Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
78

BusKill: New USB Cable for Linux Laptops Prevents Theft and Data Loss

A software engineer has designed a so-called USB "kill cable" that works as a dead man's switch to shut down or wipe a Linux laptop when the device is stolen off your table or from your lap in public spaces like parks, malls, and internet cafes. Learn more about this interesting and potentially dangerous new USB cable: . The cable, named BusKill , was designed by Michael Altfield , a software engineer and Linux sysadmin from Orlando, Florida. The idea is to connect the BusKill cable to your Linux laptop on one end, and to your belt, on the other end. When someone yanks your laptop from your lap or table, the USB cable disconnects from the laptop and triggers a udev script [ 1 , 2 , 3 ] that executes a series of preset operations. The link for this article located at ZDNet is no longer available. . Discover BusKill, a USB cable that acts as a dead man’s switch to protect your Linux laptop from theft and data loss.. software, engineer, designed, so-called, cable', works, man', switch. . LinuxSecurity.com Team

Calendar%202 Jan 03, 2020 User Avatar LinuxSecurity.com Team Vendors/Products
83

ATM Skimmers Risk: Threats to Banking Security Identified

An increasing number of ATM skimmers targeting banks and consumers appear to be of the razor-thin insert variety. These card-skimming devices are made to fit snugly and invisibly inside the throat of the card acceptance slot. Here. The bank that shared these photos asked to remain anonymous, noting that the incident is still under investigation. But according to an executive at this financial institution, the skimmer below was discovered inside the ATM The link for this article located at Krebs on Security is no longer available. . The bank that shared these photos asked to remain anonymous, noting that the incident is still under. increasing, number, skimmers, targeting, banks, consumers, appear, razor-thin. . LinuxSecurity.com Team

Calendar%202 Aug 22, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

PayPal Unveils $5 OTP Device To Enhance Identity Security Against Phishing

PayPal announced last week that it will soon support a key fob to provide its customers with two-factor authentication. Costing $5 for personal accounts--and free for business accounts--people can get a One-Time Password (OTP) device that displays a new six-digit code every 30 seconds. The intent is to provide customers with another line of defense against identity theft and the continuous onslaught of PayPal-based phishing attacks. . On the plus side, it's nice to see PayPal being aggressive with security. If people feel they can't trust PayPal, the financing company suffers. A big PayPal breach could also be the only thing that has the potential to crash the eBay party. If PayPal can't be trusted, the natural question consumers will ask is: What about eBay? A security breach at a brick-and-mortar business is bad. A security breach at an e-business can be lethal. Now kudos to PayPal aside, I see a potential problem in the not-too-distant future. Pretty soon, we consumers will be required to have multiple security tokens, smart cards and passwords to do anything online. Imagine a string of security fobs you carry around next to the keys to your minivan and SUV. This could get out of hand rather quickly. . On the plus side, it's nice to see PayPal being aggressive with security. If people feel they can't . paypal, announced, support, provide, customers, two-fac. . LinuxSecurity.com Team

Calendar%202 Jan 21, 2007 User Avatar LinuxSecurity.com Team Privacy
78

Panda Software Network Security Appliances: 8000 Series Launch

Panda Software has launched a series of security network appliance designed to fight viruses, control spam, and filter out non-business or unapproved web surfing. The Panda GateDefender 8000 series includes four devices, designed for companies ranging from small businesses to large enterprises. . . .. Panda Software has launched a series of security network appliance designed to fight viruses, control spam, and filter out non-business or unapproved web surfing. The Panda GateDefender 8000 series includes four devices, designed for companies ranging from small businesses to large enterprises. The devices can scan traffic at up to 30 Mbps and up to 600,000 messages per hour, with a minimum drain on network resources, according to Panda officials. It is designed to protect the corporate network perimeter against viruses, worms, and Trojans, detecting and eliminating malicious code in the six most widely-used protocols: HTTP, FTP, SMTP, POP3, IMAP4 and NNTP. The link for this article located at Preston Gralla is no longer available. . Panda Software has unveiled new cybersecurity solutions to combat malware and control junk emails for organizations. Discover additional details!. Panda Software, Network Security Appliance, Security Device. . LinuxSecurity.com Team

Calendar%202 Oct 01, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
67

iKey 3000 Two-Factor Authentication Device for Remote Access

One-factor authentication (user IDs and password) is still the most widely used method, primarily because it is simple, easy and there are no pieces of hardware to configure. But there are many applications where this is just not secure enough. In two-factor authentication, not only do users need to know a PIN but they also need to possess the correct token.. . .. One-factor authentication (user IDs and password) is still the most widely used method, primarily because it is simple, easy and there are no pieces of hardware to configure. But there are many applications where this is just not secure enough. In two-factor authentication, not only do users need to know a PIN but they also need to possess the correct token. This higher level of security, combined with the token's memory and cryptographic processing capabilities, makes it particularly attractive as a solution for many situations such as digitally signing documents and mails and authenticating the user remotely for access to corporate networks through VPNs. Physically, the iKey 3000 token is small and purple, around the same size as a door key, with a USB plug at one end and a green LED and a key ring hole at the other. The plastic body has a fine finish and is fairly robust under normal circumstances, although the review sample could be prized apart fairly easily to reveal the printed circuit board and chips inside, wrapped in yellow transparent tape. In situations where people wear tokens on a ribbon around their neck, the token should be fairly safe, but where this is not practical, it will probably end up on a key ring with the user's house and car keys - this also solves the problem of arriving at work without it. In these circumstances, the unprotected USB end is susceptible to damage, which if severe enough, could stop the token from fitting into the USB socket on the computer. Inside, there is 32Kb of EEPROM of which 12Kb is used by the operating system, leaving approximately 20Kb - enough space to store a number of X.509 certificates andPGP keys. The iKey has a secure processor chip and runs the Giesecke & Devrient STARCOS SPK 2.3 operating system which has been ITSEC E4 High certified. Random number generation, generation and storage of keys, and resistance to known attacks are also part of the ITSEC E4 High evaluation. Public and private keys are generated on the token, as are all digital authentication and signing operations, thus precluding interception of private keys on the computer's USB port. The USB interface runs at 1.5M Baud, making key operations on a token with a few certificates on it take one to two seconds. The link for this article located at SC Magazine is no longer available. . One-factor authentication (user IDs and password) is still the most widely used method, primarily be. one-factor, authentication, (user, password), still, widely, method, primarily. . LinuxSecurity.com Team

Calendar%202 Oct 17, 2003 User Avatar LinuxSecurity.com Team Cryptography
78

Explore SH7710 RISC Processor For Enhanced Network Security

The SH7710 32bit RISC microprocessor features an IPsec accelerator for fast encryption and communication processing. The device also offers two on-chip Ethernet controllers that enable connection to two Ethernet LANs. Both peripherals make it suitable for security-enabled devices designed . . . . The SH7710 32bit RISC microprocessor features an IPsec accelerator for fast encryption and communication processing. The device also offers two on-chip Ethernet controllers that enable connection to two Ethernet LANs. Both peripherals make it suitable for security-enabled devices designed for use in networks, such as VPN dedicated boxes, home gateway servers, surveillance cameras and IP phones. The SH7710 is based on a SuperH RISC SH3-DSP CPU core that operates at speeds of up to 200MHz and achieves a high processing capability of 260MIPS. The on-chip DSP supports various kinds of middleware, such as a voice codec and echo canceller, and enables fast execution of multimedia related processing such as VoIP. The link for this article located at ElectronicsTalk is no longer available. . Explore the SH7710 RISC microcontroller, equipped with IPsec enhancement for improved data protection and secure networking.. SH7710 RISC, IPsec Accelerator, Encryption Technology, Network Security Solutions. . LinuxSecurity.com Team

Calendar%202 Aug 20, 2003 User Avatar LinuxSecurity.com Team Vendors/Products
78

Explore CrunchBox: Customizable Network Security Device by John Draper

John Draper - The CrunchBox itself is a very proactive device and can be programmed to satisfy any company's security policy. It can also be programmed to do some pretty nasty things, should you want it to. . John Draper - The CrunchBox itself is a very proactive device and can be programmed to satisfy any company's security policy. It can also be programmed to do some pretty nasty things, should you want it to. The link for this article located at TheGuardian.co.uk is no longer available. . Delve into the GuardSphere developed by Emily Carter, an innovative gadget tailored to adapt to diverse compliance regulations.. Network Security, Firewall Device, Security Solutions. . LinuxSecurity.com Team

Calendar%202 Sep 20, 2001 User Avatar LinuxSecurity.com Team Vendors/Products
83

2600 Australia Calls For Secure Systems To Honor Charity Pledge

Hacker advocacy group 2600 Australia has called on a Perth company to honor its promise to donate $US1 million to charity after its network security device remained uncracked after a 30-day public trial. Secure Systems, which has developed a hardware-based network . . . . Hacker advocacy group 2600 Australia has called on a Perth company to honor its promise to donate $US1 million to charity after its network security device remained uncracked after a 30-day public trial. Secure Systems, which has developed a hardware-based network security device called the Silicon Data Vault, said earlier this year it would donate $1 million to the United States-based Make-a-Wish Foundation if the device was cracked within a 30-day period ending at midnight on February 28, but only if the technology was onsold to a developer. It said if the device was cracked, Secure Systems would donate $US10,000 to the charity of the cracker's choice. The link for this article located at Fairfax IT is no longer available. . Cyber collective 404 Down Under pressures Brisbane firm to fulfill community contribution vow after defense mechanism stays intact.. Hacker Advocacy, Charity Challenge, Network Security, Hardware Device. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200