Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Online photography network 500px has forced a password reset for all users after revealing this week that it suffered a data breach last summer. . The link for this article located at InfoSecurity is no longer available. . The link for this article located at InfoSecurity is no longer available.. online, photography, network, 500px, forced, password, reset, users, revealing. . LinuxSecurity.com Team
Computer manufacturer Dell has revealed that earlier this month it discovered that hackers had breached its security and were attempting to access customer details - including names, email addresses, and hashed passwords.. Affected sites are said to include Dell.com, Premier, Global Portal and support.dell.com (‘Esupport’), but it’s important to note that there is no reason to believe that customers’ financial information has been accessed. The link for this article located at Graham Cluley is no longer available. . Cyber intruders infiltrated Dell's defenses, resulting in a mandatory password change for users and raising alarms about potential unauthorized personal information exposure.. Dell Security Breach, Customer Data Compromise, Cybersecurity Measures. . LinuxSecurity.com Team
For me . On Tuesday, Hyatt alerted some 200 customers that their Gold Passport account had been flagged for suspicious activity, while the other 18 million members have had their account passwords reset out of an abundance of caution. The link for this article located at CSO Online is no longer available. . Marriott notified 150 patrons regarding compromised Bonvoy accounts and initiated a password reset as a precautionary measure.. Hyatt Gold Passport, Customer Security, Account Safety, Suspicious Activity. . Dave Wreski
Forumware giant vBulletin.com has admitted that it's been turned over by hackers who made off with customer user IDs and encrypted passwords.. vBulletin said it was resetting account passwords in response the the breach, which it blamed on a series of "sophisticated attacks": The link for this article located at The Register UK is no longer available. . Leading forum platform vBulletin.com triggers password resets following a security breach where attackers accessed user identifiers and encrypted passwords.. vBulletin Breach, Password Security, Hacking Response. . LinuxSecurity.com Team
Evernote and its 50 million-user population are having a bad week. The productivity software-as-a-service issued a systemwide password reset for all of its users on Saturday after a hacker or group of hackers broke into its user database and swiped various bits of user information, including usernames, emails and passwords.. It's another weapon in the arsenal of cloud skeptics, who tend to point at breaches like this as proof the cloud is not secure. Of course, that's ridiculous, as these breaches are less common than attacks or theft within the four walls of a business. Still, Evernote is coming under fire The link for this article located at Read this full article is no longer available. . It's another weapon in the arsenal of cloud skeptics, who tend to point at breaches like this as pro. evernote, million-user, population, having, productivity, software-as-a-se. . LinuxSecurity.com Team
Twitter users -- especially those with desirable handles -- risk having their accounts stolen, according to one recently hacked user who says there's a fundamental vulnerability in the service's security system. . According to Daniel Dennis Jones, whose account, @blanket, was recently hijacked, Twitter's password reset process allows hackers to attempt a more wide-ranging brute force approach to breaking into accounts than other services with more restrictive systems. The link for this article located at CNET is no longer available. . According to Daniel Dennis Jones, whose account, @blanket, was recently hijacked, Twitter's password. twitter, users, especially, those, desirable, handles, having, their, accounts, stolen. . LinuxSecurity.com Team
User data for some registered developers of Mozilla Add-ons was temporarily exposed by mistake on a Mozilla server. Mozilla has disabled those users' accounts until they reset their passwords.. As a registered user, I received an e-mail last night from Chris Lyon, Director of Infrastructure Security at Mozilla, informing me of the breach, which occurred on December 17 and was discovered by "a 3rd party," identified as a security researcher in a subsequent blog post on the matter. A file was on the server containing "...a partial representation of the users database from addons.mozilla.org. The file included email addresses, first and last names, and an md5 hash representation of your password." The letter stated that, apart from the referenced 3rd party, only Mozilla staff had downloaded the file before it was removed. They have also identified how the file came to be on the server and have take steps to prevent it being repeated. The link for this article located at PC Magazine Blogs is no longer available. . Mozilla inadvertently revealed information related to developer accounts, prompting necessary password resets and other critical actions to bolster overall security.. Developer Data Breach, Mozilla Security Update, Password Reset Process. . LinuxSecurity.com Team
Twitter reset passwords for an unknown number of users on Tuesday whose accounts appeared to have been compromised via phishing. "As part of Twitter's ongoing security efforts, we reset passwords for a small number of accounts that we believe may have been compromised offsite," the company said in a statement.. Some Twitter users apparently "used their Twitter username and password to sign up for an untrusted third-party application which then posted Tweets to their account," a spokeswoman said. "While we're still investigating and ensuring that the appropriate parties are notified, we do believe that the steps we've taken should ensure user safety," the statement said. "We'll continue to provide updates as warranted at @safety and @spam." Users who want information on what to do if their accounts have been compromised can visit this page and learn how to use Twitter safely here. Update 12:05 p.m. PST: In response to a reader e-mail suggesting that there may have been a breach at Twitter, Del Harvey, trust and safety director at Twitter, said there was no data breach at the company. "We've noticed a high correlation of users with accounts on third-party Torrent sites and users' accounts that we believe are compromised. It's possible that this person falls into this category. It's not a result of a data breach on Twitter." [All of article] The link for this article located at CNET is no longer available. . LinkedIn initiates password changes for members impacted by fraudulent activities, bolstering user protection during active inquiries.. Password Reset, Phishing Alert, User Safety. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.