Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
83

Compromised WordPress Plugins: Blackhat SEO Attack Insights

Researchers have discovered a group of attackers who have published a variety of compromised WordPress themes and plug-ins on legitimate-looking sites, tricking developers into downloading and installing them on their own sites. The components then give the attackers remote control of the compromised sites and researchers say the attack may have been ongoing since September 2013.. The incident came to light through an investigation by researchers at Fox-IT in the Netherlands, who discovered it after noticing a compromised Joomla plug-in on a customer The link for this article located at ThreatPost is no longer available. . The incident came to light through an investigation by researchers at Fox-IT in the Netherlands, who. researchers, group, attackers, published, variety, compromised, wordpre. . LinuxSecurity.com Team

Calendar%202 Nov 24, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Wikipedia Users Beware of Malware Causing Fake Advertisements

Visitors to Wikipedia who see advertisements on the site have most likely fallen victim to a browser-based malware infection, Wikimedia Foundation, the organization operating the website, said on Monday. . "We never run ads on Wikipedia," said Philippe Beaudette, director of community advocacy for the Wikimedia Foundation, in a blog post. "If you're seeing advertisements for a for-profit industry ... or anything but our fundraiser, then your web browser has likely been infected with malware." The link for this article located at InfoWorld is no longer available. . 'We never run ads on Wikipedia,' said Philippe Beaudette, director of community advocacy for the Wik. visitors, wikipedia, advertisements, likely, fallen, victim, browser. . LinuxSecurity.com Team

Calendar%202 May 16, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Defacer's Challenge: Unsecured Sites Targeted During Hacking Contest

Computer hackers vying in a global contest on Sunday defaced a slew of Web sites, but the damage was confined to the Internet's backwater of small, unsecured sites, security officials said. The "Defacer's Challenge" got off to a quick start . . . . Computer hackers vying in a global contest on Sunday defaced a slew of Web sites, but the damage was confined to the Internet's backwater of small, unsecured sites, security officials said. The "Defacer's Challenge" got off to a quick start on Sunday with 300 attacks reported minutes after the 0600 GMT official start, said Roberto Preatoni, founder of Estonia-based Zone-H.org, a site that tracks hack attacks. "There were no big names," he said. But he added his own site, www.zone-h.org, was knocked offline for much of the day because of a high volume of legitimate visitors and apparent attempts by hackers to bog down his computer servers. According to the contest Web site https://www.defacers-challenge.com which was taken offline last week, hackers were urged to prove their skills by defacing as many Web sites as possible during a six-hour span on Sunday. Points were awarded for the number and type of computer servers they infiltrated, the rules stated. The link for this article located at CNN is no longer available. . The hacking competition led to a variety of website disruptions, primarily affecting vulnerable sites lacking proper security measures, while avoiding significant targets.. Web Defacement, Cyber Attack Trends, Security Risks, Hacking Contest. . LinuxSecurity.com Team

Calendar%202 Jul 07, 2003 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

South Africa: r00t3rs Attack Leads to 20 Website Defacements

A hacker is reported to have targeted at least 20 South African Web sites last week, 14 of the attacks occurring in a single day. This is according to Internet law firm Buys Attorneys, which routinely tracks the behaviour of hackers. Reinhardt Buys of Buys Attorneys says last week saw a sharp increase in the number of hacker attacks on local Web sites. "During the past week, a hacker who refers to himself only as `r00t3rs' hacked into more than 20 sites." . . .. A hacker is reported to have targeted at least 20 South African Web sites last week, 14 of the attacks occurring in a single day. This is according to Internet law firm Buys Attorneys, which routinely tracks the behaviour of hackers. Reinhardt Buys of Buys Attorneys says last week saw a sharp increase in the number of hacker attacks on local Web sites. "During the past week, a hacker who refers to himself only as `r00t3rs' hacked into more than 20 sites." Buys says the hacker defaced 14 sites on 16 October, making it the worst hacking attack in SA's history. He says the hacker appeared to have focused on sites operating on Windows NT and bearing a .co.za domain name. "The hacker defaced the sites simply by deleting pages and replacing them with a blank page featuring his, or her, name. The successful attacks occurred in the early hours of Tuesday morning. "Since we started monitoring hackers that target South African sites in 2000, we never saw one hacker deface so many local sites in one day," says Buys. The link for this article located at ITWeb is no longer available. . An infiltration event led to the compromise of 15 Australian websites, signifying a groundbreaking breach in the nation's cybersecurity.. South Africa Hacking Attacks, Website Defacement, Cyber Breach, Online Security, R00t3rs Threat. . LinuxSecurity.com Team

Calendar%202 Oct 21, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

How Hackers Exploit Weak Site Security Through Search Engines

"... With a bit of ingenuity, anyone can skirt basic password authentication and go straight to the goodies on those sites where administrators are foolish enough to post them. If the desired information is contained in a Web page, anyone . . .. "... With a bit of ingenuity, anyone can skirt basic password authentication and go straight to the goodies on those sites where administrators are foolish enough to post them. If the desired information is contained in a Web page, anyone can find it." The link for this article located at TheRegister is no longer available. . Uncover the methods utilized by cybercriminals to exploit inadequate online security and simplistic login vulnerabilities through search engines, highlighting major threats.. web exploits, site security issues, online authentication flaws. . Anthony Pell

Calendar%202 Jun 05, 2000 User Avatar Anthony Pell Network Security
79

W3C Privacy Proposal Update for Enhanced Site Security Awareness

The W3C is working on creating a consistent means to find information on a site's security policy. "With a key proof-of-concept event looming in June, the leaders of a World Wide Web Consortium working group on Tuesday outlined changes . . .. The W3C is working on creating a consistent means to find information on a site's security policy. "With a key proof-of-concept event looming in June, the leaders of a World Wide Web Consortium working group on Tuesday outlined changes to an Internet privacy proposal they expect to finalize later this year. The newly released working draft of the W3C's Platform for Privacy Preferences Project, which offers Web sites a way to communicate their privacy policies in a standard machine-readable format, calls for online users to receive a snapshot of a site's privacy policy before they send any data to the site. They also would receive a warning if any health care information will be requested." The link for this article located at PC World is no longer available. . The W3C is developing a unified strategy that enables users to navigate site safety protocols with ease and assurance.. W3C Privacy Proposal, Security Policies, Data Privacy. . LinuxSecurity.com Team

Calendar%202 May 18, 2000 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200