Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Linus Torvalds has warned of a nasty security bug in the first release candidate (RC) of the Linux kernel 5.12, which he has deemed a "double ungood" that can have catastrophic consequences for a computer's filesystem. . Linus Torvalds has issued a warning to open-source developers to avoid the first release candidate (RC) of the Linux kernel 5.12. Linux kernel 5.12 was released on time despite the snow storms that lashed Oregon and knocked out power to Torvalds' home for the better part of a week . Torvalds and his thousands of contributors managed to get version 5.12 out on time, but he now says RC 5.12 is a "double ungood" that can have catastrophic consequences for a computer's filesystem. . Avoid using Linux kernel 5.12 RC1; Linus Torvalds warns of a significant flaw in the file system security.. Linux Kernel Threat, Filesystem Bug, Open Source Warning. . Brittany Day
Two days after Cisco patched a severe vulnerability in a popular brand of SOHO routers, and one day after the publication of proof-of-concept code, hackers have started scans and attacks exploiting the said security bug to take over unpatched devices. . The vulnerability , tracked asCVE-2019-1663, was of note when it came out on February 27 because it received a severity score from the Cisco team of 9.8 out of a maximum of 10. The link for this article located at ZDNet is no longer available. . The vulnerability, tracked asCVE-2019-1663, was of note when it came out on February 27 because it r. cisco, patched, severe, vulnerability, popular, brand, routers. . LinuxSecurity.com Team
In early December, Facebook’s developer team declared the discovery of a security bug that gave developers access to photos users hadn’t shared on their timeline, including photos they had posted in Facebook Marketplace or Stories.. More worryingly, apps could find access to images users might have uploaded to Facebook but didn’t post anywhere. For example, this could be pictures you uploaded to a profile update you abandoned and did not complete. These are pictures that users haven’t shared with anyone. The link for this article located at The Next Web is no longer available. . Applications were able to view photos that users had uploaded without publicly sharing them on Facebook. This raised serious issues regarding privacy and safety.. Facebook Privacy Breach, Security Bug, Data Exposure, Image Access, Software Flaw. . LinuxSecurity.com Team
An exploit that fetched a teenage hacker a $60,000 bounty targeted six different security bugs to break out of the security sandbox fortifying Google's Chrome browser. . The extreme lengths taken in March by a hacker identified only as Pinkie Pie underscore the difficulty of piercing this safety perimeter. Google developers have erected their sandbox to separate Web content from sensitive operating-system functions, such as the ability to read and write files to a hard drive. Such sandboxes are designed to minimize the damage that can be done when attackers identify and exploit buffer overflows and other types of software bugs that inevitably find their way into complex bodies of code.. The extreme lengths taken in March by a hacker identified only as Pinkie Pie underscore the difficul. exploit, fetched, teenage, hacker, bounty, targeted, different, security. . LinuxSecurity.com Team
Sun Microsystems has fixed a pair of security bugs in Java that could be exploited by attackers to take over computers running Windows, Linux and Solaris. The flaws are "highly critical," security monitoring company Secunia said in an advisory posted Tuesday. Flaws that get that ranking--one notch below Secunia's most severe "extremely critical" rating--are typically remotely exploitable and can lead to full system compromise. . Both flaws affect the Java Runtime Environment, or JRE. This is the Java software many computer users have on their system to run Java applications. The bugs could allow a Java application to read and write files or execute applications on a victim's computer, Sun said in two separate security advisories released Monday. One is a general flaw in the JRE, while the other is specific to Java Web Start, a technology to load Java applications over a network such as the Internet. The flaws could be exploited through a malicious Web site, according to alerts from the French Security Incident Response Team, which rates both issues "critical." Sun said it wasn't aware of any exploits or attacks using the flaws.. Vulnerabilities in the Java Runtime Environment can enable remote attackers to exploit systems, potentially granting them complete control and jeopardizing user security.. Java Runtime Environment, Remote Exploits, Critical Threats. . LinuxSecurity.com Team
The Mozilla Foundation, maker of the Firefox web browser and Thunderbird e-mail application, is offering a $500 (£275) bounty to users who identify and report bugs found in its open-source software. . . .. The Mozilla Foundation, maker of the Firefox web browser and Thunderbird e-mail application, is offering a $500 (£275) bounty to users who identify and report bugs found in its open-source software. Foundation staff will determine who earns the cash prize. Mozilla launched the initiative with funding from Linux software developer Linspire and internet entrepreneur Mark Shuttleworth. The goal of the Mozilla Security Bug Bounty Programme is to encourage users to identify and report security bugs. "This programme reflects our commitment to protecting consumers from malicious actors," said Mitchell Baker, president of the Mozilla Foundation. "Recent events illustrate the need for this type of commitment. While no software is immune from security vulnerabilities, bugs in open-source projects are often identified and fixed more quickly." Mitchell said the programme will help Mozilla unearth security issues earlier and get a head start on correcting vulnerabilities before they are exploited by malicious hackers. The Mozilla Foundation is soliciting donations for the programme from its users and supporters. The link for this article located at ComputerWeekly.com is no longer available. . The Mozilla Foundation offers a reward of $500 for those who identify and report security vulnerabilities in both the Firefox and Thunderbird applications.. Mozilla Foundation, Bug Bounty, Open Source Security, Firefox, Thunderbird. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.