Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 6 articles for you...
83

China: Cyberattack on Telecom Industry Raises Encryption Backdoor Risks

U.S. authorities are on high alert as they investigate an alleged Chinese state-sponsored hack targeting major U.S. telecommunications companies. This attack has reignited debate about encryption backdoors , an ongoing contention among security practitioners. . To help you understand this incident and the security implications of encryption backdoors, I'll discuss these recent attacks, lawmakers' reactions, the role of encryption backdoors in this threat, and why many security professionals—including us at LinuxSecurity.com —oppose their usage. Understanding This Hack Federal authorities have quickly investigated a cyberattack known as Salt Typhoon, linked to China-backed hackers. According to an anonymous U.S. official, these attackers targeted multiple U.S. telecommunications firms, including Verizon, AT&T, and Lumen Technologies. They compromised systems explicitly used by government intelligence collection capabilities such as wiretaps. The implications of this breach extend far beyond corporate walls, posing potential threats to national security. Chinese hackers compromised telecom systems and breached U.S. intelligence systems used for lawful surveillance, such as wiretapping. Investigators are meticulously studying the depth to which hackers have penetrated these networks and whether these criminals have extracted sensitive data. Lawmakers' Reaction to This Incident This incident has sparked significant concern among U.S. lawmakers, with Senator Ron Wyden of Oregon leading the charge by calling upon both the Justice Department and Federal Communications Commission (FCC) to implement stringent security standards for telecom companies' wiretapping systems. He specifically mentioned an outdated regulatory framework as he expressed disappointment over how the DOJ dealt with cyberattacks, which he considered negligent. Wyden suggested setting baseline cybersecurity standards that can be enforced through fines while conducting annual third-party cybersecurity auditsby an independent firm. He also advocated for full transparency regarding data breaches among Congress, investigators, and the public, holding negligent corporations responsible - an approach that signals a shift toward corporate accountability rather than prosecuting foreign hackers who rarely find justice in U.S. court systems. What Are Encryption Backdoors? Encryption backdoors are built into encrypted systems to give authorized authorities access to encrypted data for regulatory or national security reasons. Still, if discovered, they can potentially be exploited by malicious actors. Encryption is at the core of modern cybersecurity, protecting sensitive information from unintended access and modification. Robust encryption protocols also facilitate secure communications, safeguard individual privacy, and enhance national security. Examining the Pros & Cons of Encryption Backdoors Encryption backdoors offer both advantages and drawbacks. On one side, they can improve national security by aiding law enforcement with lawful surveillance operations and efficient investigations by providing necessary access to encrypted data. On the other hand, however, they could threaten national security. Encryption backdoors may help ensure compliance in critical infrastructure sectors like telecom and finance; however, their advantages come with potential drawbacks that should not be ignored. Backdoors introduce inherent vulnerabilities into systems, rendering them insecure without discriminating between good and bad actors. Unauthorized individuals could exploit them to access sensitive data. Recent hacks by China have illustrated how malicious actors can exploit backdoors to access data via backdoors, thus endangering national security and corporate confidentiality. Encryption backdoors can potentially erode public trust in cybersecurity and privacy efforts, discouraging users from adopting encryption technologies. Finally, exploited backdoors may lead to security breaches with substantial financiallosses, legal liabilities, and damage to corporate reputations. What Is the Security Community's Stance on Encryption Backdoors? Security experts have long opposed encryption backdoors as contrary to encryption's very purpose. China-backed hacks prove that backdoors can be dangerous. By exploiting backdoor access mechanisms, hackers can gain entry to systems considered secure by encryption. Leading cybersecurity experts advocate for solid encryption without any backdoors. Vital, unbreakable encryption is critical for protecting against sophisticated cyber threats, ensuring personal privacy, and maintaining national security systems' integrity. Responsible encryption involves designing systems to minimize risks without including backdoors. Our Final Thoughts: The Potential Risks of Encryption Backdoors Outweigh Their Advantages Recent attacks targeting U.S. telecom companies highlight the vulnerabilities posed by encryption backdoors. Although intended for national security and regulatory compliance purposes, backdoors present vulnerabilities that malicious actors can exploit—even state-sponsored hackers—looking for vulnerabilities they can use to breach national security and regulatory compliance. As digital ecosystems mature and cyber threats grow increasingly sophisticated, robust encryption without backdoors remains essential to safeguard sensitive information, maintain personal privacy, and fortify national security systems from unintended access. Instead of compromising encryption standards, policymakers should improve cybersecurity protocols, revise regulatory frameworks, and hold corporations accountable for their security practices. Encryption backdoors may seem beneficial regarding law enforcement and regulatory compliance, yet their inherent risks far outweigh their perceived advantages. This is demonstrated by China-backed hacks, such as those perpetrated against our digital infrastructures by hackers armed with access devices from China. Robust encryption without backdoorsmust be implemented for optimal digital security. . The U.S. investigation into hacking by Chinese operatives raises tensions, impacting corporate regulations, international alliances, and public trust in technology security.. Telecom Cybersecurity, Encryption Backdoors, Cybersecurity Legislation, National Security Issues. . Brittany Day

Calendar%202 Oct 16, 2024 User Avatar Brittany Day Hacks/Cracks
82

Congress Approves Protecting Cyber Networks Act For Data Sharing

Congress is hellbent on passing a cybersecurity bill that can stop the wave of hacker breaches hitting American corporations. And they. On Wednesday the House of Representatives voted 307-116 to pass the Protecting Cyber Networks Act, a bill designed to allow more fluid sharing of cybersecurity threat data between corporations and government agencies. The link for this article located at Wired is no longer available. . Congress has approved legislation aimed at enhancing information exchange regarding cybersecurity between private firms and federal entities.. Data Sharing, Cybersecurity Bill, Threat Intelligence, Corporate Security. . Dave Wreski

Calendar%202 Apr 24, 2015 User Avatar Dave Wreski Government
82

New Data Security Act: Strengthening Protection Standards for Data

A bill introduced yesterday by Sen. Bob Bennett (R-Utah) and Sen. Tom Carper (D-Del.) both of whom serve on the Senate Banking Committee, joins a growing list of data security measures now pending before Congress. The proposed Data Security Act of 2006 seeks to create a national data protection and breach notification standard. . "This bill would require all financial institutions, retailers and government agencies to maintain strong internal safety protections for the data they hold," Carper said in a statement. It would also require them to "quickly investigate" security breaches and to notify law enforcement, regulators and customers when there is a real risk of harm, he said. The proposed bill would expand the reach of current laws that require only financial institutions to protect the security and confidentiality of customer information, Bennett said in a separate statement. The link for this article located at ComputerWorld is no longer available. . New bill proposed to reinforce cybersecurity measures within banks and public sector organizations.. Data Protection Act, Security Standards, Breach Notification. . Benjamin D. Thomas

Calendar%202 Jun 28, 2006 User Avatar Benjamin D. Thomas Government
82

Nebraska Panel Evaluates Effects of Spyware Along With Cybersecurity Risks

Laws against theft don't end stealing, and laws against the ills of the Internet age aren't likely to stop the spread of computer spyware, the Legislature's Judiciary Committee was told Friday. But such laws are worth passing, said Alex Nicoll, associate director of technologies for the Nebraska University Consortium on Information Assurance. The spyware programs "are causing people grief. They are causing people loss. We should not just say we should give up," Nicoll said at a committee hearing. . Spyware programs can track a person's computer and Internet use, collect personal information or hijack computers into opening certain advertisements or Web pages. Some also can disable security Latest News about Security programs designed to keep them from operating.. Discussing the impact of spyware on users and the importance of legislation to combat its spread.. Spyware Regulations, Cyber Threats, Online Security, Information Governance. . Benjamin D. Thomas

Calendar%202 Mar 23, 2005 User Avatar Benjamin D. Thomas Government
81

Analysis of CAN-SPAM Act Compliance Dramatically Decreased

LS: Some of you may remember that we at LinuxSecurity confidently predicted that the CAN-SPAM act was bound to fail. We might congratulate ourselves for this foresight, if only it weren't so obvious. No serious security or privacy expert thought that it stood a chance of reducing the volume of spam. Our question still remains: was CAN-SPAM really just a cover for Congress, so that they could pretend to be legislating against spam while instead doing the bidding of the Direct Marketing lobbyists? . . .. The numbers don't lie: CAN-SPAM is a bust. Compliance with CAN-SPAM has fallen to a new low, according to recent data collected by MX Logic. In July, compliance fell for the first time under one percent to a measly 0.54 percent of all unsolicited commercial mail the company sampled during the month. The Denver-based firm has been tracking compliance with CAN-SPAM since the federal law went on the books in January. Through April, MX Logic's numbers remained stable, with about three percent of spam messages complying with the law's requirements, which range from verifiable return addresses to measures consumers and businesses can use to opt out of mailing lists. In May and June, however, the number slipped to one percent. "Now it's been halved," said Steve Ruskin, a senior analyst at MX Logic. "No one's really sure what's going on, but it's clear that CAN-SPAM isn't a threat to spammers. They're just ignoring it." Although hardcore spammers -- the relatively small number who account for the bulk of the world's spam -- were never likely to toe the line, said Ruskin, it's possible that some spammers who were complying have stopped. The blame, he said, could be laid on law enforcement, which hasn't exactly been successful in tracking down on spammers. Some individuals have been stymied -- most recently a Boca Raton resident whose assets were frozen by the courts -- but enforcement is the exception rather than the rule. The link for this article located at techweb.com is no longer available. . The numbers don'tlie: CAN-SPAM is a bust.Compliance with CAN-SPAM has fallen to a new low, accordin. remember, linuxsecurity, confidently, predicted, can-spam. . LinuxSecurity.com Team

Calendar%202 Aug 06, 2004 User Avatar LinuxSecurity.com Team Privacy
82

Exploring Information Security Laws Impacting Public Sector Operations

This is the last article in a four-part series looking at U.S. information security laws and the way those laws affect the work of security professionals. This installment continues the discussion of information security in the public sector and provides an . . . . This is the last article in a four-part series looking at U.S. information security laws and the way those laws affect the work of security professionals. This installment continues the discussion of information security in the public sector and provides an overview of national security law in the United States as it pertains to information security. It is easy to think of "national security" as meaning the security provided by military and intelligence gathering capabilities, and in certain specific legal contexts, that specific definition is both accurate and complete [1]. But as the threat of terrorism became clear, even before the attacks of September 11, 2001 national security came to mean, in additional to national defense, the protection of the public and private sector facilities essential to delivering the goods and services that maintain the quality of life in the United States, or as officially defined, the nation's "critical infrastructure." [2] Executive Order No. 13231 [3] , entitled, Critical Infrastructure Protection in the Information Age, issued by the President five weeks after the September 11, 2001 attacks, addressed itself to the information technology systems that form part of the nations' critical infrastructure. The Executive Order noted that information technology had "changed the way business is transacted, government operates, and national defense is conducted. Those three functions now depend on an interdependent network of critical information infrastructures." The order went on to authorize "continuous efforts to secure information systems for critical infrastructure." As we begin the discussion of the law in this area, it is useful to understand that the information technology we are talking about operates in threegeneral arenas: (1) the business environment, (2) the environment for the delivery of government services, and (3) national defense. The link for this article located at SecurityFocus is no longer available. . Explore the impact of federal privacy regulations on governmental cyber defense experts in the concluding episode of our series.. Information Security, Security Laws, Public Sector Operations. . Anthony Pell

Calendar%202 Jul 09, 2003 User Avatar Anthony Pell Government
74

Reorganizing Senate Homeland Security: Cyber Safety Reform Implications

The overwhelming vote by the Senate late Tuesday approving a Homeland Security Department clears the way for massive reorganization of the federal government that will have a dramatic impact on computer and network security. . .. The overwhelming vote by the Senate late Tuesday approving a Homeland Security Department clears the way for massive reorganization of the federal government that will have a dramatic impact on computer and network security . The bill, which sets the stage for the largest federal reorganization since the Defense Department was formed in 1947, does more than reshuffle government agencies. It gives the government a major role in securing operating systems, hardware and the Internet, including allowing for more police surveillance of the Net; punishing malicious computer hackers with up to life in prison; establishing a national clearinghouse for computer and network security work; and spending at least half a billion dollars a year for homeland security research. President Bush is expected to sign the bill by the end of the month. "The United States Congress has taken a historic and bold step forward to protect the American people by passing legislation to create the Department of Homeland Security," Bush said after the vote. "This landmark legislation, the most extensive reorganization of the federal government since the 1940s, will help our nation meet the emerging threats of terrorism in the 21st century." Attorney General John Ashcroft heralded the Senate's 90-9 vote for the massive new bureaucracy, which combines about 170,000 employees from 22 existing agencies, as beginning "a new era of cooperation and coordination in the nation's homeland defense." Earlier on Tuesday, the Senate voted 52-47, largely along party lines, to reject Democratic amendments to the bill. The final bill prohibits the Justice Department's proposed citizen-informant program called TIPS (Terrorist Information and Prevention System) and rejects "the development of a national identification system orcard." But privacy advocates and civil libertarians remain worried about the negative consequences of such a sweeping reorganization of law enforcement functions with little oversight. In a statement calling for more supervision of law enforcement practices, the Center for Democracy and Technology said the plan "raises serious concerns about the privacy of Americans" by granting the government "substantial--and potentially invasive--authorities to compile, analyze and mine the personal information of millions of Americans." Technology companies, on the other hand, praised the plan, which promises to be a cash cow for businesses that develop security products. AeA, a trade group representing technology companies, in particular applauded a provision that would require the government to focus on small businesses. "Some of the most cutting-edge technologies are being developed in smaller firms, but we are frequently lost in the shadow of the big guys," Michele Wong, CEO of Synergex and an AeA board member, said in a statement. Meanwhile, Microsoft is one of many large technology companies looking to further expand its government contracts into the homeland security arena. The company has named a new internal federal director of homeland security to work with the government on information technology issues. After the federal reorganization is complete, the new department will mash together five agencies that currently divvy up responsibility for "critical infrastructure protection." Those are the FBI's National Infrastructure Protection Center, the Defense Department's National Communications System, the Commerce Department's Critical Infrastructure Assurance Office, an Energy Department analysis center, and the Federal Computer Incident Response Center. Policing the Net A last-minute addition to the bill last week, before the House approved it by a 299-121 vote, is the 16-page Cyber Security Enhancement Act. It stiffens prison terms for hackers, expands the ability of police to conduct Internetor telephone eavesdropping without first obtaining a court order, and grants Internet providers more latitude to disclose information about subscribers to police. Another addition, which was opposed by open-government activists and journalist groups, says that information businesses give the department that's related to "critical infrastructure" will not be subject to the Freedom of Information Act. That could include details on virus research, security holes in applications, or operating system vulnerabilities. Included in the bill is a Homeland Security Advanced Research Projects Agency (HSARPA), modeled after the Defense Advanced Research Projects Agency, which will receive at least $500 million a year to fund the development of new technologies. According to the bill, HSARPA will "promote revolutionary changes in technologies that would promote homeland security, advance the development (of technologies), and accelerate the prototyping and deployment of technologies that would address homeland vulnerabilities." The final version of the mammoth, 484-page bill also does the following: * Establishes an office that is designed to become "the national focal point for work on law enforcement technology." Categories include computer forensics, tools for investigating computer crime, firearms that recognize their owner, and DNA identification technologies. The office also is charged with funding the development of tools to help state and local law enforcement agencies thwart computer crime. * Creates a Directorate for Information Analysis and Infrastructure Protection that is charged with analyzing vulnerabilities in systems including the Internet, telephone networks, and other critical infrastructures. * Orders the creation of "a comprehensive national plan for securing the key resources and critical infrastructure of the United States" including information technology, financial networks and satellites. * Requires all federal agencies, including the CIA, the Defense Department, and NationalSecurity Agency, to provide the new department with any "information concerning the vulnerability of the infrastructure of the United States." * Punishes any department employee with one year in prison for disclosing details that are "not customarily in the public domain" about critical infrastructures. * Creates a privacy representative and a civil liberties officer to ensure that the department follows reasonable "privacy protections relating to the use, collection and disclosure of personal information." * Orders the department to provide technical assistance and confidential warnings of potential vulnerabilities to companies that operate "critical information systems." * Allows the department to create a national corps of volunteers to "assist local communities to respond and recover from attacks on information systems and communications networks." * Creates a Homeland Security Institute to perform systems analysis, risk analysis, and simulation and modeling to determine the vulnerabilities of critical infrastructures, including the Internet. The nine senators who voted against the bill were Democrats Robert Byrd of West Virginia, Paul Sarbanes of Maryland, Daniel Akaka and Daniel Inouye of Hawaii, Edward Kennedy of Massachusetts, Russ Feingold of Wisconsin, Fritz Hollings of South Carolina, and Carl Levin of Michigan. Democratic-leaning independent James Jeffords of Vermont also opposed the bill. The link for this article located at News.com is no longer available. . The overwhelming vote by the Senate late Tuesday approving a Homeland Security Department clears the. overwhelming, senate, tuesday, approving, homeland, security, department, clears. . Anthony Pell

Calendar%202 Nov 20, 2002 User Avatar Anthony Pell Network Security
81

Governments Adopt New Laws Favoring Security Over Privacy Rights

Governments have made it easier for authorities to plumb databases and eavesdrop on telephone and online conversations, a survey of privacy regulations released this week found. The report, from the Electronic Privacy Information Center and Privacy International, shows that many countries . . . . Governments have made it easier for authorities to plumb databases and eavesdrop on telephone and online conversations, a survey of privacy regulations released this week found. The report, from the Electronic Privacy Information Center and Privacy International, shows that many countries besides the United States have adopted laws that value increased security over personal privacy. "It's a general theme toward total identification," said Sarah Andrews, an author of the report. "When you're outside in public or when you're online, you can be identified." That dismays privacy groups, who worry about free-speech restrictions and abuses of power. They oppose laws that loosen privacy protections, such as the ones adopted in the United States after last year's attacks on the World Trade Center and the Pentagon. The link for this article located at TechNews is no longer available. . Governments have made it easier for authorities to plumb databases and eavesdrop on telephone and on. governments, easier, authorities, plumb, databases, eavesdrop, telephone. . LinuxSecurity.com Team

Calendar%202 Sep 05, 2002 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200