Explore top 10 tips to secure your open-source projects now. Read More
×Cybersecurity researchers have identified two new vulnerabilities in Linux-based OSes that, if successfully exploited, could enable attackers to bypass mitigations for speculative attacks such as Spectre and obtain sensitive information from kernel memory. . Discovered by Piotr Krysiuk of Symantec's Threat Hunter team, the flaws — tracked as CVE-2020-27170 and CVE-2020-27171 (CVSS scores: 5.5) — impact all Linux kernels prior to 5.11.8. Patches for the security issues were released on March 20, with Ubuntu, Debian, and Red Hat deploying fixes for the vulnerabilities in their respective Linux distributions. While CVE-2020-27170 can be abused to reveal content from any location within the kernel memory, CVE-2020-27171 can be used to retrieve data from a 4GB range of kernel memory. The link for this article located at The Hacker News is no longer available. . Newly discovered weaknesses could enable cybercriminals to circumvent Spectre defenses on Linux platforms, raising issues of data privacy.. Linux Kernel Security,Spectre Attack,Kernel Mitigation Bypass,Red Hat Fix. . Brittany Day
A security researcher has discovered a massive cache of data for millions of Instagram accounts, publicly accessible for everyone to see. The account included sensitive information that would be useful to cyberstalkers, among others. . A security researcher calling themselves anurag sen on Twitter discovered the database hosted on Amazon Web Services. It had over 49 million records when discovered and was still growing before it was deleted. The Instagram data included user bios, profile pictures, follower numbers and location. This information is viewable online. What’s more puzzling is that it also contained the email address and telephone number used to set up the accounts, according to Techcrunch, which broke the story. The link for this article located at NakedSecurity is no longer available. . A security researcher calling themselves anurag sen on Twitter discovered the database hosted on Ama. security, researcher, massive, cache, millions, instagram, accounts. . LinuxSecurity.com Team
Bosses should be worried about their employee behaviour around sensitive documents according to a recent report. With the high volume of data that IT teams handle, communicating efficiently and securely is essential to preventing a breach. . Kitchener-ON-based SaaS company Igloo Software recently released a report showing that email is IT employees' top method for sharing sensitive or private information. The link for this article located at ZDNet is no longer available. . IT professionals predominantly rely on email for transmitting confidential data, which amplifies worries about potential security violations. Discover more about this issue.. Sensitive Data Sharing, IT Worker Behavior, Data Breach Concerns, Email Security Practices. . LinuxSecurity.com Team
FIFA President Gianni Infantino said in a statement to the press that the world football governing body's computer systems suffered a data breach for the second time this year. Moreover, both the Fédération Internationale de Football Association (FIFA) and Union of European Football Associations (UEFA) are both suspected of having suffered data breaches.. Hackers might have stolen sensitive data after compromising FIFA's computer systems via a phishing campaign targeting multiple officials of the football global governing entity. The link for this article located at Softpedia News is no longer available. . Hackers might have stolen sensitive data after compromising FIFA's computer systems via a phishing c. president, gianni, infantino, statement, press, world, football, governing. . LinuxSecurity.com Team
The DEF CON 2018 Voting Machine Hacking Village aimed to raise awareness in voting security through a full day of speakers and panel discussions along with a challenge for attendees to hack more than 30 pieces of voting equipment. A partnership with rOOtz Asylum offered youths between 8 and 16 years old an opportunity to hack replicas of the websites of secretaries of state to demonstrate that even hackers with limited years of experience can easily compromise critical systems.. The goal was to break as many voting machine pieces as possible in order to draw attention to the vulnerabilities that will be present in the upcoming 2018 elections. The focus on election equipment, however, ignores the greater danger caused by hacking into the diverse collection of sensitive information that flows through political campaigns and the electoral process, and using that to influence and sow distrust among voters. While changing a vote or voting results can be traced back to a particular stakeholder, changing people's understanding of facts is far more insidious. The link for this article located at DarkReading is no longer available. . Delve into the multifaceted nature of electoral integrity beyond mere electronic manipulation, underscoring significant risks and the vital role of citizen confidence.. Election Security,Cyber Threats,Voting Systems,Hacking Awareness,Sensitive Information. . Brittany Day
A security error by a third-party supplier has left over 100 manufacturing firms including several big-name carmakers red-faced after sensitive documents were exposed.. Over 150GB of data was left on a publicly accessible server by Level One Robotics, a supplier to Tier 1 automotive firms including VW, Chrysler, Ford, Toyota, GM and Tesla, and German manufacturing giant ThyssenKrupp. The link for this article located at InfoSecurity is no longer available. . Over 150GB of data was left on a publicly accessible server by Level One Robotics, a supplier to Tie. security, error, third-party, supplier, manufacturing, firms. . LinuxSecurity.com Team
Data breaches at the U.S. government's personnel management agency by hackers, with suspicions centering on China, involves millions more people than previously estimated, U.S. officials said on Thursday.. The Office of Personnel Management (OPM) said data stolen from its computer networks included Social Security numbers and other sensitive information on 21.5 million people who have undergone background checks for security clearances. The link for this article located at Reuters is no longer available. . The Office of Personnel Management (OPM) said data stolen from its computer networks included Social. breaches, government's, personnel, management, agency, hackers, suspicions, cente. . LinuxSecurity.com Team
Analyzing encrypted Web traffic can potentially reveal highly sensitive information such as medical conditions and sexual orientation, according to a research paper that forecasts how privacy on the Internet may erode.. In a paper titled "I Know Why You Went to the Clinic," researchers show that by observing encrypted Web traffic and identifying patterns, it is possible to know what pages a person has visited on a website, giving clues to their personal life. The paper will be presented July 16 at the Privacy-Enhancing Technology Forum in Amsterdam. The link for this article located at TechWorld is no longer available. . Scientists demonstrate that scrutinizing secure internet data can expose sensitive details, affecting individual confidentiality profoundly.. Data Privacy Issues, Web Traffic Analysis, Encryption Implications. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.