Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
83

Vermilion Strike: New Linux Cobalt Strike Port Boosts Attack Capabilities

Hackers have developed a Linux port of the Cobalt Strike penetration testing toolkit dubbed Vermilion Strike to evade malware detection. . Cyber criminals have developed a Linux port of the Cobalt Strike penetration testing tool that has been dubbed Vermilion Strike, security researchers have discovered. The tool has been developed from scratch to avoid detection from malware scanners. According to a report published by cloud security firm Intezer Labs, researchers last month discovered a fully undetected ELF implementation of Cobalt Strike’s beacon . The malware used Cobalt Strike’s Command and Control (C2) protocol when communicating to its C2 server and has remote access capabilities such as uploading files, running shell commands, and writing to files. . Hackers have developed a Linux variant of Cobalt Strike, upgrading their malware avoidance strategies with additional features.. Linux Port Cobalt Strike, Vermilion Strike, Malware Evasion, Penetration Testing Toolkit, Cyber Crime. . LinuxSecurity.com Team

Calendar%202 Sep 14, 2021 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

Understanding Linux Malware Through VirusTotal Insights and Assessments

The rise of malware designed to infect Linux servers' distributed denial-of-service attacks has earned greater attention from VirusTotal, the Google-owned go-to tool for malware hunters. For security researchers that need to stay on top of emerging malware threats, the VirusTotal malware database has become an integral tool.. Anyone can upload a suspicious file to the web tool to check whether the dozen or so antivirus engines, such as Kaspersky, McAfee, Symantec, and other equivalents, detect it as malware. The tool is meant for good guys, but as one researcher found last year, black hat hackers were also using the service to test their malware against antivirus products prior to releasing it in the wild - despite the tool's shortcomings for comparative analysis. The link for this article located at ZDNet Blogs is no longer available. . Explore the ways in which ThreatTracker supports analysts in tackling new Linux malware challenges and scrutinizing server infiltration pathways.. Linux Malware, VirusTotal Detection, Server Security Insights. . LinuxSecurity.com Team

Calendar%202 Nov 12, 2014 User Avatar LinuxSecurity.com Team Security Projects
77

Essential Linux Admin Tools for Enhancing Security on CentOS System

Most Linux distributions have a significant focus on security. This does not mean they are necessarily ready for production out of the box. Tools like SELinux, excellent firewall options, and robust access controls can make Linux exceptionally secure. . Despite this, actually deploying a Linux system into production still requires that the systems administrator have some idea what they are doing. Let's use my favourite distribution, CentOS, as an example. (CentOS is a near-identical repackaging of Red Hat Enterprise Linux.) By default, SELinux is turned on. In most situations, this is a great thing; SELinux provides a layer of sandboxing so that applications of a certain class can't impinge upon files belonging to applications or users of another class. The link for this article located at The Register UK is no longer available. . Despite this, actually deploying a Linux system into production still requires that the systems admi. linux, distributions, significant, focus, security, necessari. . LinuxSecurity.com Team

Calendar%202 Jul 23, 2012 User Avatar LinuxSecurity.com Team Server Security
79

Innovative Hypervisor Tool For Rootkit Defense and Protection

Researchers at North Carolina State University and Microsoft Research have come up with a way to combat rootkits by using the machine's own hardware-based memory protection: the so-called HookSafe tool basically protects the operating system kernel from rootkits.. Rootkits are the most difficult of malware to detect and remove: they often evade detection by anti-malware software, and even if they are discovered, they can still be difficult to completely eradicate. A rootkit typically hijacks "hooks" in the operating system -- basically the control data in the kernel used to augment or extend the features of an OS -- in order to hide out in the OS. This in turn lets the rootkit intercept and manipulate the system's data, remain invisible to the user and anti-malware tools, and to install other malware aimed at stealing data from the system. "Then the rootkit can hijack and manipulate the results seen by the user applications ... only allowing a user to see what it wants them to see," says Xuxian Jiang, assistant professor of computer science at NC State and a member of the research team. The link for this article located at Dark Reading is no longer available. . Uncover the innovative approach taken by scientists to create a solution employing hardware memory safeguards aimed at counteracting rootkit threats.. Rootkit Protection Tools, Hardware Memory Defense, Malware Detection System. . LinuxSecurity.com Team

Calendar%202 Nov 04, 2009 User Avatar LinuxSecurity.com Team Security Projects
83

Emerging JavaScript Tool Poses Significant Threat to Browser Security

A new tool too dangerous to give away can turn any PC. After silently inserting itself to run inside any browser The link for this article located at eWeek is no longer available. . An application surfaces that can stealthily transform any web browser with JavaScript support into a harmful agent, presenting considerable dangers.. JavaScript Threat, Malware Tool, Browser Security Issue, Cyber Attack Software. . LinuxSecurity.com Team

Calendar%202 Mar 28, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Revolutionary Malware Defense Tool Improves Cybersecurity Solutions

London . The link for this article located at SourceWire is no longer available. . Delve into an innovative solution that adeptly fights off malware dangers with accuracy and effectiveness.. Robot Code Cracker, Malware Defense, Cybersecurity Tool. . Bill Locke

Calendar%202 Feb 03, 2007 User Avatar Bill Locke Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200