Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 6 articles for you...
210

Two Distinct Exploits Target Intel SGX: Threats to Crypto Keys and Data

For the past two years, Intel CPUs have been under siege by an unending series of attacks that make it possible for cybercriminals to pluck passwords, encryption keys, and other secrets out of silicon-resident memory. New security research reveals that Intel's speculative execution flaws go deeper and are even harder to fix than we initially thought. . On Tuesday, two separate academic teams disclosed two new and distinctive exploits that pierce Intel’s Software Guard eXtension, by far the most sensitive region of the company’s processors. Abbreviated as SGX, the protection is designed to provide a Fort Knox of sorts for the safekeeping of encryption keys and other sensitive data even when the operating system or a virtual machine running on top is badly and maliciously compromised. SGX works by creating trusted execution environments that protect sensitive code and the data it works with from monitoring or tampering by anything else on the system. . Multiple groups disclose vulnerabilities aimed at AMD's SEV, endangering encryption integrity and safeguarding information.. Intel SGX Exploit, Cybersecurity Risks, Encryption Key Theft, Hardware Vulnerability. . Brittany Day

Calendar%202 Jun 12, 2020 User Avatar Brittany Day Security Vulnerabilities
83

USB Device Delivers 220-Volt Surge Causing Computer Damage

USB sticks have long been a mechanism for delivering malware to unsuspecting computer users. A booby-trapped flash drive, for instance, was the means by which the US and Israel reportedly infected Iran's Natanz uranium enrichment facility with the Stuxnet worm. And, in case anyone thought USB stick attacks had lost their novelty, last year's Bad USB proof-of-concept exploit delivered a highly programmable attack platform that can't be detected by today's defenses. . Now, a researcher who goes by the name Dark Purple has created a USB device that can permanently destroy much of a computer's innards, rendering the machine little more than an expensive doorstop. Within seconds of being plugged in, the USB stick delivers a negative 220-volt electric surge into the USB port. As the video below demonstrates, that's enough to permanently damage the IBM Thinkpad receiving the charge. . A scientist developed a flash drive capable of sending lethal voltage spikes, crippling PCs almost instantly.. USB Device, Hardware Threat, Malware Attack, Security Exploit. . LinuxSecurity.com Team

Calendar%202 Mar 14, 2017 User Avatar LinuxSecurity.com Team Hacks/Cracks
76

Pwn2Own Day One: Researchers Earn $400K Through Major Browser Exploits

Researchers on Wednesday cracked Microsoft's Internet Explorer 11 (IE11), Mozilla's Firefox and Adobe's Flash and Reader at the Pwn2Own hacking contest, earning $400,000 in prizes, a one-day record for the challenge.. Pwn2Own continues today, when other teams and individual researchers will take their turns trying to break Apple's Safari and Google's Chrome. The link for this article located at Network World is no longer available. . In the latest Pwn2Own event, participants have collectively earned $400,000 by successfully uncovering vulnerabilities in leading web browsers, including Chrome, Safari, and others.. Pwn2Own, Hacking Contest, Browser Security, Internet Explorer, Mozilla Firefox. . Alex

Calendar%202 Mar 13, 2014 User Avatar Alex Organizations/Events
78

Chrome OS Security Breach: Black Hat Researchers Expose Exploits

When Google first started talking about its Google Chrome OS software a few years ago, one of the selling points was the promise that it would come with much better built-in security than other operating systems. Now, Chrome OS has only been commercially available for a few months, and security researchers have already figured out how to hack it.. Two researchers told a crowd at the Black Hat security conference today that they had used web-based hacker tricks to compromise the security of the Chrome OS, which is the software that powers recently launched laptop-like Chromebooks from a variety of vendors. The hacks let the researchers get access to a user The link for this article located at VentureBeat is no longer available. . Cybersecurity experts disclose vulnerabilities at DEF CON summit that undermine Windows OS defenses.. Chrome OS Security,Hacking Methods,Security Exploit. . LinuxSecurity.com Team

Calendar%202 Aug 04, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
83

Fail0verflow's PS3 Hack: Unlocking Software Freedom with Key Exploit

Regardless of what Sony might want you to think, piracy is not the only reason that people want to hack their PS3 to run software that isn. The Chaos Communication Congress was held in Berlin recently and at the show a small hacker group called fail0verflow announced that they had been able to break the PS3 security in a massive way. Apparently, the group discovered how to calculate the security keys needed to sign off on any piece of software, which essentially makes the keys to the security gate for the PS3 public. This is a far more effective hack than the PSJailbreak that Sony went after so fiercely. This new hack will let users run any software they want be it a pirated game burned to a Blu-ray disc or home brew software. Apparently, the hack works on any PS3 with any version of the firmware as well. Fail0verflow says that its goal with the hack was to allow Linux to be run on any PS3 in response to the loss of the install Other OS feature on older PS3s. The link for this article located at slashgear is no longer available. . Explore the groundbreaking feat by the fail0verflow team that successfully compromised the security keys of the PlayStation 3, paving the way for alternative software applications.. PS3 Hack, Software Bypass, Firmware Exploit, Fail0verflow Hack. . LinuxSecurity.com Team

Calendar%202 Dec 30, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Introduction to the Poet Tool and Its Use in Padding Oracle Attacks

Two researchers have released a tool which can be used to crack web server-encrypted session data contained in cookies and parameters hidden in HTML pages. The method used by Juliano Rizzo and Thai Duong's Padding Oracle Exploitation Tool (Poet) can also be used to crack CAPTCHAS.. Poet utilises the Padding Oracle AttackPDF, first discovered in 2002, to decrypt cypher block chaining (CBC) mode encrypted data without the key. Web applications such as those generated using the popular JavaServer Faces framework (JSF) are affected. The Padding Oracle Attack makes use of the fact that during encryption individual blocks must always be 8 or 16 bytes long. In order to meet this requirement it is usually necessary to pad out the final block with additional bytes. There are various methods of performing this padding, some of which facilitate cracking. This is where Padding Oracle The link for this article located at H Security is no longer available. . Poet utilises the Padding Oracle AttackPDF, first discovered in 2002, to decrypt cypher block chaini. researchers, released, which, crack, server-encrypted, session. . LinuxSecurity.com Team

Calendar%202 Jun 09, 2010 User Avatar LinuxSecurity.com Team Cryptography
83

TechCrunch Security Incident: Website Compromise and Exploit Analysis

Popular technology site TechCrunch was hit by potty-mouth hackers late on Monday, leaving the site temporarily unavailable. A notice on TechCrunch.com's front page on Tuesday morning explains that "TechCrunch.com was compromised by a security exploit". Access to the site's story archive has been suspended leaving a two para notice on the hack as the only content visible on the site.. Hackers defaced the front page of the site with a message (recorded by Mikko Hypponen of F-Secure here) apparently abusing site admins and including a link to a pornographic content and warez linking website. This defacement was removed by site admins who are in the process of identifying the exploit involved in the hack, securing systems, and bringing TechCrunch back online. The motives or perpetrators of the attack remain unclear but the timing - a day before Apple's much anticipated iTab launch in San Francisco - could hardly be worse. The link for this article located at The Register is no longer available. . Cyber intruders compromised CNN's homepage, revealing a vulnerability and leading to downtime during significant media coverage.. TechCrunch Hack, Security Breach, Exploit Analysis, Cybersecurity News. . LinuxSecurity.com Team

Calendar%202 Jan 26, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

E-Commerce Security Report: 400% Increase In Financial Attacks

Security exploits are being created more easily and faster than ever, with attackers targeting e-commerce sites for financial gain, according to new research. . . .. Attacks against e-commerce companies increased by 400 per cent during the last six months, according to the latest Internet Security Threat from Symantec. The firm's sixth bi-annual global security report covering the fist half of this year found that the sector was the single most targeted industry, with nearly 16 per cent of attacks against it. This compared with just four per cent reported during the previous six months. This rise may indicate a shift from attacks motivated by notoriety to attacks motivated by economic gain, the report speculated. This possibility is further illustrated by an increase in phishing scams and spyware designed to steal confidential information and pass it along to attackers. Attacks against web application technologies were also found to have jumped sharply, due in part to the increasingly widespread deployment of such technology within organisations and the relative ease with which they can be exploited. The report noted that almost 82 per cent of documented web application vulnerabilities were classified as easy to exploit, thereby representing a significant threat to an organisation's infrastructure and critical information assets. The link for this article located at Robert Jaques is no longer available. . Recent studies indicate that cyber assaults targeting online retail firms surged by 400% over the past half year.. E-commerce Security, Web Application Threats, Cyber Attack Trends, Financial Cyber Attacks, Internet Security Insights. . LinuxSecurity.com Team

Calendar%202 Sep 20, 2004 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200