Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
North Korean hackers who have targeted American and European businesses for 18 months kept up their attacks last week even as President Trump was meeting with North Korea’s leader in Hanoi. . The attacks, which include efforts to hack into banks, utilities and oil and gas companies, began in 2017, according to researchers at the cybersecurity company McAfee, a time when tensions between North Korea and the United States were flaring. But even though both sides have toned down their fiery threats and begun nuclear disarmament talks, the attacks persist. The link for this article located at The New York Times is no longer available. . The attacks, which include efforts to hack into banks, utilities and oil and gas companies, began in. north, korean, hackers, targeted, american, european, businesses, months, their. . Brittany Day
The latest Adobe Reader and Acrobat zero-day attack is part of a larger, longer-term targeted attack campaign aimed mainly at stealing intellectual property from the U.S. and U.K. industries and government agencies, according to Symantec.. Symantec identified the malware family involved in the attacks as Sykipot, which has been used in targeted attacks for the past two years and possibly as far back as 2006. Organizations hit in the latest wave of attacks were mainly U.S. and U.K. defense contractors, telecommunications firms, computer hardware companies, chemical companies, energy companies, and government agencies. The link for this article located at Dark Reading is no longer available. . Kaspersky disclosed that the ShadowPad malware is aimed at industries in Canada and Australia through an unpatched vulnerability.. Adobe Reader Exploit,Sykipot Malware,Zero-Day Attack. . LinuxSecurity.com Team
In this article I have identified five influential security trends to watch in 2012. The results, identified by a team of highly experienced accredited security professionals and based upon extensive tests at client sites, suggest security threats are becoming more targeted and personal.. Hackers are sidestepping automated security technology and are using social engineering and data mining to orchestrate attacks against prominent individuals and their corporate networks. This trend has been brought about through advances in network protection and tighter regulation both of which have conspired to make it more difficult for hackers to compromise systems and create widespread disruption. The link for this article located at Business Computing World is no longer available. . Hackers are sidestepping automated security technology and are using social engineering and data min. article, identified, influential, security, trends, watch, results. . LinuxSecurity.com Team
Dating back to the end of February, we have been tracking test runs of malicious PDF messages to very specific targets. These PDF files exploit the recent vulnerability CVE-2008-0655. Ever since the end of March, beginning of April, the amount of samples seen in the wild has significantly increased. Interestingly enough, there is almost no "public, widespread" exploitation. All reports are limited to very specific, targeted attacks. However, due to the wide scope of these attacks, and the number of targets we know of, we feel a diary entry was in order. Remember the old saying of "if it ain't broke, don't fix it"? It appears this exploit seems very focused on targeting not only the vulnerability mentioned in the article, but the very facet of sticking with stable software. Nothing is apparently "broken" about Adobe Acrobat v7, however as you can tell by the diary entry, updating is the key to preventing "it ain't broke" software from having to be "fixed" due to exploits such as this one.. The link for this article located at SANs is no longer available. . This report dives into focused assaults exploiting a particular PDF weakness. Uncover current risks and protective measures.. Targeted PDF Exploits, Adobe Acrobat Risks, Cybersecurity Defenses. . LinuxSecurity.com Team
This is a proof of concept to exploit the registration functionality of a website to build targeted password cracking engine. I am using Ajax to automatically detect the parameters which are submitted for a successful password and automatically resubmitting the modified passwords. Of course other technologies can be used for the same. . I think I can safely assume that by now we all understand the need of a strong password handling mechanism, which starts from a strong password policy. In the password policy we define the rules for the password selected by the user to login to their account. The idea is to make them stronger so that they are not easily guessed and more importantly, the password cracking tools cannot break them easily. Some websites have stricter password policy as compared to others but more often then not, the website owners also care about the customers as stronger passwords are difficult to remember. The stronger the password is, the chances are that the user might forget it especially if it is not something you use every day. Many companies also define the password policy keeping in mind many criteria, in which two of the main criteria are: The link for this article located at Anurag Agarwal - Application Security Evangelist is no longer available. . I think I can safely assume that by now we all understand the need of a strong password handling mec. proof, concept, exploit, registration, functionality, website, build, targeted. . LinuxSecurity.com Team
As a white-hat hacker for a big audit firm I spent days and nights in our “lab. The most interesting stage of a targeted attack is the reconnaissance, or footprint analysis. Here you use the web, search engines, whois, and nslookup, to discover as much about the target as possible. A whois lookup can tell you email address formats for instance (first letter last name @ company.com). The link for this article located at www.zdnet.com is no longer available. . Explore the captivating exploration stage of focused assaults, showcasing data collection techniques employed by ethical hackers.. Footprint Analysis, Targeted Attack Strategies, White-Hat Techniques. . LinuxSecurity.com Team
Cyber criminals are stepping up smaller, more targeted attacks as they seek to avoid detection and reap bigger profits by stealing personal and financial information, according to a report issued Monday. Symantec's Internet Security Threat report said during the second half of 2005 attackers continued to move away from broad attacks seeking to breach firewalls and routers and are now taking aim at the desktop and Web applications. . The latest report from the world's biggest security software maker said threats such as viruses, worms and trojans that can unearth confidential information from a user's computer rose to 80 percent of the top 50 malicious software code threats from 74 percent in the previous six months. The link for this article located at ZDNet.com is no longer available. . An updated analysis shows that hackers are increasingly employing focused, miniature assaults to pilfer sensitive personal and monetary information.. Cyber Crime, Data Theft, Security Software, Malware Attacks. . LinuxSecurity.com Team
Targeted attacks do not make nearly as much 'noise' as the mass-mailing worms and widespread vulnerabilities of the Internet, but they can be much more dangerous. The number and variety of computer worms, security vulnerabilities and attacks on the Internet . . . . Targeted attacks do not make nearly as much 'noise' as the mass-mailing worms and widespread vulnerabilities of the Internet, but they can be much more dangerous. The number and variety of computer worms, security vulnerabilities and attacks on the Internet continue to grow, often leaving more dangerous, targeted hack attacks that go beyond random worm infections and hacker scans overlooked, according to some experts. These targeted attacks, which typically involve a savvy perpetrator who knows where to go and what to get, can be much more dangerous than the run-of-the-mill viruses and vulnerabilities lurking on the Web. Experts say less attention is paid to targeted attacks because they affect fewer victims, but that may be changing as mass-mailing worm launches and vulnerability scans become more refined. The link for this article located at OS Opinion is no longer available. . Targeted attacks do not make nearly as much 'noise' as the mass-mailing worms and widespread vulnera. targeted, attacks, nearly, 'noise', mass-mailing, worms, widespread, vulnera. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.