Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
83

KorBanker Malware: Google & Facebook ID Exposure on Command Server

Text messages containing VPN passwords and authentication codes for Google and Facebook are found on a command-and-control server for Android malware. Research on Android malware called KorBanker has uncovered a treasure trove of text messages that include authentication codes for Google and Facebook and VPN passwords. How the thieves made use of the data is not known. However, FireEye researcher Hitesh Dharmdasani assumes cybercriminals have figured out a way to exploit it for financial gain. The link for this article located at CSO Online is no longer available. . The malicious software known as KorBanker for Android compromises personal data by revealing confidential messages that involve authentication tokens for services like Google and Facebook.. KorBanker Malware, Android Malware Attack, Data Exposure. . LinuxSecurity.com Team

Calendar%202 Sep 05, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

New Cyber Threats Rising Following Arrest of Blackhole Hacker

Security researchers Tuesday said reports of the arrest of the hacker behind Blackhole, one of the most widely used exploit kits on the Internet, is good news for IT operations and users. But it shouldn't be long before another hacker takes his place.. "[It's] is a big deal," said Mikko Hypponen, chief research officer at security firm F-Secure. "According to our statistics, Paunch has been the biggest provider of exploit packs for the past two years." The link for this article located at Network World is no longer available. . '[It's] is a big deal,' said Mikko Hypponen, chief research officer at security firm F-Secure. 'Acco. security, researchers, tuesday, reports, arrest, hacker, behind, blackhole. . LinuxSecurity.com Team

Calendar%202 Oct 09, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Exploring Kernel Malware and Rootkit Threats: F-Secure Insights

Security analysts have been predicting that kernel rootkits, which cloak their activity by replacing a portion of a program's software kernel with modified code, are expected to continue to grow in frequency in 2007. While rootkit-fighting technologies such as the PatchGuard kernel protection system built into 64-bit versions of Microsoft's new Windows Vista operating system are arriving, most PC users will still be left open to the attacks over the next twelve months, CA has said, and even experienced PC users are vulnerable to their sophisticated techniques. . F-Secure Security Labs has been tracking and dissecting kernel malware for years; this form of attack was first spotted as far back as 1999, in the form of the WinNT/Infis attack. F-Secure researcher Kimmo Kasslin has made the findings available in a paper titled "Kernel Malware: The Attack from Within" (a PDF) as well as in a slide show (also a PDF). The link for this article located at eweek is no longer available. . F-Secure Security Labs has been tracking and dissecting kernel malware for years; this form of attac. security, analysts, predicting, kernel, rootkits, which, cloak, their, activity, replacing. . LinuxSecurity.com Team

Calendar%202 Feb 26, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
82

NSF Grants $12M for Internet Centers on Cyber Security Research

The National Science Foundation announced Tuesday that it has granted more than $12 million to academic researchers for the creation of two centers to investigate infectious code and study the Internet's ecology. . . .. The funds set aside for the centers are part of the NSF's Cyber Trust program, through which the foundation has granted a total of $30 million to 33 projects focused on researching ways to provide better information security. The Center for Internet Epidemiology and Defenses, or the CIED, will work to understand how digital diseases such as worms and viruses spread across the Internet, and how epidemics can be defeated. The Security Through Interaction Modeling, STIM, Center will draw parallels with nature's ecology to understand the complex interaction between machines, humans and cyberattacks. "These centers, as well as our other funded activities, are looking not only for new ways to cope with imperfections in today's systems but also for the knowledge and techniques to build better systems in the future," Carl Landwehr, the NSF's program director for Cyber Trust, said in a statement. The link for this article located at Robert Lemos CNET News.com is no longer available. . The funds set aside for the centers are part of the NSF's Cyber Trust program, through which the fou. national, science, foundation, announced, tuesday, granted, million, acade. . Anthony Pell

Calendar%202 Sep 22, 2004 User Avatar Anthony Pell Government
83

Exploring Slapper and Scalper Unix Worms and Linux Security Threats

Fueled by the old myth that "you can't get a virus in Unix" and by the increasing popularity of Linux and FreeBSD, Unix viruses passed an important milestone in 2001 and continued by receiving even more attention during 2002. . .. Fueled by the old myth that "you can't get a virus in Unix" and by the increasing popularity of Linux and FreeBSD, Unix viruses passed an important milestone in 2001 and continued by receiving even more attention during 2002 . It all begun with the Ramen worm, then continued with Adore, Lion, Cheese, RST.B and many, many more. Some of them even became widespread, culminating with the inclusion of OSF.8759 in the May 2002 Wildlist Unfortunately, while there are lots of charts and distribution statistics available for Win32 viruses, the same cannot be said about Unix viruses. Actually, at the time of writing, there is no reliable (and constantly updated) source of information regarding the distribution of Linux/FreeBSD malware, not to mention other Unix flavors which are less appealing to virus writers. The link for this article located at SecurityFocus is no longer available. . The belief in Unix’s strong immunity fostered a false security among users, encouraging worm exploits that highlighted vulnerabilities and spurred security dialogues in Linux.. Unix Worms, Linux Malware, Virus Myths, Security Threats, Worm Tracking. . LinuxSecurity.com Team

Calendar%202 Feb 04, 2003 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200