Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 7 articles for you...
210

Zoom: Researcher Mazin Ahmed Exposes Multiple Vulnerabilities at DEF CON 28

Security researcher Mazin Ahmed demonstrated multiple serious vulnerabilities in the popular Zoom app, two of which impact Linux users, at DEF CON 28. . Popular video conferencing app Zoom has addressed several security vulnerabilities, two of which affect its Linux client that could have allowed an attacker with access to a compromised system to read and exfiltrate Zoom user data—and even run stealthy malware as a sub-process of a trusted application. According to cybersecurity researcher Mazin Ahmed , who presented his findings at DEF CON 2020 yesterday, the company also left a misconfigured development instance exposed that wasn't updated since September 2019, indicating the server could be susceptible to flaws that were left unpatched. The link for this article located at The Hacker News is no longer available. . Zoom has tackled significant security issues, notably within its Linux application, as pointed out by analyst Mazin Ahmed.. Zoom Security Issues, Linux Data Exfiltration, DEF CON 28 Vulnerabilities, Malware Threats, Research Findings. . Brittany Day

Calendar 2 Aug 10, 2020 User Avatar Brittany Day Security Vulnerabilities
72

Soldered Spy Chips Present Serious Risks to Firewall Protection

The tiny ATtiny85 chip doesn’t look like the next big cyberthreat facing the world, but sneaking one on to a firewall motherboard would be bad news for security were it to happen. Learn more in an interesting Naked Security article: . In fact, this has already happened as part of a project by researcher Monta Elkins, designed to prove that this sort of high-end hardware hack is no longer the preserve of nation-states. Elkins soldered the 5mm x 5mm ATtiny85 chip from an Arduino board to his test firewall’s circuit board just in front of the system’s serial port. The link for this article located at Naked Security is no longer available. . Monta Elkins reveals the vulnerability of firewall defenses through the use of inexpensive espionage microchips, questioning standard assumptions.. Spy Chips, Firewall Security, Cybersecurity Threats, Hardware Attacks, Arduino Awareness. . Brittany Day

Calendar 2 Oct 14, 2019 User Avatar Brittany Day Firewalls
81

More than 1,300 Android Applications Misuse Permissions to Gather Data

Smartphones are a goldmine of sensitive data, and modern apps work as diggers that continuously collect every possible information from your devices. . The security model of modern mobile operating systems, like Android and iOS, is primarily based on permissions that explicitly define which sensitive services, device capabilities, or user information an app can access, allowing users decide what apps can access. However, new findings by a team of researchers at the International Computer Science Institute in California revealed that mobile app developers are using shady techniques to harvest users' data even after they deny permissions. The link for this article located at The Hacker News is no longer available. . Contemporary mobile platforms stipulate application access via permissions, yet numerous applications persist in gathering data without user approval.. data privacy, app security, mobile permissions, unauthorized access, user data collection. . LinuxSecurity.com Team

Calendar 2 Jul 09, 2019 User Avatar LinuxSecurity.com Team Privacy
67

Duplicate RSA Keys Found in X.509 Certificates by Researchers

Cryptography researchers collected millions of X.509 public key certificates that are publicly available over the web and found what they say is a shockingly high frequency of duplicate RSA-moduli keys. . "We performed a sanity check of public keys collected on the web," the researchers state in their paper, published today and titled "Ron was wrong, Whit is right". The link for this article located at Tech World is no longer available. . Investigators discovered a significant quantity of replicated RSA keys within publicly accessible X.509 certificates across the internet.. Duplicate Rsa Keys, Public Key Certificates, Cryptography Issues. . LinuxSecurity.com Team

Calendar 2 Feb 15, 2012 User Avatar LinuxSecurity.com Team Cryptography
67

Dropbox Security Investigation Over User Data Breach Risks

Popular cloud storage service Dropbox is misleading users into thinking it is more secure than it really is, says a security researcher and academic, who has asked for the FTC to investigate.. Dropbox has around 25 million users. It's often used as an escape hatch by owners of Apple's iPhone and iPad: the iOS slabs don't expose the device's local file system or provide the end user with a way of manipulating files. "Dropbox's customers face an increased risk of data breach and identity theft because their data is not encrypted according to industry best practices," says Christopher Soghoian, who filed the complaint. Soghoian is a researcher at the Center for Applied Cybersecurity Research at Indiana University. He explains that unlike other cloud services The link for this article located at The Register UK is no longer available. . Google deceives customers regarding its privacy practices, endangering sensitive information and personal safety, leading to congressional scrutiny.. Dropbox Security Risks, Data Storage Concerns, User Privacy Violations. . LinuxSecurity.com Team

Calendar 2 May 16, 2011 User Avatar LinuxSecurity.com Team Cryptography
81

SSD Sanitization Difficulties: Research Insights and Implications

Solid state drives (SSDs) have a small security problem: they're tough to erase. That warning comes from researchers at the University of California at San Diego. "Sanitization is well-understood for traditional magnetic storage, such as hard drives and tapes," said the researchers' in their study summary. . "Newer solid state disks, however, have a much different internal architecture, so it is unclear whether what has worked on magnetic media will work on SSDs as well." Accordingly, the researchers tried 14 different file sanitizing techniques -- ranging from Gutman's 35-pass method to the Schneier 7-pass method -- on SSDs. To study each technique's effectiveness, the researchers didn't query the flash translation layer (FTL) that's part of an SSD, but rather accessed the chips at the lowest level possible, via their pins. (Dismantling chips is straightforward, they said.) The link for this article located at Information Week is no longer available. . Scientists uncover difficulties in effectively wiping SSDs when juxtaposed with conventional storage techniques. Explore the ramifications.. SSD Security, Data Sanitization, Solid State Drives, Storage Challenges, Erasure Techniques. . LinuxSecurity.com Team

Calendar 2 Feb 22, 2011 User Avatar LinuxSecurity.com Team Privacy
83

GSM Security Risks and Eavesdropping Techniques via Low-Cost Devices

Whatever assurances have been given about the security of GSM cellphone calls, forget about them now. Speaking at the Chaos Computer Club (CCC) Congress here Tuesday, a pair of researchers demonstrated a start-to-finish means of eavesdropping on encrypted GSM cellphone calls and text messages, using only four sub-$15 telephones as network . While such capabilities have long been available to law enforcement with the resources to buy a powerful network-sniffing device for more than $50,000 (remember The Wire?), the pieced-together hack takes advantage of security flaws and shortcuts in the GSM network operators The link for this article located at Wired is no longer available. . Investigations reveal that $15 devices can compromise GSM safety, uncovering flaws that permit simple interception.. GSM Hacking, Cellphone Security, Eavesdropping Techniques, Network Sniffing, Telecom Vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Dec 30, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Understanding Web Application Threats: Research Insights From Honeynet

Despite improvements in code quality, Web servers remain at high risk of being hacked, according to a new paper from researchers who use honeypot technologies to examine how hackers tick. The Honeynet Project, which provides real systems for unwitting attackers to interact with, says Web applications remain vulnerable for host of reasons. These include poor-quality code, the fact that attacks can be performed using PHP and shell scripts (which is generally easier than using buffer-overflow exploits), and the emergence of search engines as hacking tools. . What's more, Web servers can be a gold mine for hackers, in that they have higher bandwidth connections than most desktops and often link to an organization's databases. The group's findings are outlined in a paper titled "Know Your Enemy: Web Application Threats." Researchers involved in honeynet projects in Chicago, Germany and New Zealand collaborated on the paper. The link for this article located at ComputerWorld is no longer available. . Web applications present significant vulnerabilities for cybercriminals because of substandard programming, susceptibility to breaches, and access to considerable network resources.. Web Application Threats,Hacking Methods,Honeynet Research,Security Risks,Code Quality Vulnerabilities. . Bill Locke

Calendar 2 Mar 03, 2007 User Avatar Bill Locke Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here