Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 436
Alerts This Week
Warning Icon 1 436

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
72

Impact of JavaScript Malware on Application and Network Security

All ports were open to the world and practically every application had holes in it. It was like the Wild West. Eventually application security became a big deal as more serious issues were uncovered and more commerce depended upon secure platforms. Network security was next on the scene. It made sense to build a single choke point for all security needs. It was slick because it could see all the packets in transit to and from your servers, and turn off all access to anything that had a known hole in it. Those were the good times. Times have since changed. . Network security, in large part, had a huge role to play in creating the newest attacks. Network administrators rightly told their architects to build applications that could be tunneled over hypertext transfer protocol, while at the same time they would close down all access to any other unnecessary inbound services. Can you see the obvious flaw in their logic here? Even still, aside from the occasional hole in IMAP or BIND, the world of computer security seemed to be calming down quite a bit with the advent of stateful packet inspection and security information management tools. Most of the holes at that time were against the security tools themselves, which most of the hardcore security folks felt was scraping the bottom of the barrel -- the last bunch of entry points to a secured network. The link for this article located at Dark Reading is no longer available. . Cyber defense is crucial in preventing malicious attacks on apps and firewalls that exploit JavaScript vulnerabilities. Learn more!. JavaScript Malware, Network Security Threats, Application Security Risks, Firewall Vulnerabilities. . Brittany Day

Calendar%202 Oct 31, 2006 User Avatar Brittany Day Firewalls
82

Examining Hacker Accountability In The Legal System's Failures

In the Internet criminal justice system the people are betrayed by two separate, yet equally important groups: the hackers who investigate and exploit security problems and the legal authorities who don't take the offenders seriously. These are their stories. . Of the many discouraging aspects of computer security, one of the worst is that offenders are rarely punished at all, let alone seriously. I have to think another disappointment in this regard is imminent. I refer to the case of Sven Jaschan, who last year was ratted out for money by a friend. Jaschan had authored the Sasser and Netsky worms, both on the short list for most damaging and long-lasting malware infestations, and both still on the charts as active threats. The news stories give the unmistakable whiff of "community service": Little Svenny was a minor when some of the offenses were committed, the maximum sentence is five years, he confessed, and it's presumably his first offense. The link for this article located at eWeek is no longer available. . Of the many discouraging aspects of computer security, one of the worst is that offenders are rarely punished seriously or at all.. Hacker Accountability, Legal System Failures, Cybercrime Consequences, Malware Threats. . Brittany Day

Calendar%202 Jul 13, 2005 User Avatar Brittany Day Government
74

Examining the Sobig Worm's Role in the Rise of Spam in 2003

The Sobig worm is to thank for a massive increase in spam e-mail during 2003 and the problem of unsolicited commercial junk e-mail is set to get worse in 2004.. . .. The Sobig worm is to thank for a massive increase in spam e-mail during 2003 and the problem of unsolicited commercial junk e-mail is set to get worse in 2004. That is according to UK-based e-mail filtering company MessageLabs, which claims that there was a 77 percent increase in global spam volumes this year. The firm said that in May, the global spam to e-mail ratio exceeded 50 percent for the first time, with the average ratio for the year being one spam for every 2.5 normal e-mails received. This compared to 1 in 11 during 2002. But possibly the most worrying statistic in the report was a claim that more than two-thirds of all spam was sent through hijacked computers, thanks in part to malware like the Sobig worm which represents a new breed of cyber-pest that blends spamming with viruses. "Sobig.F, the pre-eminent example of this convergence, sought not only to infect a machine and propagate further through mass mailing techniques, but to compromise systems by exploiting open proxies," commented Mark Sunner, chief technology officer at MessageLabs "This backdoor route turns infected PCs into spam relay engines -- causing individual users concern, as well as security breaches and lost bandwidth and productivity for organisations." The link for this article located at ElectricNews.net is no longer available. . The Sobig worm is to thank for a massive increase in spam e-mail during 2003 and the problem of unso. sobig, thank, massive, increase, e-mail, during, problem. . Anthony Pell

Calendar%202 Dec 16, 2003 User Avatar Anthony Pell Network Security
74

Nimda Virus Anniversary- Impact on IT Security Changes Since 2022

This week marks the first anniversary of the Nimda virus attack, an event that may have driven more corporate IT security changes during the past 12 months than the Sept. 11 terrorist attacks did. . .. This week marks the first anniversary of the Nimda virus attack, an event that may have driven more corporate IT security changes during the past 12 months than the Sept. 11 terrorist attacks did . Nimda first surfaced on Sept. 18 last year and was among the first major viruses to target both servers and client computers. It combined features from previous threats and propagated not just via e-mail attachments, but also through shared files on servers. It also exploited Web pages containing Java scripts. "Nimda heightened awareness, unfortunately at a very high cost," said Kim Milford, information security manager at the University of Wisconsin-Madison. For example, the virus showed that "filtering at the e-mail gateway or on the desktop alone wasn't the Holy Grail that we security folks are always seeking," Milford said. The link for this article located at IDG is no longer available. . Reviewing the transformative IT security changes driven by the Nimda virus attack anniversary since its emergence last year.. Nimda Virus, Cybersecurity Threat, IT Security Transformation, Malware Awareness. . Anthony Pell

Calendar%202 Sep 23, 2002 User Avatar Anthony Pell Network Security
83

Examining Liability For Software Companies In Security Breaches

Should software companies be more liable for problems caused when software breaks or some malicious outsider breaks it? The National Academy of Sciences, in a security paper released last month, says yes. But I'm not sure our nation's supposedly brightest minds have really thought this out.. . .. Should software companies be more liable for problems caused when software breaks or some malicious outsider breaks it? The National Academy of Sciences, in a security paper released last month, says yes. But I'm not sure our nation's supposedly brightest minds have really thought this out. First, let me make one thing very clear: I don't understand why I have to buy antivirus and security software. Not that I hold anything against the companies that make those products; actually, I think McAfee and--especially--Norton do a pretty good job. BUT IF ALL this software does is protect me against vulnerabilities in Microsoft's operating systems, technologies, and applications, why doesn't Microsoft just give me the protection for free? Or perhaps as a subscription (I know readers hate the word) that includes operating system updates and upgrades as well? The link for this article located at ZDNet is no longer available. . The accountability of software firms for data breaches is critical. These organizations must protect user information and may face legal actions for negligence if they fail.. Software Liability,Cybersecurity Risks,Security Breach,Malware Impact. . LinuxSecurity.com Team

Calendar%202 Feb 05, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Understanding Code Red Worm's Threats and Network Security Impact

While the initial version of the worm did little more harm to compromised servers than deface their Web sites, Maiffret said he's among those who fear the impact of an renewed outbreak on Internet traffic could be greater the second time . . . . While the initial version of the worm did little more harm to compromised servers than deface their Web sites, Maiffret said he's among those who fear the impact of an renewed outbreak on Internet traffic could be greater the second time around. The alternate variation of the worm has been described as a "mutated" incarnation of the original, but Maiffret said it doesn't mutate by itself. "How that second version got out is really unclear," he said. "Whether it was the same person who wrote the first one or someone modified (it), we don't know. But it is a little more devious because the way it generates the IP address to attack is random, whereas the first one was in sequence. "Also, the second one doesn't deface Web sites, so it's going to spread more quickly than the first one, and with stealth - which is not a good combination." Maiffret said the total of more than 300,000 infected Web servers during the first outbreak doesn't illustrate the full power of a worm that might have been just getting rolling when it switched to White-House-attack mode late on the 19th. The link for this article located at Newsbytes is no longer available. . The original worm variant attacked server systems by altering web pages. Concerns about heightened traffic disruptions from potential resurgences intensify.. Code Red Worm, Internet Cybersecurity, Malware Analysis, Network Attack, Enhanced Threats. . Anthony Pell

Calendar%202 Jul 31, 2001 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200