectual property theft and data collection. While the overall campaign is multi-platform, a newly uncovered part of it has been exploiting vulnerabilities in Linux since at least 2012 – and without the attackers having to update their offensive capabilities in that time. . Investigate current cyber intrusion efforts attributed to Chinese entities aimed at Linux servers to take advantage of vulnerabilities in security protocols.. Linux exploitation, cyber espionage, hacking threats, security vulnerabilities, data theft. . LinuxSecurity.com Team

Calendar%202 Apr 07, 2020 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Black Vine's Sophisticated Attacks on High-Profile Organizations Revealed

An attack in early 2014 on Anthem, the No. 2 US health insurer, was by most measuring sticks a historic hack, leading to the biggest healthcare data breach ever. New evidence unearthed by researchers from security firm Symantec, however, shows it was business as usual for the hacking group, which over the past three years has carried out more than a dozen similar attacks.. Dubbed Black Vine, the group is well financed enough to have a reliable stream of weaponized exploits for zero-day vulnerabilities in Microsoft's Internet Explorer browser. Since 2012, the gang has brazenly infected websites frequented by executives in the aerospace, energy, military, and technology industries and then used the compromises to siphon blueprints, designs, and other intellectual property from the executives' organizations. . Dubbed Black Vine, the group is well financed enough to have a reliable stream of weaponized exploit. attack, early, anthem, health, insurer, measuring, sticks, histo. . LinuxSecurity.com Team

Calendar%202 Jul 29, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Morpho Group Targets Corporate IP Theft: Twitter, Apple, Microsoft

Symantec has identified a group of cybercriminals, whom they've named "Morpho," as targeting corporate intellectual property for financial gains, with Twitter, Facebook, Apple and Microsoft among those hit. "Attackers going after intellectual property is not that usual," said Vikram Thakur, senior manager at Symantec.. However, those attackers tend to be state-sponsored and target information or military or other strategic importance. The link for this article located at CSO Online is no longer available. . McAfee identifies the 'Chimera' collective engaging with prominent organizations for data breaches, highlighting a transformation in digital crime strategies.. Morpho Group, Corporate IP Theft, Cyber Espionage. . LinuxSecurity.com Team

Calendar%202 Jul 14, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Chinese Cyber Attacks on U.S. Military Secrets and Corporations

Chinese hacking of American computer networks is old news. For years we've known about their attacks against U.S. government and corporate targets. We've seen detailed reports of how they hacked The New York Times. Google has detected them going after Gmail accounts of dissidents. . They've built sophisticated worldwide eavesdropping networks. These hacks target both military secrets and corporate intellectual property. They're perpetrated by a combination of state, state-sponsored and state-tolerated hackers. It's been going on for years. The link for this article located at Schneier on Security is no longer available. . They've built sophisticated worldwide eavesdropping networks. These hacks target both military secre. chinese, hacking, american, computer, networks, years, we've, known, about, their. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

U.S. Indictment Against Chinese Army Unit: Cyber Espionage Implications

A U.S. criminal indictment against Chinese Army personnel over alleged hacking describes how stolen intellectual property was funneled to Chinese companies, an unresolved question for analysts.. In the first legal action of its kind, federal prosecutors charged five members of Chinese Army signals intelligence Unit 61398 with stealing nuclear, solar power and steel trade secrets from six U.S. organizations over eight years. China denies the accusations. The link for this article located at TechWorld is no longer available. . In the first legal action of its kind, federal prosecutors charged five members of Chinese Army sign. criminal, indictment, against, chinese, personnel, alleged, hacking, describes, stolen. . LinuxSecurity.com Team

Calendar%202 May 20, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

IP Commission Proposes Extortion Tactics to Combat IP Theft

Buried in a 100-page report issued last week by the Commission on the Theft of American Intellectual Property was a recommendation to copy a tactic cyber scammers use to extort money from innocent victims.. The IP Commission -- a private panel of politicians, military and defense officials and technology leaders -- is co-chaired by Jon Huntsman, former governor of Utah and former U.S. ambassador to China, and Dennis Blair, a retired U.S. Navy admiral and former Director of National Intelligence. The link for this article located at Network World is no longer available. . The Security Council suggests deploying aggressive measures against copyright infringers, focusing on safeguarding national creative assets.. Intellectual Property Theft,Cybersecurity Strategy,Technology Leaders. . Alex

Calendar%202 May 28, 2013 User Avatar Alex Network Security
81

Debate Over Copyright Alert System's Punitive Impact on ISPs

A new system launched to curb online piracy of intellectual property is meant to be educational, not punitive, says the organization behind it. But suspended Internet service or slowing service to a crawl sounds pretty punitive to critics of the Copyright Alert System (CAS).. The Center for Copyright Information (CCI)'s move has ignited yet another debate over the best way to protect the owners of creative property without inhibiting the free flow of information and entertainment. CCI has also angered freedom of information advocates for another reason -- it makes Internet Service Providers (ISP) the first line of enforcement of alleged copyright infringement. The link for this article located at CSO Online is no longer available. . The initiative by the Intellectual Property Alliance sparks discussion regarding the balance between safeguarding artistic rights and ensuring public access.. Copyright Enforcement, Online Piracy, Intellectual Property Rights, ISPs, Information Advocacy. . LinuxSecurity.com Team

Calendar%202 Mar 05, 2013 User Avatar LinuxSecurity.com Team Privacy
83

Zero-Day Attack: Sykipot Malware Targets U.S. & U.K. Defense and Industry

The latest Adobe Reader and Acrobat zero-day attack is part of a larger, longer-term targeted attack campaign aimed mainly at stealing intellectual property from the U.S. and U.K. industries and government agencies, according to Symantec.. Symantec identified the malware family involved in the attacks as Sykipot, which has been used in targeted attacks for the past two years and possibly as far back as 2006. Organizations hit in the latest wave of attacks were mainly U.S. and U.K. defense contractors, telecommunications firms, computer hardware companies, chemical companies, energy companies, and government agencies. The link for this article located at Dark Reading is no longer available. . Kaspersky disclosed that the ShadowPad malware is aimed at industries in Canada and Australia through an unpatched vulnerability.. Adobe Reader Exploit,Sykipot Malware,Zero-Day Attack. . LinuxSecurity.com Team

Calendar%202 Dec 12, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200