Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 462
Alerts This Week
Warning Icon 1 462

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
83

UC Browser: Address Bar Spoofing Threat Exposes Phishing Risk

A bug hunter has discovered and publicly disclosed details of an unpatched browser address bar spoofing vulnerability that affects popular Chinese UC Browser and UC Browser Mini apps for Android. . Developed by Alibaba-owned UCWeb, UC Browser is one of the most popular mobile browsers, specifically in China and India, with a massive user base of more than half a billion users worldwide. According to the details security researcher Arif Khan shared with The Hacker News, the vulnerability resides in the way User Interface on both browsers handles a special built-in feature that was otherwise designed to improve users Google search experience. The link for this article located at The Hacker News is no longer available. . Discover the unaddressed vulnerability in UC Browser applications' address bar that may render users susceptible to phishing schemes.. Address Bar Spoofing, Mobile Browser Flaws, UC Browser Security. . LinuxSecurity.com Team

Calendar%202 May 08, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Router Exploits: Asus, TP-Link, Arcor - Phishing Threat Identified

A whole range of Arcor, Asus and TP-Link routers are vulnerable to being reconfigured remotely without authorisation. On his blog, security researcher Bogdan Calin demonstrates that just displaying an email within the router's own network can have far-reaching consequences: when opened, his specially crafted test email reconfigures the wireless router so that it redirects the user's internet data traffic.. An attacker could exploit this to, for example, redirect unwitting users to a phishing site and harvest their details when they are trying to log into facebook.com. The link for this article located at H Security is no longer available. . An intruder might leverage this vulnerability to mislead unsuspecting individuals to a fraudulent webpage, thereby capturing confidential data.. Router Exploits, Remote Configuration Threats, Asus Vulnerabilities. . Dave Wreski

Calendar%202 Nov 30, 2012 User Avatar Dave Wreski Network Security
83

New 64-Bit Rootkit Steals Banking Credentials Using Browser Exploits

Security researchers have come across a new rootkit that is designed specifically to infect 64-bit Windows systems and steal users' online banking credentials. It's believed to be the first piece of malware of its kind that is capable of compromising x64 systems.. The new rootkit is being used by attackers in Brazil as part of drive-by download attacks and is then used to steal banking credentials after the infection. The malware has the ability to change some of the boot configurations of infected machines and then aims to redirect users to phishing sites. The new rootkit can infect machines running either 32-bit or 64-bit versions of Windows. The drive-by download is accomplished by using a malicious Java applet that is targeted at older versions of the Java Runtime Environment. The applet includes a number of files that each have different jobs to do once they're on an infected PC, including one that disables the Windows User Account Control mechanism. The link for this article located at ThreatPost is no longer available. . The new rootkit is being used by attackers in Brazil as part of drive-by download attacks and is the. security, researchers, across, rootkit, designed, specifically, infect, 64-bit. . LinuxSecurity.com Team

Calendar%202 May 20, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

XSS Issues in Anti-Virus Websites: Phishing Risks Identified

White-hat hackers have uncovered vulnerabilities on the websites of anti-virus firms that created a phishing risk. Cross-site scripting (XSS) bugs of varying severity were found on the websites of Symantec (here), Eset (here) and Panda Security (here) by Team Elite, the white-hat hackers who discovered the flaws. We notified all three firms of the issue and all three responded by plugging the flaws in good time.. Coding errors that give rise to cross-site scripting flaws are endemic in web development. This class of vulnerability might, for example, allow a hacker to present content from third-party sites (pop-ups, malicious scripts etc.) as if it came from a site a surfer was trying to visit and that site alone. As such these flaws are very handy for phishing attacks that attempt to trick the unwary into handing over their credentials to untrusted sites. The link for this article located at The Register UK is no longer available. . Exposed weaknesses within malware protection sites put visitors at risk of deceitful schemes and underscore critical CSRF issues.. Cross-Site Scripting Issues, Anti-Virus Security Flaws, Cybersecurity Risks. . LinuxSecurity.com Team

Calendar%202 Oct 04, 2010 User Avatar LinuxSecurity.com Team Security Projects
83

New SSL Protocol Threat Uncovered by Leviathan Security Group

A Seattle computer security consultant says he's developed a new way to exploit a recently disclosed bug in the SSL protocol, used to secure communications on the Internet. The attack, while difficult to execute, could give attackers a very powerful phishing attack.. Frank Heidt, CEO of Leviathan Security Group, says his "generic" proof-of-concept code could be used to attack a variety of Web sites. While the attack is extremely difficult to pull off -- the hacker would first have to first pull off a man-in-the-middle attack, running code that compromises the victim's network -- it could have devastating consequences. The attack exploits the SSL (Secure Sockets Layer) Authentication Gap bug, first disclosed on Nov. 5. One of the SSL bug's discoverers, Marsh Ray at PhoneFactor, says he's seen a demonstration of Heidt's attack, and he's convinced it could work. "He did show it to me and it's the real deal," Ray said. The link for this article located at Network World is no longer available. . Frank Heidt, CEO of Leviathan Security Group, says his 'generic' proof-of-concept code could be used. seattle, computer, security, consultant, developed, exploit, recently, disclosed. . LinuxSecurity.com Team

Calendar%202 Nov 23, 2009 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Researchers Identify New Phishing Threats with DNS Attacks

Researchers at Google and the Georgia Institute of Technology are studying a virtually undetectable form of attack that quietly controls where victims go on the Internet. The study, set to be published in February, takes a close look at "open recursive" DNS servers, which are used to tell computers how to find each other on the Internet by translating domain names like google.com into numerical Internet Protocol addresses. Criminals are using these servers in combination with new attack techniques to develop a new generation of phishing attacks. What is so new about the possible attacks on DNS servers? We all know they are very vulnerable to attack because they are so visible and important to the Internet. The link for this article located at PC World is no longer available. . The link for this article located at PC World is no longer available.. researchers, google, georgia, institute, technology, studying, virtually, undetectable. . LinuxSecurity.com Team

Calendar%202 Dec 20, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Security Flaws in Financial Sites Expose Customers to Phishing Threats

Nine out of ten financial web sites contain security flaws that could expose them to phishing attacks, according to a study by Next Generation Security Software (NGS). . . .. Nine out of ten financial web sites contain security flaws that could expose them to phishing attacks, according to a study by Next Generation Security Software (NGS). More than 90 per cent of web-based applications audited by NGS over the last year contained 'trivial security' or 'logic flaws' and approximately a third of the applications contained vulnerabilities that could be exploited to extract volumes of confidential customer information from back-end databases. The study also revealed that fraudsters were developing increasingly sophisticated forms of social-engineering to trick customers into giving away financially sensitive information. The link for this article located at vnunet.com is no longer available. . Approximately 90% of financial websites exhibit vulnerabilities that may leave them open to phishing threats.. financial Sites, Security Flaws, Phishing Exposure, Web Application Security. . LinuxSecurity.com Team

Calendar%202 Sep 28, 2004 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200