Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Symantec today backed away from earlier statements regarding the theft of source code of some of its flagship security products, now admitting that its own network was compromised. . In a statement provided to the Reuters news service, the security software giant acknowledged that hackers had broken into its network when they stole source code of some of the company's software. The link for this article located at Network World is no longer available. . Symantec admits to a breach in its network security, resulting in the unauthorized acquisition of its proprietary source code, marking a departure from its previous assertions.. symantec source code theft, network breach, cybersecurity incident. . LinuxSecurity.com Team
Hackers have posted the source code for two Symantec security products, claiming they obtained the information from systems belonging to Indian military intelligence. The products affected are four and five years old, Symantec said. "If the source code from product released in the past three or four years was compromised, I'd be pretty concerned," said security consultant Randy Abrams.. Source code for two security applications from Symantec (Nasdaq: SYMC) has been stolen and posted on the Web. The hackers claiming responsibility, who call themselves the "Lords of Dharmaraja," say they obtained code for the Norton Antivirus application.. Source code for two security applications from Symantec (Nasdaq: SYMC) has been stolen and posted on. hackers, posted, source, symantec, security, products, claiming, obtained. . LinuxSecurity.com Team
The site that hosts the Linux kernel's source code, Kernel.org was compromised earlier this month. The discovery was made on August 28th, and steps are being taken now to enhance security for the site and recovery is underway. The kernel code repositories are believed to be unaffected.. According to an unattributed post on the front page of Kernel.org, intruders managed to gain access via a compromised user credential. It's currently unknown how the attacker managed to escalate to root access. After gaining access, the attacker modified files related to SSH services and added a trojan startup file to the system startup scripts. The trojan was discovered due to an error showing in a system log from a program not actually installed on the server (Xnest). The link for this article located at ReadWriteWeb is no longer available. . GitHub.com, known for hosting extensive open-source projects, experienced a security incident attributed to the unauthorized access of user accounts.. Linux Kernel, SSH Trojan, Source Code Security, Kernel.org Breach. . LinuxSecurity.com Team
The plot thickens. According to iDefense Labs, the recent Internet attack that has so upset Google affected 33 other US tech and defence firms and is directly related to an Adobe Reader-based attack of last July.. The US flaw-hunting specialist said that the attack was an attempt to steal source code on an industrial scale and was, in many cases, probably successful. If correct, this might explain why Google has by its own normally quite restrained standards gone ballistic to the extent of threatening to quit China. "Two independent, anonymous iDefense sources in the defense contracting and intelligence consulting community confirmed that both the source IPs and drop server of the attack correspond to a single foreign entity consisting either of agents of the Chinese state or proxies thereof," said the iDefense press statement, confirming what the world already knows. It now turns out that Adobe itself was targeted in the latest alleged Chinese attacks, as a statement on its own website explains. The link for this article located at Tech World is no longer available. . The US flaw-hunting specialist said that the attack was an attempt to steal source code on an indust. thickens, according, idefense, recent, internet, attack, upset, google. . LinuxSecurity.com Team
Cisco Systems issued a statement Monday confirming that police in Sweden have arrested a suspect in connection with the theft of its networking equipment source code last year. A spokesman for the FBI, which began working on the theft last May, said the case is ongoing and declined to offer details. . The stolen code was a portion of Cisco's Internetworking Operating System version 12.3. The incident has been a matter of concern because malicious hackers might find flaws in the code that could be exploited to impair the functioning of Cisco's routers, which handle a significant portion of traffic on the Internet. At the time of the incident, however, Cisco said that the availability of its code did not pose an increased security risk. On Tuesday, The New York Times reported that federal officials and security experts have acknowledged that the theft of the Cisco source code was part of a wider pattern of thousands of attacks on military and research computers perpetrated by an unknown number of individuals. The link for this article located at Information Week is no longer available. . Unauthorized individuals could leverage the compromised code from Cisco, potentially affecting router performance. Ongoing inquiries have validated this.. Cisco Code Theft, Networking Security, Source Code Breach, Cyber Attacks. . LinuxSecurity.com Team
An anonymous group of malicious hackers reopened an online store that sells the stolen source code of prominent software products and is offering the code for Cisco Systems (Profile, Products, Articles) Inc.'s PIX firewall software to interested parties for $24,000, according to messages posted in online discussion groups. . . .. An anonymous group of malicious hackers reopened an online store that sells the stolen source code of prominent software products and is offering the code for Cisco Systems (Profile, Products, Articles) Inc.'s PIX firewall software to interested parties for $24,000, according to messages posted in online discussion groups. The Source Code Club reappeared online Monday, using messages to online security discussion groups to announce that it was back in business. The group is using e-mail and messages posted in a Usenet group to communicate with customers and receive orders for the source code of several security products, including Cisco's PIX 6.3.1 firewall and intrusion detection system (IDS) software from Enterasys Networks (Profile, Products, Articles) Inc., the group said. Cisco did not immediately respond to a request for comment. The club first surfaced in July, using a Web page with an address in the Ukraine and messages posted to the Full-Disclosure security discussion list to advertise its wares. Initially, the Source Code Club said it was selling "corporate intel(ligence)" to its customers, along with other unnamed services, according to a message posted in July to the Full-Disclosure mailing list by a group or individual using the name "Larry Hobbles." The link for this article located at infoworld.com is no longer available. . An anonymous group of malicious hackers reopened an online store that sells the stolen source code o. anonymous, group, malicious, hackers, reopened, online, store, sells, stolen, source. . LinuxSecurity.com Team
Police in the U.K. have arrested a man in connection with the theft of source code from networking equipment maker Cisco Systems Inc. in May, a Scotland Yard spokeswoman confirmed Friday. . . .. The Metropolitan Police Computer Crime Unit searched residences in Manchester, U.K. and Darbyshire, U.K. on Sept. 3., confiscated computer equipment and arrested a 20 year-old man suspected of committing "hacking offenses" under that country's Computer Misuse Act of 1990. While authorities could not discuss the specifics of the case, the arrest was linked to the Cisco source code, according to Julie Prinsep, a Yard spokeswoman. The suspect has since been released on bail and is scheduled to appear before authorities at a London police station again in November, Prinsep said. Computer equipment seized in the searches is being forensically examined, she said. Cisco did not immediately respond to requests for comment. The arrest marks a major breakthrough in the case, which involves the posting of more than 800MB of source code from Cisco's Internetwork Operating System (IOS) to a Russian Web site in May. The link for this article located at Paul Roberts, IDG News Service is no longer available. . The Metropolitan Police Computer Crime Unit searched residences in Manchester, U.K. and Darbyshire, . police, arrested, connection, theft, source, networking. . LinuxSecurity.com Team
A group of self-identified hackers has set up shop online to sell what it claims are files containing confidential software code--and it says it's ready to take orders for more. . . .. A group of self-identified hackers has set up shop online to sell what it claims are files containing confidential software code--and it says it's ready to take orders for more. The group, which calls itself the Source Code Club, is offering what seems to be the stolen source code for an older version of Enterasys Networks' Dragon intrusion detection system and Napster's client and server software. The price: $16,000 and $10,000, respectively. As proof that it has the code, the group has put a listing of the files online. By using e-mail drops and encryption, the group believes that it can keep both the buyer's and its own identity secret. The link for this article located at zdnet.com is no longer available. . A group of self-identified digital intruders has debuted a platform aimed at marketing purported documents containing sensitive program code.. Source Code, Cybersecurity, Hacker Group, Software Theft, Dark Web. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.