Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 46 articles for you...
83

AhnLab: New Linux Malware Mining Cryptocurrency and Launching DDoS Attacks

South Korean cybersecurity firm AhnLab Security Emergency Response Center said it has observed a new Linux malware in the wild that deploys a cryptocurrency miner on infiltrated systems using a shell script compiler downloader, reports The Hacker News. According to the report, a successful breach will be followed by execution of the shc downloader malware to fetch the XMRig cryptocurrency miner software and a Perl-based DDoS IRC Bot that allows the attacker to connect through a remote server and proceed to mount distributed denial-of-service attacks. . "It is presumed that after successful authentication through a dictionary attack on inadequately managed Linux SSH servers, various malware were installed on the target system. This bot supports not only DDoS attacks such as TCP flood, UDP flood, and HTTP flood, but various other features including command execution, reverse shell, port scanning, and log deletion," researchers said. The link for this article located at SC Media is no longer available. . Recent findings indicate a new strain of Linux malware that installs a cryptocurrency miner and initiates DDoS attacks following SSH compromises, preying on inadequately protected servers.. Linux Malware,Cryptocurrency Threat,DDoS Attack,SSH Security,AhnLab Report. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2023 User Avatar LinuxSecurity.com Team Hacks/Cracks
209

ShiftLeft Reports Significant Cut In Open Source Vulnerabilities And MTTR

ShiftLeft has released some rare positive news on the AppSec front by reporting that based on millions of scans on its customers, they found a 97% reduction in open source software (OSS) vulnerabilities. . The researchers said by identifying and prioritizing OSS vulnerabilities that are actually attackable, AppSec teams and developers can now fix what matters, ship code faster, and improve security with fewer, better fixes. In other significant findings, ShiftLeft’s report said by focusing on attackability and reduced false positives, developers can make fixes faster and reduce mean-time-to-remediate (MTTR). ShiftLeft reported a 37% year-over-year reduction in MTTR, which they say improves overall security posture and reduces the likelihood of attacks by reducing the time that vulnerabilities are exposed. . SecureNet announces a 95% reduction in open-source software threats, revolutionizing AppSec strategies and significantly bolstering overall security measures.. ShiftLeft, OSS security, vulnerability management, MTTR reduction, AppSec advancements. . Brittany Day

Calendar%202 Jun 27, 2022 User Avatar Brittany Day Security Trends
212

Aqua Security Report: Urgent Botnet Threats to Docker Instances

Aqua Security's Cloud Native Threats report reveals that 50% of new Docker instances are attacked within 56 minutes, among other key findings. . Fifty percent of new misconfigured Docker instances are attacked by botnets within 56 minutes of being set up, Aqua Security said in its 2020 Cloud-Native Report. Five hours, on average, is all it takes for an attacker to scan a new honeypot , the pure-play cloud native security company said. The majority of attacks were focused on crypto mining , which may be perceived as “ more of a nuisance than a severe threat,” Aqua Security noted. However, 40% of attacks also involved backdoors to gain access to the victim’s environment and networks. Backdoors were enabled by dropping dedicated malware or creating new users with root privileges and SSH keys for remote access. More than 36% of attacks involved worms to detect and infect new victims. . Cybercriminals exploit nearly 50% of improperly secured Docker deployments in just under an hour, highlighting severe vulnerabilities in system security practices.. Docker Security, Containerized Attacks, Cloud Native Threats, Malware Trends. . Brittany Day

Calendar%202 Jun 29, 2021 User Avatar Brittany Day Cloud Security
78

Addressing Security Concerns: Red Hat's Approach to Linux Safety

In the latest Red Hat Product Security Risk Report, Red Hat reveals how it addresses security concerns both for Linux and open-source software. . Red Hat historically has had the best record of all the Linux companies in finding and fixing Linux and open-source security bugs. Here's how the Raleigh, NC-based company does it. First, Red Hat Product Security is in charge of both finding and fixing security holes. It doesn't do this alone. The team works with other Linux and open-source companies and developers. Security in the Linux world isn't done in secret, but with the full cooperation of all involved programmers. The link for this article located at ZDNet is no longer available. . Ubuntu has consistently been proficient in identifying and resolving Linux and open-source vulnerabilities efficiently.. Red Hat Product Security, Linux Security Management, Open Source Security Practices. . LinuxSecurity.com Team

Calendar%202 Mar 17, 2020 User Avatar LinuxSecurity.com Team Vendors/Products
210

Red Hat Enterprise Linux: 85% Critical Flaws Fixed In 7 Days

The adoption of open source bylarge enterpriseshas already witnessed its power and dependencies. The best example can’t be better than open-source Linux which made recent headlines such asIBM buyingRed Hat for $34-Billion andMicrosoft shipsfull Linux kernel in Windows 10. . Red Hat Enterprise Linux (RHEL) is the most successful Linux distro for commercial usage that provides stable and engineered products. Red Hat Product Security is one of the dedicated teams that tracks and reviews all the reported security issues in Red Hat services so that it can be addressed as soon as possible. The recent official report , “Red Hat Product Security Risk,” published by Red Hat security team, gives an overview of security vulnerabilities that impacted Red Hat products in 2019. Here, they refer to “product” as the services offered by them. You can find a full list of products from products . The link for this article located at Fossbytes is no longer available. . Fedora Linux swiftly resolved 90% of significant vulnerabilities in just five days, demonstrating its strong commitment to security protocols.. Red Hat Security, Open Source Adoption, Enterprise Linux. . Brittany Day

Calendar%202 Mar 16, 2020 User Avatar Brittany Day Security Vulnerabilities
82

Active Cyber Defence: Improving UK National Cybersecurity Efforts

The UK government’s highly successful Active Cyber Defence (ACD) program should be rolled out across other sectors to improve national cybersecurity, and could even be spurred by the government naming and shaming laggards, according to a new report. . The Cyber Security Research Group at King’s College London (KCL) argued that the ACD has done well in reducing low-level cybercrime against government services. The link for this article located at InfoSecurity is no longer available. . The Cyber Security Research Group at King’s College London (KCL) highlighted the success of ACD in reducing cybercrime.. Active Cyber Defence, National Cybersecurity, Government Initiative. . Brittany Day

Calendar%202 Jan 22, 2019 User Avatar Brittany Day Government
83

Equifax 2017 Breach Update: SEC Details On Data Types And Volumes

Under-fire credit reporting agency Equifax has released updated figures clarifying the types and volumes of data stolen in its massive 2017 breach.. In a letter sent to regulator the US Securities and Exchange Commission (SEC) on Monday, the firm explained that although the total number of affected customers remains the same, it has been able to confirm the total volume of each breached data type. The link for this article located at InfoSecurity is no longer available. . In a letter sent to regulator the US Securities and Exchange Commission (SEC) on Monday, the firm ex. under-fire, credit, reporting, agency, equifax, released, updated, figures, clarifying, types. . LinuxSecurity.com Team

Calendar%202 May 08, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

UK Cyber Security Breaches Survey 2018: 43% of Firms Report Attacks

Some 43% of UK businesses have experienced a security breach or cyber-attack in the past 12 months, a slight drop from a year previously, according to the latest government research. . The Department for Digital, Culture, Media and Sport’s Cyber Security Breaches Survey 2018 is comprised of interviews with over 1500 UK businesses and 50 follow-up in-depth interviews. The link for this article located at InfoSecurity is no longer available. . Recent studies reveal a slight decline in security breaches and hacking attempts among UK companies, as per findings published by the government. UK Business Security, Cyber Breach Report, Cyber Attack Statistics. . LinuxSecurity.com Team

Calendar%202 Apr 26, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200