Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 32 articles for you...
83

New FinSpy Variants Target Linux And macOS Users Amid Activist Campaigns

The infamous FinSpy spyware has returned - and is now targeting Linux and macOS users. FinSpy is being used in new campaigns targeting dissident organizations in Egypt. . The FinSpy commercial spyware is back in recently observed campaigns against organizations and activists in Egypt. While the spyware previously targeted Windows, iOS and Android users, researchers have discovered these campaigns using new variants that target macOS and Linux users. FinSpy is a full-fledged surveillance software suite, which has the ability to intercept victims’ communications, access private data, and record audio and video, according to Amnesty International, which uncovered the recent new variants. It’s been in use by law-enforcement and government agencies around the world since 2011. The link for this article located at ThreatPost is no longer available. . The sophisticated malware known as FinSpy is particularly aimed at individuals using Linux and macOS, focusing on campaigns against both activist groups and various organizations.. FinSpy, Linux Security Threats, Malware Attacks, macOS Surveillance. . LinuxSecurity.com Team

Calendar%202 Sep 29, 2020 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Open Source Spyware Found in Google Play Store: A Serious Concern

Have you heard that spyware based on two-year-old AhMyth RAT has made it past Play Store's scans, despite not being anything special? Learn more in this interesting ZDNet article: . You know Play Store security scans are really bad when spyware based on open source code manages to slip past Google's defenses, not once, but twice. The Android app that did this is called Radio Balouch, also RB Music, an app for streaming Balouchi music, specific to a geographical region and population that spreads across Iran, Afghanistan, and Pakistan. The link for this article located at ZDNet is no longer available. . App Marketplace inspections falter as community-driven malware evades safeguards, revealing critical vulnerabilities in data protection.. Open Source Spyware, Play Store Security, Android Security Risks. . LinuxSecurity.com Team

Calendar%202 Aug 22, 2019 User Avatar LinuxSecurity.com Team Privacy
83

Xinjiang Border Control: Spyware Apps on Foreign Tourists' Devices

Chinese authorities are secretly installing surveillance apps on smartphones of foreigners at border crossings in the Xinjiang region who are entering from neighboring Kyrgyzstan, an international investigation revealed. . Xinjiang (XUAR) is an autonomous territory and home to many Muslim ethnic minority groups where China is known to be conducting massive surveillance operations, especially on the activities of Uighurs, a Muslim Turkic minority group of about 8 million people. The Chinese government has blamed the Muslim Turkic minority group for Islamic extremism and deadly attacks on Chinese targets. The link for this article located at The Hacker News is no longer available. . Xinjiang authorities are reportedly installing spyware on foreign smartphones at border crossings, revealing alarming surveillance tactics.. chinese, authorities, secretly, installing, surveillance, smartphones, foreigners, border. . LinuxSecurity.com Team

Calendar%202 Jul 03, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

WhatsApp Zero-Day Alert: Critical Spyware Access Through Phone Calls

On Monday 13 May, Facebook revealed that an “advanced cyber actor” has been spying on some users of its ridiculously popular WhatsApp messaging app, thanks to a zero-day vulnerability that allowed hackers to install spyware, silently, just by calling a victim’s phone. . The vulnerability is now fixed, which means that if you’re one of WhatsApp’s 1,500,000,000 users you need to go to the well and drink up the latest version. There’s a good chance your app’s already updated itself, but this is a serious vulnerability so we advise you to check all the same. The link for this article located at NakedSecurity is no longer available. . The issue has been resolved. For the 1,500,000,000 users of WhatsApp, make sure to update immediately to ensure your device's protection.. WhatsApp Update, zero-day exploit, cyber security threat, spyware risk. . LinuxSecurity.com Team

Calendar%202 May 14, 2019 User Avatar LinuxSecurity.com Team Privacy
83

Amnesty International Spyware Attack Via WhatsApp Message

Amnesty International has been spearphished by a WhatsApp message bearing links to what the organization believes to be malicious, powerful spyware: specifically, Pegasus, which has been called History’s Most Sophisticated Tracker Program. . On Wednesday, the human rights-focused NGO said in a post that a staffer received the link to the malware in June. It was baited with a message written in Arabic that implored the group to cover a protest for “your brothers detained in Saudi Arabia in front of the Saudi embassy in Washington.” The link for this article located at Naked Security/Sophos is no longer available. . Human Rights Watch disclosed that malware was transmitted via Facebook Messenger, targeting an employee masquerading as news article distribution.. Amnesty International, WhatsApp Phishing, Cybersecurity Threats. . LinuxSecurity.com Team

Calendar%202 Aug 05, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Hacking Team Data Breach: 400GB Exposed Corporate and Customer Information

The cyberattacker who stole 400GB in corporate data belonging to spyware firm Hacking Team has come forward. Hacking Team has not had a good week. The Milan, Italy-based company, known for selling surveillance and spyware tools to government agencies and private companies, experienced a data breach over the weekend which led to the alleged theft of 400GB of corporate data.. The file, which has spread like wildfire through torrent sharing, magnets and mirrors, contains information including customer lists, financial statements and allegedly the source code of tools supplied by the company. The link for this article located at ZDNet Security is no longer available. . Significant leak of corporate information by CyberOps, revealing customer databases and accounting details. Discover more here.. Data Breach, Spyware Tools, Cybersecurity Incident, Corporate Intelligence. . LinuxSecurity.com Team

Calendar%202 Jul 07, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

NSA's Specialized Unit Intercepts Deliveries for Spyware Deployment

A special hacking unit of the U.S. National Security Agency intercepts deliveries of new computer equipment en route to plant spyware, according to a report on Sunday from Der Spiegel, a German publication.. The method, called "interdiction," is one of the most successful operations conducted by the NSA's Office of Tailored Access Operations (TAO), which specializes in infiltrating computers, wrote the publication, citing a top-secret document. The link for this article located at Network World is no longer available. . CIA's elite team adeptly executes network surveillance to introduce malware, exposing critical data vulnerabilities.. NSA Operations, Cyber Surveillance, Computer Security, Spyware Interception. . LinuxSecurity.com Team

Calendar%202 Dec 30, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Trojanized Simurgh Tool Threatens Privacy of Iranian Citizens

Backdoored versions of a widely used privacy tool have surfaced in Iran, raising fears that its government is using the Trojanised software to spy on its citizens. . A free encrypted proxy tool called Simurgh The link for this article located at The Register UK is no longer available. . Compromised iterations of the Simurgh application highlight alarm over the Iranian state surveilling individuals via malware.. Trojan Software, Iranian Surveillance, Encrypted Proxy Tools. . LinuxSecurity.com Team

Calendar%202 May 30, 2012 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200