Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 438
Alerts This Week
Warning Icon 1 438

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 11 articles for you...
74

I2P 2.5.0: Security Enhancements and New Features for Linux Users

The recent release of I2P 2.5.0 , an anonymous P2P network that protects against online censorship, surveillance, and monitoring, has brought a slew of improvements and new features that will certainly intrigue security practitioners. This release aims to enhance user-facing features while addressing compatibility and security issues. . Let's examine the changes introduced in this release and their security implications for Linux admins and I2P users. What's New In I2P 2.5.0? Why Are These Changes Significant? The updates to I2PSnark and SusiMail are particularly noteworthy. Users of I2PSnark can now enjoy the added convenience of searching through torrents, and the bug fixes have ensured better compatibility with other I2P torrent clients such as BiglyBT and qBittorrent . Meanwhile, SusiMail has received support for Markdown formatting in emails and the ability to drag-and-drop attachments, which will likely streamline the user experience. These improvements could be especially valuable for Linux admins and sysadmins, as they often rely on secure communication tools like SusiMail for daily operations. Furthermore, introducing "Keepalive" support for tunnels created with the Hidden Services manager promises performance enhancements and better compatibility with web technologies, potentially making I2P sites more sophisticated. This should spark the interest of internet security enthusiasts, as it hints at the prospect of improved and more secure web applications within the I2P network. It is critical to emphasize the impact of this release on the user, particularly from a security perspective. The improvements made to NetDB to enhance its resilience against spam and suspicious messages, along with rectifying the isolated piercing event, are an essential facet of this release. These fixes could mitigate security vulnerabilities and prevent potential breaches , which is vital for infosec professionals and other security practitioners. Looking ahead, it's crucial to consider thelong-term consequences of these improvements. How will these changes impact the network's overall security posture? Could the added features in I2PSnark and SusiMail lead to new attack vectors? Furthermore, how will these updates affect the global reach of I2P? These are questions that Linux admins, infosec professionals, and internet security enthusiasts should ponder. You can download I2P 2.5.0 for Linux here. Our Final Thoughts on the I2P 2.5.0 Release I2P 2.5.0's release signifies a substantial step forward, particularly in enhancing user-facing features and addressing network security. The implications of these upgrades extend beyond just technical improvements, impacting the everyday experiences of security practitioners who rely on the I2P network. Witnessing such continuous dedication to evolving and improving I2P is commendable, and the security community should engage critically with these developments. . The I2P 2.5.0 release brings key improvements to enhance anonymity and security, ideal for Linux administrators focused on protecting their systems and data. I2P Release Updates, P2P Software Improvements, Network Security Enhancements, Linux Admin Security, Software Security Updates. . Brittany Day

Calendar%202 Apr 22, 2024 User Avatar Brittany Day Network Security
79

OpenBSD 7.3 Release: Enhanced Security And Disk Encryption Capabilities

Theo de Raadt has released OpenBSD 7.3 as the 54th release for this BSD operating system project. . OpenBSD 7.3 has tons of improvements from new hardware support to new kernel innovations and security improvements to various other updates. OpenBSD 7.3 is also notable for finally adding guided disk encryption to its installer. Downloads and for a complete list of the hundreds of changes making up OpenBSD 7.3 can be found via the official release announcement on OpenBSD.org . The link for this article located at Phoronix is no longer available. . OpenBSD 7.3 brings enhanced hardware compatibility, upgrades to the kernel, and offers an interactive disk encryption option in its setup process.. OpenBSD 7.3, Disk Encryption, AMD RDNA3, Security Innovations. . LinuxSecurity.com Team

Calendar%202 Apr 12, 2023 User Avatar LinuxSecurity.com Team Security Projects
209

C++ Programming's Evolution Towards Memory Safety and Security Enhancements

There's been a shift towards 'memory safe' languages. So, can updates to C++ help it catch up in the eyes of developers? . A group working on the development of the hugely popular C++ programming language has outlined a path to make the language "memory safe" -- just like its younger rival, Rust. Rust has been embraced by Microsoft , AWS , Meta , Google's Android Open Source Project , the C++-dominated Chromium project (sort of) , the Linux kernel , and many more, which has helped to reduce memory security flaws . Even the National Security Agency (NSA) has recommended developers make a strategic shift away from C++ in favor C#, Java, Ruby, Rust, and Swift. Widespread warnings about C++ security have prompted moves to plot a path forward for the "Safety of C++", detailed in a paper by a group including Bjarne Stroustrup, the creator of C++, for the C++ Standards Committee Working Group 21 (WG21), which was released this month. . A team is charting a course for enhancing memory integrity within C++, tackling past vulnerabilities in software engineering.. Memory Safety, C++ Trends, Software Security, Development Insights. . Brittany Day

Calendar%202 Jan 23, 2023 User Avatar Brittany Day Security Trends
76

OpenSSF Q1 2023 Summary: Insights from Log4Shell and Security Upgrades

“Log4j has been around for 20 years; it’s become embedded into nearly every meaningful Java application; and the Log4Shell event led to compromises in everything from iCloud to physical security systems. Moreover, malware groups are continuing to exploit unpatched Log4j instances. We will likely see additional Log4Shell-like events unless we address its root issues.” . Happy 2023 Linux Foundation members and open source community readers! Recently at the Open Source Security Foundation, we shared several notable updates you won’t want to miss, including: A retrospective on Log4Shell in which Brian Behlendorf, General Manager of the OpenSSF, takes a look at what we’ve learned over the past year related to the core issues around software supply chain security and vulnerability disclosure, the unique nature of securing open source software (OSS), and the best techniques for improving OSS security moving forward. News about our global engagement efforts focused on collaborating with leaders in the public and private sectors to further the ecosystem understanding of open source software security. A recap of our year that highlighted the many accomplishments of OpenSSF working groups and projects. As we reflect on the past year and forge ahead, we invite you to get involved and help make the OSS ecosystem more secure. . Investigate essential advancements in open-source software (OSS) security, reflecting on insights gained from the Log4Shell incident and strategies for future security improvements.. OpenSSF, OSS Security Reflections, Software Vulnerabilities, Security Advances. . Brittany Day

Calendar%202 Jan 16, 2023 User Avatar Brittany Day Organizations/Events
79

Upgrade From Linux 5.14 EOL To 5.15 LTS For Enhanced Security

The time has come to say goodbye to another Linux kernel series, Linux 5.14, which is now end-of-life and it won’t receive further updates, so it’s time to upgrade to a newer kernel branch. . Linux kernel 5.14 was released almost three months ago, on August 30th, 2021, in celebration of Linux’s 30th anniversary, and it introduced quite some interesting features, starting with better protection against those pesky Spectre vulnerabilities and continuing with much-enhanced support for AMD GPUs. Today, November 21st, renowned Linux kernel developer Greg Kroah-Hartman announced the release of Linux kernel 5.14.21 as the twenty-first maintenance update and also the last in the series. Yes, that’s right, Linux 5.14 is now marked as EOL (End of Life) on the kernel.org website and it will no longer be supported. The link for this article located at 9 to 5 Linux is no longer available. . The Linux kernel version 5.14 has now reached its end of life, prompting users to transition to the 5.15 LTS to ensure enhanced security measures and additional features.. Linux Kernel Upgrade, Kernel Support, Maintenance Update. . LinuxSecurity.com Team

Calendar%202 Nov 23, 2021 User Avatar LinuxSecurity.com Team Security Projects
215

Cinnamon 5.0: New Update Tools, Stability Enhancements For Linux Mint

Cinnamon 5.0 has been released with many improvements that make the desktop environment more secure, stable and reliable, including new GUI and CLI tools for checking, listing, and performing updates of Cinnamon Spices. . Cinnamon 5.0 comes with many improvements to make Linux Mint’s default desktop environment more stable and reliable, including a memory limit mechanism so that it won’t eat up all the RAM on your personal computer. One of the biggest change in Cinnamon 5.0 is the inclusion of new GUI and CLI tools for checking, listing, and performing updates of Cinnamon Spices, which includes applets, desklets, extensions, and themes. This means that you no longer have to rely on a third-party tool or go into Settings to update your Spices. The link for this article located at 9 to 5 Linux is no longer available. . Cinnamon 5.0 brings enhancements for reliability, protection, and fresh utilities for managing Spices in Linux Mint.. Cinnamon 5.0, Linux Mint, desktop improvements, software updates, GUI tools. . Brittany Day

Calendar%202 Jun 04, 2021 User Avatar Brittany Day Desktop Security
78

Parrot OS 4.11: Security-Focused Distro with Linux 5.10 for Pentesting

Parrot OS is an excellent privacy-focused distro for pentesters, reverse engineers and security researchers. Version 4.11 offers numerous security improvements that make the OS even more impressive. . Linux distribution based on the Debian test Parrot OS Specially designed for penetration testing and vulnerability assessment, thus competing with the best dog Kali Linux 2021.1. The operating system considers itself a forensic distribution and detects vulnerabilities in systems and networks. All updates to the Debian test repository, including the upcoming Debian 11 (“Bulsey”), until March 2021 and already included in the new version 4.11, include the latest version of the desktop and the basic computer kernel Linux 5.10 LTS. The change to Linux 5.11 is immediate. The link for this article located at The Press Stories is no longer available. . Discover Parrot OS 4.11, tailored for penetration testers and security professionals, built on Linux 5.10, featuring advanced security enhancements.. Parrot OS, Pentesting Tools, Security Improvements, Debian Based, Privacy-Focused Linux. . LinuxSecurity.com Team

Calendar%202 Mar 30, 2021 User Avatar LinuxSecurity.com Team Vendors/Products
79

Google Funds Developers For Linux Kernel Security Enhancements

Google has demonstrated serious concern about the security of Linux and open-source code, and is sponsoring a pair of full-time developers to work on the kernel's security. . The internet giant builds code from its own repositories rather than downloading outside binaries, though given the pace at which code is being added to Linux, this task is non-trivial. Google's open-source security team lead Dan Lorenc spoke to The Register about its approach, and why it will not use pre-built binaries despite their convenience. But first: the two individuals full-time sponsored by Google are Gustavo Silva, whose work includes eliminating some classes of buffer overflow risks and on kernel self-protection , and Nathan Chancellor, who fixes bugs in the Clang/LLVM compilers and improves compiler warnings. . Amazon's dedication to open-source software involves funding developers to address bugs and enhance system integrity.. Linux Security, Kernel Development, Open Source Contributions. . LinuxSecurity.com Team

Calendar%202 Feb 25, 2021 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200