Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 15 articles for you...
209

The Essential Reasons for Keeping SELinux Active for Optimal Security

Too many admins disable SELinux or set it to Permissive on their data center systems, as opposed to spending the necessary time to make the projects they're working on work with SELinux. Jack Wallen warns that admins are playing with fire by shrugging off SELinux, leaving their OSes weakened and susceptible to attacks. . Given the kerfuffle that has been CentOS lately, and the number of inevitable forks that will rise out of the ashes, there will probably be a large percentage of admins migrating to, or finally deploying, a Linux distribution based on Red Hat Enterprise Linux in some form or fashion. It may be Rocky Linux or AlmaLinux . It may be that you stick with CentOS Stream , or even purchase a license for Red Hat Enterprise Linux . If you're a non-profit or another eligible organization, you might qualify for RHEL for Open Source Infrastructure . No matter which route you take, you'll be using a solid Linux distribution with serious security systems in place. However... It's such a powerful word, "however." It stops all natural flow of the narrative to make you wonder just what comes next. You wait, and you wait, and you wait. Until the inevitable: SELinux. . Numerous administrators opt to deactivate SELinux or configure it in Permissive mode, jeopardizing overall system security. Discover the reasons this approach needs to change.. SELinux Management,System Security,Linux Best Practices,Admin Recommendations,Data Center Security. . Brittany Day

Calendar%202 Mar 03, 2021 User Avatar Brittany Day Security Trends
81

Examining Security Protocols for Messaging Applications and Services

One of EFF’s strengths is that we bring together technologists, lawyers, activists, and policy wonks. And we’ve been around long enough to know that while good technology is necessary for success, it is rarely sufficient. Good policy and people who will adhere to it are also crucial. . People write and maintain code, people run the servers that messaging platforms depend on, and people interface with governments and respond to pressure from them. We could never get on board with a tool—even one that made solid technical choices—unless it were developed and had its infrastructure maintained by a trustworthy group with a history of responsible stewardship of the tool. . Effective regulations and accountable management are essential for the success of secure communication platforms amidst a challenging environment.. Secure Messengers, Policy Considerations, Technologist Collaboration. . LinuxSecurity.com Team

Calendar%202 Apr 02, 2018 User Avatar LinuxSecurity.com Team Privacy
82

NSA Data Collection's Role in Preventing Future Terror Attacks

The Obama administration has framed its defense of the controversial bulk collection of all American phone records as necessary to prevent a future 9/11.. During a House Intelligence Committee hearing on June 18, NSA director Gen. Keith Alexander said, "Let me start by saying that I would much rather be here today debating this point than trying to explain how we failed to prevent another 9/11." The link for this article located at CNN Security is no longer available. . Delving into the debates surrounding the NSA's extensive collection of phone records, its impact on national security, and its effectiveness in preventing incidents akin to 9/11.. NSASurveillance,MassDataCollection,TerrorismPrevention,InformationSecurity. . Alex

Calendar%202 Dec 31, 2013 User Avatar Alex Government
79

Navigating Security From Compliance Pressures And Missteps

Compliance pressures often push companies to make security improvements they wouldn't have tackled otherwise. More budget goes toward technology needed to protect customer data. New policies are created to rein in what employees do online with company machines. But there's a dark side to this story.. In the mad rush to comply -- whether the stick takes the shape of PCI DSS or the Red Flags Rule -- companies sometimes make decisions that weaken their security. Poorly chosen and deployed IT security technology is perhaps the best example; for more on that, see " How to Make Things Worse With IT Security Technology. The link for this article located at Network World is no longer available. . Regulatory demands can frequently cause organizations to overlook crucial security measures, jeopardizing their comprehensive safety and trustworthiness.. Compliance Measures, Security Policies, Risk Factors. . LinuxSecurity.com Team

Calendar%202 Feb 24, 2010 User Avatar LinuxSecurity.com Team Security Projects
81

Bruce Schneier Discusses Misguided File-Sharing Law Efforts

Leading security expert Bruce Schneier was in London this week on a whirlwind lecture tour. ZDNet UK caught up with the ex-NSA man, who is now BT's chief security technology officer, at lectures in parliament and at University College London.. Schneier talked to ZDNet UK about his views on behavioural advertising, the efforts of various governments to tackle unlawful file-sharing, cyber-warfare and vendor lock-in. Q: The UK government is currently trying to pass the Digital Economy Bill, which includes provisions to penalise unlawful file-sharing. Is this technically feasible? A: The problem with a lot of these measures is that they only affect the average user. Professionals, hackers, clever people can get around them. No, I don't think this is technically feasible. The ones they don't care about, the average user, are the ones they are going to stop, and the detection mechanisms are sloppy. There are so many examples of the industry getting it wrong. The link for this article located at ZDNet UK is no longer available. . Schneier talked to ZDNet UK about his views on behavioural advertising, the efforts of various gover. leading, security, expert, bruce, schneier, london, whirlwind, lecture, zdnet. . LinuxSecurity.com Team

Calendar%202 Dec 09, 2009 User Avatar LinuxSecurity.com Team Privacy
82

Exploring Cybercrime Legislation: New Laws Affecting Hackers and Security

Everyone is in favour of sending hackers to prison for longer, but technology commentator Bill Thompson wonders if our MPs are competent to make good cyber-laws. If all goes to plan and the fuss over ID cards and school governance does not derail the parliamentary timetable, then we will soon have a new Police and Justice Act. . It makes many changes to the criminal law, but anyone considering writing a virus, hacking a bank system, launching a phishing or denial of service attack or installing some of the dodgier tools that can be used to 'test' network security should pay particular attention to clauses 33 to 36.. It makes many changes to the criminal law, but anyone considering writing a virus, hacking a bank sy. everyone, favour, sending, hackers, prison, longer, technology, commentator, thomp. . Brittany Day

Calendar%202 Mar 16, 2006 User Avatar Brittany Day Government
81

John Daugman On Privacy Rights Versus Government Security Policies

John Daugman, Cambridge-based pioneer of iris recognition told an audience of sixty security professionals, lawyers, and privacy advocates last night: “it is Orwellian to base a political campaign on disinformation. But he re-stated his main objection “to a creeping communitarianism – where the common good, as defined by the government takes precedence over the privacy rights of the individual The link for this article located at InfoSecurity-Magazine is no longer available. . The debate on privacy rights intensifies with government security measures. John Daugman emphasizes that national security shouldn't compromise personal privacy rights.. Iris Recognition, Privacy Protection, Security Measures, Communitarianism. . LinuxSecurity.com Team

Calendar%202 Dec 02, 2005 User Avatar LinuxSecurity.com Team Privacy
83

Understanding Linux Security Issues Amid Rising Cyber Threats

A report from British security firm mi2g last week blasted Linux system administrators for their failure to master the operating system's intricacies. It's important, though, to read between the lines before placing the blame solely on IT. As mi2g itself noted, the often chaotic growth of Linux has resulted in a tangle of procedures and a variety of security upgrade policies that make the administrators' job tougher. . . .. A report from British security firm mi2g last week blasted Linux system administrators for their failure to master the operating system's intricacies. It's important, though, to read between the lines before placing the blame solely on IT. As mi2g itself noted, the often chaotic growth of Linux has resulted in a tangle of procedures and a variety of security upgrade policies that make the administrators' job tougher. That growth has made Linux a more appealing target for hackers. But it will also generate more and better security products, and a deeper IT understanding of Linux security needs, policies, and vulnerabilities. A survey taken at the Computer Security Institute's annual conference calls for the same kind of between-the-lines consideration. Most of the 350 IT executives participating in the survey considered their networks to be more secure today than they were a year ago. Yet the same group reported sharp increases in the numbers of attacks their networks are experiencing. Is there a disconnect at work here? Is the increased sense of security delusional? Or is something else going on? The link for this article located at securitypipeline.com is no longer available. . This analysis uncovers the contradiction surrounding the efficacy of Linux administration security in the face of increasing cyber threats.. Linux Administration, Security Insights, IT Challenges, Cyber Resilience. . LinuxSecurity.com Team

Calendar%202 Nov 18, 2004 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200