Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
210

Linux Kernel: High Severity DoS And Privilege Escalation Risks Identified

Multiple significant security vulnerabilities have been discovered in the Linux kernel, including a remotely exploitable null pointer dereference flaw in the networking protocol (CVE-2023-3338), use-after-free vulnerabilities in kernel's netfilter subsystem in net/netfilter/nf_tables_api.c (CVE-2023-3390) and nft_chain_lookup_byid() (CVE-2023-31248), and an out-of-bounds read/write vulnerability (CVE-2023-35001). These bugs are easy to exploit and pose a severe risk to your system's confidentiality, integrity, and availability. As a result, they have received a National Vulnerability Database severity rating of “High”. . These issues could result in system crashes and privilege escalation attacks. Important updates for the kernel that mitigate these severe vulnerabilities have been released. We strongly recommend that all impacted users apply the Linux kernel updates issued by their distro(s) now to protect against attacks leading to system downtime and compromise. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Several vulnerabilities addressed in the Linux kernel may result in system instability and privilege escalation. It's crucial to apply the latest updates.. Linux Kernel Vulnerabilities, Security Updates, Privilege Escalation Risks. . Brittany Day

Calendar%202 Jul 25, 2023 User Avatar Brittany Day Security Vulnerabilities
83

HBGary Breach: SQL Injection Leads To Credential Exposure And Linux Flaws

Ars Technica has documented the background of the break-in at the US security firm that tried to expose Anonymous but ended up being taken apart itself. The report explains that the attackers' point of entry was a proprietary CMS which was custom-designed for HBGary. . The CMS reportedly failed to sufficiently check certain input parameters and this enabled the attackers to send SQL commands to the database via specially crafted URLs. This apparently allowed them to retrieve the CMS users' password hashes, which turned out to be simple, unsalted MD5 hashes that presented an easy target for a rainbow table attack. The attackers subsequently found that at least HBGary Federal's CEO Aaron Barr and COO Ted Vera used their CMS passwords for various other services, including their email access and Twitter. Vera also had an account at the support.hbgary.com site, where Anonymous managed to log in via SSH using the same password. The site ran a Linux system that was still vulnerable to a security hole in the GNU C loader, disclosed last October. Ars Technica said that the vulnerability presented the uninvited guests with the opportunity to obtain root privileges on the system, which gave them access to several gigabytes of backup and research data they reportedly deleted. The link for this article located at H Security is no longer available. . The platform allegedly did not adequately validate specific user inputs, which facilitated the breach.. SQL Injection Risks, CMS Vulnerabilities, Security Breaches, Linux System Flaws. . LinuxSecurity.com Team

Calendar%202 Feb 17, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Austin Incident: Vehicle Disabling Due to Web-Based Breach Incident

Great article by Kevin Poulsen. More than 100 drivers in Austin, Texas found their cars disabled or the horns honking out of control, after an intruder ran amok in a web-based vehicle-immobilization system normally used to get the attention of consumers delinquent in their auto payments. . Police with Austin The link for this article located at Wired is no longer available. . Police with AustinThe link for this article located at Wired is no longer available.. great, article, kevin, poulsen, drivers, austin, texas, found, their, disabled. . LinuxSecurity.com Team

Calendar%202 Mar 18, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Kernel Vmsplice() Exploit: Understanding Root Access Threats and Solutions

This recent kernel exploit has been spreading around the Internet quickly in recent days. So what is it, exactly? What is it really doing and how does it allow a cracker to exploit the root privileges in your system? Jonathan Corbet chimes in with one of the best overviews of the exploit, why it's a problem, how it got here, and what's being done to address it: "Unlike a number of other recent vulnerabilities which have required special situations (such as the presence of specific hardware) to exploit, these vulnerabilities are trivially exploited and the code to do so is circulating on the net. . The link for this article located at is no longer available. . The link for this article located at is no longer available.. recent, kernel, exploit, spreading, around, internet, quickly. . LinuxSecurity.com Team

Calendar%202 Feb 20, 2008 User Avatar LinuxSecurity.com Team Hacks/Cracks
82

Gregory Herns Hacked NASA: Sentenced to Six Months in Jail

A US man has been jailed for six months for a 2001 attack on the web systems of space agency NASA which cost $200,000 to fix. . Gregory Aaron Herns, 21, from Portland, Oregon, hacked into the network at NASA's Goddard Space Flight Center to store movies he had downloaded. The intrusion caused systems to crash and took technicians hours to fix, according to reports. In court last Friday, Herns admitted his guilt and apologised for the inconvenience he caused. "These actions took place years ago and are behind me. I've moved on since," he told US District Judge Anna Brown, AP reports. Herns, a computer science student at Mt. Hood Community College, was ordered to pay compensation. Judge Brown also imposed an order restricting his use of computers for three years. The link for this article located at John Leyden is no longer available. . Liam Christie Smith, 22, hailing from Seattle, Washington, infiltrated the database of the Jet Propulsion Laboratory, incurring expenses of $300K.. NASA Cyber Crime, Computer Intrusion, Network Breach, Hacking Case. . Joe Shakespeare

Calendar%202 Dec 20, 2004 User Avatar Joe Shakespeare Government
83

California Power Grid Under Attack: 17 Days Exposing Security Flaws

A computer system that controls much of the flow of electricity across California was under siege from hackers for at least 17 days during the height of the state's ongoing power crisis, the Los Angeles Times reported Saturday. The cyber attack . . . . A computer system that controls much of the flow of electricity across California was under siege from hackers for at least 17 days during the height of the state's ongoing power crisis, the Los Angeles Times reported Saturday. The cyber attack , while apparently limited, exposed security lapses in the system that the California Independent Systems Operator (Cal-ISO) uses to oversee most of the state's massive electricity transmission grid and connect to the grid for the western United States. The link for this article located at Boston.com is no longer available. . A digital infrastructure overseeing New York's water supply endured a 15-day hacking incident, exposing critical vulnerabilities.. California Electricity Grid,Cybersecurity Threats,System Security Failures,Power Grid Risks. . LinuxSecurity.com Team

Calendar%202 Jun 10, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200