Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 31 articles for you...
210

CISA: Mandate for Trend Micro Apex One Security Flaw Patch

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added half a dozen vulnerabilities to its catalog of Known Exploited Vulnerabilities and is ordering federal agencies to follow vendor’s instructions to fix them. . Of the six security flaws, only one was disclosed this year. It impacts Trend Micro’s Apex One platform for automated threat detection and response. CISA is giving federal agencies until October 6th to patch security vulnerabilities that have been reported between 2010 and 2022. . NIST mandates that government departments tackle critical weaknesses, impacting applications like Symantec's Endpoint Protection. Take immediate action!. CISA Mandate, Trend Micro Apex One, Vulnerability Management. . Brittany Day

Calendar%202 Sep 19, 2022 User Avatar Brittany Day Security Vulnerabilities
210

Red Hat RPM Security Advisory: Major Flaw by CloudLinux Developer

Red Hat has used RPM for software package distribution for decades, but thanks to CloudLinux developer Dmitry Antipov we now know that RPM contained a nasty hidden security bug since Day One. A repair patch for this major security hole has been submitted, but Antipov fears that it may be months before the fix is released. . In 1995, when Linux 1.x was the hot new Linux kernel, early Red Hat founding programmers Marc Ewing and Erik Troan created RPM . This software package management system became the default way to distribute software for Red Hat Linux-based distributions such as Red Hat Enterprise Linux (RHEL) , CentOS Stream , AlmaLinux OS , and Rocky Linux . Unfortunately, hidden within its heart is a major security hole. Dmitry Antipov, a Linux developer at CloudLinux , AlmaLinux OS's parent company, first spotted the problem in March 2021. Antipov found that RPM would work with unauthorized RPM packages . This meant that unsigned packages or packages signed with revoked keys could silently be patched or updated without a word of warning that they might not be kosher. . An important vulnerability in RPM identified by Dmitry Antipov poses risks for Red Hat and related distributions.. Red Hat Package Management, RPM Security Flaw, Linux Issues, CloudLinux. . Brittany Day

Calendar%202 Jul 01, 2021 User Avatar Brittany Day Security Vulnerabilities
81

Facebook Security Issue: 2018 Privacy Breach Exposed User Images

In early December, Facebook’s developer team declared the discovery of a security bug that gave developers access to photos users hadn’t shared on their timeline, including photos they had posted in Facebook Marketplace or Stories.. More worryingly, apps could find access to images users might have uploaded to Facebook but didn’t post anywhere. For example, this could be pictures you uploaded to a profile update you abandoned and did not complete. These are pictures that users haven’t shared with anyone. The link for this article located at The Next Web is no longer available. . Applications were able to view photos that users had uploaded without publicly sharing them on Facebook. This raised serious issues regarding privacy and safety.. Facebook Privacy Breach, Security Bug, Data Exposure, Image Access, Software Flaw. . LinuxSecurity.com Team

Calendar%202 Jan 19, 2019 User Avatar LinuxSecurity.com Team Privacy
81

Singapore Airlines Incident: 284 Accounts Compromised by Software Bug

Singapore Airlines (SIA) says a software glitch was the cause of a data breach that affected 284 members of its frequent flyer programme, compromising various personal information including passport and flight details. . The "software bug" surfaced after changes were made to the Singapore carrier's website on January 4 and enabled some of its Krisflyer members to view information belonging to other travellers, SIA told ZDNet in an email. The link for this article located at ZDNet is no longer available. . The 'software bug' surfaced after changes were made to the Singapore carrier's website on January 4 . singapore, airlines, (sia), software, glitch, cause, breach, affected. . LinuxSecurity.com Team

Calendar%202 Jan 06, 2019 User Avatar LinuxSecurity.com Team Privacy
78

FireEye Malware Protection System Flaw Dispute Raises Disclosure Concerns

A spat between two security companies shows just how sensitive reporting software vulnerabilities can be, particularly when it involves a popular product. The kerfuffle between FireEye and ERNW, a consultancy in Germany, started after an ERNW researcher found five software flaws in FireEye's Malware Protection System (MPS) earlier this year. . One of the flaws, found by researcher Felix Wilhelm, could be exploited to gain access to the host system, according to an advisory published by ERNW. As is customary in the industry, ERNW contacted FireEye in early April with details of the problems. . Concerns emerge regarding the disclosure of weaknesses in the Malware Defense System between CrowdStrike and CERT over issues in threat assessment.. Malware Protection System, FireEye, Ethical Disclosure, Software Flaws, Cybersecurity. . LinuxSecurity.com Team

Calendar%202 Sep 14, 2015 User Avatar LinuxSecurity.com Team Vendors/Products
67

Red Hat Research: Vulnerable TLS Implementations Expose RSA Keys

A number of TLS software implementations contain vulnerabilities that allow hackers with minimal computational expense to learn RSA keys. Florian Weimer, a researcher with Red Hat, last week published a paper called . The TLS implementations in these products, Weimer said, lack proper hardening to defend against what is known as the Lenstra attack against the Chinese Remainder Theorem, also known as RSA-CRT. . Multiple susceptible TLS versions threaten RSA key integrity, as highlighted in Veimer's findings showcasing insufficient protections.. TLS Improvements, RSA Key Protection, Cryptography Security. . LinuxSecurity.com Team

Calendar%202 Sep 09, 2015 User Avatar LinuxSecurity.com Team Cryptography
77

Linux Kernel Security Issue: Critique by Developer Jonathan Corbet

A senior Linux kernel developer has pointed to an instance of what he calls a lax approach to security in the Linux kernel, citing the case of a serious vulnerability that is now more than a month old and is yet to be fixed.. Jonathan Corbet (pictured above), who is also the editor of the Linux Weekly News website, described in an article how a flaw in the kernel, which was initially discussed on a private mailing list, had been made public with a posting by a developer named Oleg Nesterov. The link for this article located at IT Wire is no longer available. . Jonathan Corbet (pictured above), who is also the editor of the Linux Weekly News website, described. senior, linux, kernel, developer, pointed, instance, calls, approach, securi. . LinuxSecurity.com Team

Calendar%202 Feb 26, 2013 User Avatar LinuxSecurity.com Team Server Security
83

Oracle: Gowdiak Uncovers New Java Security Risks and Flaws

Serial Java fault-finder Adam Gowdiak has embarrassed Oracle yet again. Gowdiak hit the headlines last year when he reported a vulnerability, waited for Oracle's response, and then upped the ante with a comeback vuln.. It's d The link for this article located at Sophos is no longer available. . Java specialist Emma Carson reveals additional unrectified vulnerabilities in Oracle systems, raising the ante once more.. Java Security Risks, Oracle Software Issues, Gowdiak Findings, Java Flaws. . LinuxSecurity.com Team

Calendar%202 Jan 21, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200