Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
78

FireEye Protects Trade Secrets Amid Apache Security Flaw Disclosures

Cybersecurity firm FireEye has defended the decision to place an injunction against a researcher as the only way to protect trade secrets. Last week, reports surfaced suggesting the cyberforensics firm attempted to prevent the public disclosure of security vulnerabilities discovered within the firm's suite of software. . Felix Wilhelm, a security researcher for ERNW GmBH, disclosed the flaw, which permitted the default use of the root account on Apache servers linked to FireEye clients. If an attacker exploited this flaw, they would be able to compromise servers, leading to data theft and control without permissions issues -- one of the worst and most critical vulnerabilities imaginable. . CyberDefense battles a legal order that seeks to silence a developer disclosing a major Nginx vulnerability endangering user safety.. FireEye Trade Secret, Apache Security Flaw, Cybersecurity Research. . LinuxSecurity.com Team

Calendar%202 Sep 15, 2015 User Avatar LinuxSecurity.com Team Vendors/Products
74

Debian: Local Root Exploit Incident Linked To Sniffed Password Access

A member of the Debian GNU/Linux system administration team believes there is an unknown local root exploit for the Linux kernel circulating in the wild and says it may have been used to compromise four servers belonging to the free software . . . . A member of the Debian GNU/Linux system administration team believes there is an unknown local root exploit for the Linux kernel circulating in the wild and says it may have been used to compromise four servers belonging to the free software project, after initial unprivileged access was gained by using a sniffed password. Debian is a free operating system which uses the Linux kernel; most of the basic OS tools come from the GNU project hence the name GNU/Linux. The break-in was reported on November 21. An ongoing investigation had shown that a sniffed password was used to initially access the server named klecker, one of four which was compromised, a post to one of the Debian mailing lists, by James Troup, said. Troup said that on November 20, it had been noticed that the kernel on a server called master, which hosts the project's bug tracking system, was doing an oops - something which occurs when the kernel code gets into an unrecoverable state. . The Debian GNU/Linux development group warns of a potential local root vulnerability following a breach of credentials that may have impacted their server infrastructure.. Debian Server Security, Root Exploit Incident, Password Sniffing Attack. . Anthony Pell

Calendar%202 Dec 01, 2003 User Avatar Anthony Pell Network Security
77

Linux Kernel 2.2.15 Security Advisory: Local Root Access Risk

A serious bug has been discovered in the Linux kernel that can be used by local users to gain root access. The problem, a vulnerability in the Linux kernel capability model, exists in kernel versions up to and including version 2.2.15. According to Alan Cox, a key member of the Linux developer community, "It will affect programs that drop setuid state and rely on losing saved setuid, even those that check that the setuid call succeeded." To ensure that this vulnerability cannot be exploited by programs running on Linux, Linux users are advised to update to kernel version 2.2.16 immediately. Information on "capabilities" are discussed in the Capabilities FAQ We also recently ran a story on a capabilities-based operating system that is worth reading. . A serious bug has been discovered in the Linux kernel that can be used by local users to gain root access. The problem, a vulnerability in the Linux kernel capability model, exists in kernel versions up to and including version 2.2.15. According to Alan Cox, a key member of the Linux developer community, "It will affect programs that drop setuid state and rely on losing saved setuid, even those that check that the setuid call succeeded." To ensure that this vulnerability cannot be exploited by programs running on Linux, Linux users are advised to update to kernel version 2.2.16 immediately. Information on "capabilities" are discussed in the Capabilities FAQ We also recently ran a story on a capabilities-based operating system that is worth reading. The link for this article located at Sendmail.net --Â Â is no longer available. . A serious bug has been discovered in the Linux kernel that can be used by local users to gain root a. serious, linux, kernel, local, users. . LinuxSecurity.com Team

Calendar%202 Jun 08, 2000 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200