Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 5 articles for you...
210

CentOS 7 and RHEL 7 Important Kernel Update: 11 Critical Fixes

CentOS Linux 7 and Red Hat Enterprise Linux (RHEL) 7 are vulnerable to over a dozen kernel bugs. Red Hat has issued an important security update mutigating these flaws - patch now! . The new kernel security and bug fix update has been rated by Red Hat Product Security as having a security impact of ‘Important’ and affects the kernel packages in all supported Red Hat Enterprise Linux 7 operating system editions, as well as the CentOS Linux 7 operating system series. The update addresses 11 security vulnerabilities, including CVE-2020-25705, a flaw discovered in the ICMP global rate limiter that could allow an off-path remote attacker to bypass source port UDP randomization and facilitate attacks on UDP based services that depend on source port randomization. The link for this article located at 9 to 5 Linux is no longer available. . Crucial kernel security patch for CentOS 7 and RHEL 7 addresses 11 vulnerabilities categorized as critical by Red Hat. Take action immediately!. Kernel Security Update, CentOS 7, RHEL 7, Bug Fixes, Red Hat Update. . Brittany Day

Calendar%202 Mar 23, 2021 User Avatar Brittany Day Security Vulnerabilities
210

Google Chrome Urgent Update: CERT-In Advises To Avoid DoS Attacks

CERT-In is urging Google Chrome users to upgrade immediately to the new version of the Chrome browser to protect sensitive information on their machines and prevent contact spoofing and denial of service (DoS) attacks exploiting Chrome vulnerabilities. . The government's cybersecurity agency has warned Google Chrome users in the country to immediately upgrade to the new Chrome browser version to avoid remote hackers from intruding into their machines. Google has released Chrome 84.0.4147.89 upgrade that contains 38 fixes and improvements against vulnerabilities. "Multiple vulnerabilities have been reported in Google Chrome that could allow remote attacker to execute arbitrary code, bypass security restrictions, access sensitive information, contact spoofing attack and denial of service (DoS) attack on the targeted system," the Computer Emergency Response Team-India (CERT-In) warned in its latest advisory. . The Cyber Security Agency has alerted Google Chrome users to promptly update to the newest version for enhanced protection.. Google Chrome, CERT-In, browser security, software update, remote attacks. . Brittany Day

Calendar%202 Jul 21, 2020 User Avatar Brittany Day Security Vulnerabilities
210

Exim: Critical Issue With Remote Attack Potential Uncovered

Are you an Exim user? A critical security vulnerability has been discovered and fixed in the popular open-source Exim email server software, which could allow a remote attacker to simply crash or potentially execute malicious code on targeted servers. Learn more about the vulnerability in a great The Hacker News article: . Exim maintainers today released an urgent security update—Exim version 4.92.3—after publishing an early warning two days ago, giving system administrators an early head-up on its upcoming security patches that affect all versions of the email server software from 4.92 up to and including then-latest version 4.92.2. Exim is a widely used, open source mail transfer agent (MTA) developed for Unix-like operating systems like Linux, Mac OSX or Solaris, which runs almost 60 percent of the Internet's email servers today for routing, delivering and receiving email messages. The link for this article located at The Hacker News is no longer available. . A significant vulnerability in Postfix exposes mail servers to external threats. A prompt update has been issued to address this issue.. Exim Vulnerability, Email Server Security, Remote Exploits. . Brittany Day

Calendar%202 Sep 30, 2019 User Avatar Brittany Day Security Vulnerabilities
79

Aircraft Hacking Insights: Hugo Teso at HITB2013AMS Conference

The Hack in the Box (#HITB2013AMS) security conference in Amsterdam has a very interesting lineup of talks [pdf]. One that jumped out was the Aircraft Hacking: Practical Aero Series presented by Hugo Teso, a security consultant at n.runs in Germany. . According to the abstract, The link for this article located at Computer World is no longer available. . An in-depth exploration of aviation cybersecurity showcased during the HITB2013AMS summit in Amsterdam by security expert Hugo Teso.. Aircraft Hacking, Android Exploit, Cyber Threats. . LinuxSecurity.com Team

Calendar%202 Apr 11, 2013 User Avatar LinuxSecurity.com Team Security Projects
78

Chrome: Critical Update For Remote Attacks And Flash Player Patch

As part of its bug bounty program, Google doled out $6,837 to purchase the rights to information on the Chrome security vulnerabilities. Google has shipped another Chrome browser update to fix several gaping security holes.. The most serious of the patched vulnerabilities could allow remote hacker attacks via specially rigged Web sites.follow Ryan Naraine on twitter. The update also includes a new version of Adobe Flash Player, which was recently updated to cover multiple remote code execution vulnerabilities. The link for this article located at ZDNet Blogs is no longer available. . The most serious of the patched vulnerabilities could allow remote hacker attacks via specially rigg. bounty, program, google, doled, purchase, rights, information. . LinuxSecurity.com Team

Calendar%202 Feb 17, 2012 User Avatar LinuxSecurity.com Team Vendors/Products
78

Time Warner: Routers Under Siege, Exposing 65,000 Users to Remote Attacks

A blogger who stumbled across a vulnerability in more than 65,000 Time Warner Cable customer routers says the routers are still vulnerable to remote attack, despite claims by the company last week that it patched the routers.. Last Tuesday, David Chen, an internet startup-founder, published information about the vulnerability in Time Warner The link for this article located at Wired is no longer available. . Last Tuesday, David Chen, an internet startup-founder, published information about the vulnerability. blogger, stumbled, across, vulnerability, warner, cable, customer, routers. . LinuxSecurity.com Team

Calendar%202 Oct 27, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
74

Home Routers: Remote Attacks Through Malicious JavaScript Exploit

They have demonstrated that users could open up their router's traffic as a result of visiting a web page loaded with malicious javascript. The researchers said, "Settings on the router can be changed, including the DNS servers used by members of small, quickly erected internal networks. The attacks do not exploit any vulnerabilities in the user's browser. Instead, all they require is that the browser run JavaScript and Java Applets." While the threat to home routers is real, said the researchers, no actual attacks have so far taken place. Users would also first have to be persuaded to visit a malicious website for any attack to take place. . . Individuals face dangers since residential networking devices can be exploited remotely through harmful codes embedded in websites.. home routers security, remote attack prevention, javascript risks. . Benjamin D. Thomas

Calendar%202 Feb 20, 2007 User Avatar Benjamin D. Thomas Network Security
83

Remote Attack on Linux Kernel: Zero IP ID Exploit Threats

I've recently stumbled upon an interesting behaviour of some Linux kernels that may be exploited by a remote attacker to abuse the ID field of IP packets, effectively bypassing the zero IP ID in DF packets countermeasure implemented since 2.4.8 (IIRC). . The link for this article located at is no longer available. . The link for this article located at is no longer available.. recently, stumbled, interesting, behaviour, linux, kernels, exploited. . LinuxSecurity.com Team

Calendar%202 Mar 15, 2006 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200