Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
83

Cyber Attack on WordPress Sites Hits DreamHost GoDaddy Bluehost

According to various reports, in the past few days a number of websites created using WordPress have been hacked. While the attack initially appeared to be limited to web sites hosted by American ISP DreamHost, it has since become apparent that blogs hosted at GoDaddy, Bluehost and Media Temple have also been affected. . Unconfirmed reports by WPSecurityLock suggest that other PHP-based management systems, such as the Zen Cart eCommerce solution, have also been targeted. The hacked web pages appear to have been infected with scripts, which not only install malware on users' systems, but also prevent browsers like Firefox and Google Chrome, which use Google's Safe Browsing API, from issuing an alert when users try to access the page. When Google's search bot encounters such a specially crafted page, the page responds by simply returning harmless code. This camouflage strategy takes advantage of the browser switch normally used by developers to return browser specific code to suit functional variations in different browser, such as Internet Explorer and Firefox. The link for this article located at H Security is no longer available. . Widespread cyber attacks have targeted Joomla platforms hosted on various service providers, raising alarm about potential vulnerabilities.. WordPress Security, Malware Attack, Web Exploitation, ISP Threat, PHP Exploitation. . LinuxSecurity.com Team

Calendar%202 May 10, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

FTC and International Partners Tackle Remote-Controlled Spam Threats

Remote-controlled "zombie" networks operated by bottom-feeding spammers have become a serious problem that requires more industry action, the Federal Trade Commission is expected to announce on Tuesday. . The FTC and more than 30 of its counterparts abroad are planning to contact Internet service providers and urge them to pay more attention to what their customers are doing online. Among the requests: identifying customers with suspicious e-mailing patterns, quarantining those computers and offering help in cleaning the zombie code off the hapless PCs. To be sure, computers infected by zombie programs and used to churn out spam are a real threat to the future of e-mail. One report by security firm Sophos found that compromised PCs are responsible for 40 percent of the world's spam--and that number seems to be heading up, not down. But government pressure--even well-intentioned--on Internet providers to monitor their users raises some important questions. Will ISPs merely count the number of outbound e-mail messages, or actually peruse the content of e-mail correspondence? E-mail eavesdropping is limited by the Electronic Communications Privacy Act in the United States, but what about other countries without such laws? If these steps don't stop zombie-bots, will the government come back with formal requirements instead of mere suggestions the next time around?. Regulatory bodies are addressing fraudulent networks and highlighting the vital position of internet service providers in protecting consumers.. Spam Network Management, Botnet Defense, FTC Guidelines. . Brittany Day

Calendar%202 May 23, 2005 User Avatar Brittany Day Network Security
74

Insecure Networks at Seattle's Westin Building Cause Major Risks

The major Internet backbone networks for the Pacific Northwest converge at a single location: the Westin building in Seattle, a 32-story structure that houses dozens of major and minor Internet service providers. It is also home to more than 50 . . . . The major Internet backbone networks for the Pacific Northwest converge at a single location: the Westin building in Seattle, a 32-story structure that houses dozens of major and minor Internet service providers. It is also home to more than 50 wireless networks, most of which apparently have no security. "The Westin building is the Northwest nexus for all the fiber. Everyone who is anyone is colocated there," said Josh Pennell, CEO and principal consultant for Seattle security firm IOActive, who recently visited his company's servers at the site. "You can think about the mayhem that people can cause by getting onto that. It's pretty scary stuff." The link for this article located at News.com is no longer available. . Unsafe network configurations within the Westin building in Seattle create significant risk exposure for service vendors.. Westin Building, Network Liability, Internet Security. . Anthony Pell

Calendar%202 Jul 01, 2002 User Avatar Anthony Pell Network Security
83

CloudNine Communications ISP Cyber Attack Leads To Business Closure

Fears are growing once more that companies operating on the Internet may not be equipped to ward off electronic sabotage after anonymous "hackers" forced a small British firm out of business. CloudNine Communications, one of Britain's oldest Internet Service Providers (ISPs) . . . . Fears are growing once more that companies operating on the Internet may not be equipped to ward off electronic sabotage after anonymous "hackers" forced a small British firm out of business. CloudNine Communications, one of Britain's oldest Internet Service Providers (ISPs) shut down last week with the loss of eight jobs in what computer experts believe is the first instance of a company being hacked out of existence. The link for this article located at CNN.com is no longer available. . Fears are growing once more that companies operating on the Internet may not be equipped to ward off. fears, growing, companies, operating, internet, equipped. . LinuxSecurity.com Team

Calendar%202 Feb 03, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Verio Resists MPAA Pressure: A Bold Stand for Free Speech Online

In a move that free-speech activists hope will be trendsetting, Internet service provider Verio is standing up to the movie industry by refusing to remove a Web site the Motion Picture Association of America says is illegal. Many ISPs, especially smaller . . . . In a move that free-speech activists hope will be trendsetting, Internet service provider Verio is standing up to the movie industry by refusing to remove a Web site the Motion Picture Association of America says is illegal. Many ISPs, especially smaller ones that don't have large legal departments, yank sites immediately after receiving threatening letters from content providers to avoid liability. But Verio, a unit of NTT Communications that hosts more than 400,000 Web sites, is raising the bar for site closures by refusing to buckle under MPAA pressure. The link for this article located at USA Today is no longer available. . In a move that free-speech activists hope will be trendsetting, Internet service provider Verio is s. free-speech, activists, trendsetting, internet, service, provider, verio. . LinuxSecurity.com Team

Calendar%202 Jan 28, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Web Attacks Raise Questions On ISP Data Protection Role

Robert Lemos writes... "Security experts and Internet users are becoming increasingly vocal about their concerns that high-speed Internet providers are not doing enough to ensure the data security of home users." ...but, someday we will realize that security is everyones . . .. Robert Lemos writes... "Security experts and Internet users are becoming increasingly vocal about their concerns that high-speed Internet providers are not doing enough to ensure the data security of home users." ...but, someday we will realize that security is everyones responsibility. The link for this article located at Robert Lemos, ZDNet - Â is no longer available. . Fears escalate regarding ISPs' responsibility in safeguarding household data as online threats intensify.. Data Security, Internet Providers, User Protection, Threat Management. . Anthony Pell

Calendar%202 Feb 22, 2000 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200