Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Red Hat and Oracle announced jointly Tuesday that they have partnered to bring Red Hat Enterprise Linux (RHEL) to Oracle Cloud Infrastructure, broadening Oracle’s available public cloud options and creating a measure of détente between two long-standing competitors. . The announcement couched the news as step one in a broader partnership between Red Hat and Oracle, but provided details mostly of the OCI integration. RHEL will be available on Oracle’s VMs, ranging in size from 1 to 80 CPU cores and from 1GB of memory up to 1024GB. Initial support will be limited to the newer OCI virtual machine shapes, which use AMD, Intel and Arm processors. The idea is to provide an opportunity for customers who have workloads running on RHEL to move those into Oracle’s cloud. The ability for users to standardize on OCI, given the popularity of RHEL for a wide array of enterprise workloads, could prove valuable to Oracle’s push to make its cloud more competitive with the larger hyperscalers. . Announcing CentOS Stream on Azure, broadening choices for business applications and strengthening collaborations.. Red Hat, Oracle, Cloud Infrastructure, Enterprise Linux, Virtual Machines. . LinuxSecurity.com Team
Oracle has published its latest quarterly update to GraalVM, the open-source Java JVM/JDK implemented in Java that also supports other execution modes and programming languages from Python to R to Ruby, adding Java 17 support and featuring a selection of other improvements you don't want to miss! . Given last month's release of > Java 17 / OpenJDK 17, GraalVM 21.3 has added Java 17 support. Plus there are many other improvements to its various language front-ends and other components. . GraalVM 21.3 brings compatibility with Java 17 and offers several improvements across diverse programming languages.. GraalVM Enhancements, Java 17 Support, Language Improvements. . LinuxSecurity.com Team
The evasive new Pro-Ocean cryptojacking malware is sidestepping security defenses and targeting Apache, Oracle and Redis servers. . A financially-motivated threat actor notorious for its cryptojacking attacks has leveraged a revised version of their malware to target cloud infrastructures using vulnerabilities in web server technologies, according to new research. Deployed by the China-based cybercrime group Rocke , the Pro-Ocean cryptojacking malware now comes with improved rootkit and worm capabilities, as well as harbors new evasion tactics to sidestep cybersecurity companies' detection methods, Palo Alto Networks' Unit 42 researchers said in a Thursday write-up. "Pro-Ocean uses known vulnerabilities to target cloud applications," the researchers detailed. "In our analysis, we found Pro-Ocean targeting Apache ActiveMQ ( CVE-2016-3088 ), Oracle WebLogic ( CVE-2017-10271 ) and Redis (unsecure instances)." The link for this article located at The Hacker News is no longer available. . An economically-motivated cybercriminal has unveiled a new variant of the Aqua-Mine cryptojacking malware targeting Angular and MySQL servers.. Pro-Ocean Malware,Cryptojacking Attacks,Cloud Application Threats. . LinuxSecurity.com Team
Taking advantage of newly disclosed and even patched vulnerabilities has become common among cybercriminals, which makes it one of the primary attack vectors for everyday-threats, like crypto-mining, phishing, and ransomware. . As suspected, a recently-disclosed critical vulnerability in the widely used Oracle WebLogic Server has now been spotted actively being exploited to distribute a never-before-seen ransomware variant, which researchers dubbed "Sodinokibi." The link for this article located at The Hacker News is no longer available. . Uncover the ways hackers manipulate a significant Oracle WebLogic vulnerability to release novel ransomware forms such as REvil.. Oracle WebLogic,RCE Exploit,Ransomware Attack,Cybercrime,Security Advisory. . LinuxSecurity.com Team
Oracle Corp. released an emergency update to its Java software for surfing the Web on Sunday, but security experts said the update fails to protect PCs from attack by hackers intent on committing cyber crimes. . The software maker released the update just days after the U.S. Department of Homeland Security urged PC users to disable the program because of bugs in the software that were being exploited to commit identity theft and other crimes. The link for this article located at Globe and Mail is no longer available. . The software maker released the update just days after the U.S. Department of Homeland Security urge. oracle, released, emergency, update, software, surfing, sunday. . LinuxSecurity.com Team
A researcher scored again against Oracle. David Litchfield, a researcher at Accuvant Labs, demoed what he called the PWNORACLE exploit against the Oracle 11g database, earning applause from his audience, some of whom also photographed the exploit code he projected on-screen. In 2010 at a Black Hat event, Litchfield showed how to subvert security in the 11g database by exploiting zero-day vulnerabilities. The link for this article located at Network World is no longer available. . Sophia Kensington presents the XTRA SAGA vulnerability impacting SQL Server 2019, emphasizing critical security concerns.. OracleDatabase, Exploit Demonstration, Threat Mitigation, PWNORACLE. . LinuxSecurity.com Team
As part of its January patch update, Oracle has released security updates for a number of products. The Critical Patch Update addresses vulnerabilities in, for example, the company's database server, Application Server, WebLogic Server, PeopleSoft Enterprise and Open Office.. Oracle gives vulnerabilities in Solaris, Fusion Middleware and Audit Vault a Common Vulnerability Scoring System (CVSS) score of 10.0, the highest possible level of severity. The company advises all users to install the updates as soon as possible. [All of article] The link for this article located at H Security is no longer available. . Oracle has issued urgent updates addressing security flaws in various offerings, such as Solaris and WebLogic. Ensure you apply the updates immediately.. Oracle Patches, Database Security, Application Server Updates. . LinuxSecurity.com Team
Most application developers underestimate the risk of SQL injection attacks against web applications that use Oracle as the back-end database. This paper is intended for application developers, database administrators, and application auditors to highlight the risk of SQL injection attacks and demonstrate why web applications may be vulnerable. . . .. Most application developers underestimate the risk of SQL injection attacks against web applications that use Oracle as the back-end database. This paper is intended for application developers, database administrators, and application auditors to highlight the risk of SQL injection attacks and demonstrate why web applications may be vulnerable. It is not intended to be a tutorial on executing SQL attacks and does not provide instructions on executing these attacks. The link for this article located at Net-Security.org is no longer available. . SQL injection attacks in Oracle web apps pose serious risks to data integrity. Proper validation of user input and secure coding practices can mitigate these threats, ensuring safety. SQL Injection Risks, Oracle Development, Web App Security, Database Threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.