Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Huawei has denied having any official involvement in an insecure patch submitted to the Linux kernel project over the weekend, which introduced a "trivially exploitable" vulnerability. According to the tech giant, an employee submitted code as part of a personal project, not on behalf of the company. . The buggy patch was submitted to the official Linux kernel project via its mailing list on Sunday. Named HKSP (Huawei Kernel Self Protection), the patch allegedly introduced a series of security-hardening options to the Linux kernel. Big tech companies that heavily use Linux in their data centers and online services, often submit patches to the Linux kernel. Companies like Google, Microsoft, Amazon, and others have been known to have contributed code. . Huawei has rebuffed claims linking it to a flawed Linux kernel update that created an easily exploitable security loophole.. Huawei Denial, Linux Kernel Patch, Security Exploit, Buggy Patch Submission, Insecure Code. . Brittany Day
The European Union believes it has a simple way to bolster its digital security: offer lots of cold, hard cash. The European Commission is launching bug bounties in January that will offer prizes in return for spotting security flaws in 14 free, open source software tools EU institutions use. . These include well-known tools like VLC Media Player, KeePass, 7-zip and Drupal as well as something as vital as the GNU C Library. The bounties range from €25,000 to €90,000 (about $28,600 to $102,900) and will start expiring August 15th, 2019, although a few will last until 2020. The link for this article located at Engadget is no longer available. . These include well-known tools like VLC Media Player, KeePass, 7-zip and Drupal as well as something. european, union, believes, simple, bolster, digital, security, offer. . LinuxSecurity.com Team
Hundreds of tech-savvy inmates at several Idaho correctional facilities have been caught exploiting a software vulnerability on their state-funded tablets to artificially increase account balances.. Officials claimed that 364 prisoners had been caught hacking the JPay tablets which are provided to allow them access to email, music and games. The software exploit apparently allowed them to transfer a total of nearly $225,000 into their accounts, with one inmate managing an audacious $10,000. The link for this article located at InfoSecurity is no longer available. . Prisoners in Idaho have taken advantage of a software flaw in their tablets, pilfering approximately $225,000, highlighting a critical lapse in security protocols.. Idaho Inmates, Tablet Exploit, Hacking Security, Correctional Systems. . LinuxSecurity.com Team
Bitcoin's value has dropped sharply after one of the largest trading exchanges said there was a flaw in the virtual currency's underlying software. . MtGox said it had halted transfers to external Bitcoin addresses on Friday after detecting "unusual activity". The link for this article located at BBC is no longer available. . Ethereum's price plummets dramatically as Bitfinex halts withdrawals following severe system issues disrupting services.. Bitcoin Trading Platforms, Cryptocurrency Software Issues, Market Fluctuations. . LinuxSecurity.com Team
I just know other outlets will eventually pick up on this and add nonsense and subtract the facts at their own leisure, so I thought it worthwhile to get in early. A kernel vulnerabilities have been uncovered across a range of Ubuntu releases, covering 6.06 LTS to 9.10, also including Kubuntu, Edubuntu, and Xubuntu distros.. Here The link for this article located at ZDNet is no longer available. . Serious security flaws detected in Debian from 4.0 to 7.0 necessitating urgent patches for every version.. Ubuntu Kernel Issues, Critical Software Updates, Security Advisory. . LinuxSecurity.com Team
The Wireshark developers have announced the release of version 1.2.1 of Wireshark, the popular open source, cross-platform network protocol analyser. In addition to over 30 bug fixes, the security update addresses seven vulnerabilities that could crash the application remotely or lead to a buffer overflow. The denial-of-service (DoS) vulnerabilities affect the IPMI, AFS, Infiniband, Bluetooth L2CAP, RADIUS, MIOP and sFlow dissectors. Versions from 0.9.2 up to and including 1.2.0 of Wireshark are affected and all users are advised to update.. The release includes new capture file support for Btsnoop, DCT3, Packetlogger and pcap-ng. Protocol support for AFS, ANSI ISUP, ANSI MAP, ASN.1 PER, Bluetooth HCI H4, Bluetooth L2CAP, BSS CFLOW, COPS, Diameter, DICOM, FF-HSE, ICMPv6, IEC-60870-5-104, IEEE 802.11, Infiniband, IPMI, MIOP, RADIUS, RSVP, sFlow, SNMP, SMB2 and ZIOP has also been updated. The link for this article located at H Security is no longer available. . The newest version of Wireshark, 1.2.1, tackles 7 security issues, providing improved network inspection alongside fresh functionalities.. Wireshark Update, Networking Tools, DoS Issues. . LinuxSecurity.com Team
Researchers at Secunia have flagged a . The link for this article located at ZDNet is no longer available. . The link for this article located at ZDNet is no longer available.. researchers, secunia, flagged, article, located, zdnet, longer, availa. . LinuxSecurity.com Team
Less rigor in Web programming, an increasing variety of software, and restrictions on Web security testing have combined to make flaws in Web software the most reported security issues this year to date, according to the latest data from the Common Vulnerabilities and Exposures (CVE) project. A draft report on the latest numbers from the vulnerability database found that 4,375 security issues had so far been cataloged in the first nine months of 2006, just shy of the 4,538 issues documented last year. . The data shows that Web flaws have continued their meteoric rise since 2005, capturing the top-three spots on the list of most common vulnerabilities. Buffer overflows, a perennial favorite, fell to the No. 4 slot. "The takeaway is that researchers are paying a lot more attention to Web vulnerabilities, and if companies don't want to get caught up in that, then they need to pay attention to those flaws," said Steven Christey, the security researcher that authored the draft report and the CVE Editor for The MITRE Corp., a nonprofit government contractor. The jump in Web-based vulnerabilities is fueled by the simplicity of exploiting many of the most common Web vulnerabilities, the enormous number of Web applications freely available, and the difficulty in eradicating cross-site scripting flaws. The link for this article located at is no longer available. . In 2006, vulnerabilities in web applications escalated significantly due to more accessible exploits and an increase in software diversity, raising substantial security alarms.. Web Security, Software Flaws, Exploit Techniques. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.