Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 86 articles for you...
81

Tails 6.13 Released: Improved Wi-Fi Diagnostics and Enhanced User Privacy

Tails OS has once again proven itself a go-to option for privacy-focused users with the release of Tails 6.13. This update brings with it a host of improvements designed to boost security and user experience for Linux admins who prioritize anonymity and data protection. . Tails 6.13 includes an upgrade to diagnose Wi-Fi hardware issues quickly so users can address connectivity problems more effectively, as well as updates to Tor Browser (version 14.0.7) and Tor Client (0.4.8.14). Persistent Storage has also significantly improved with this release, including fixes that address partitioning errors and improve reliability when setting up new USB sticks. These updates make it easier than ever for users to leverage all the potential of Tails OS while upholding its high standards of security and accessibility. Whether troubleshooting Wi-Fi connectivity issues or checking for updated security patches, Tails 6.13 offers practical enhancements Linux security admins will appreciate as part of their ongoing effort to protect user privacy. Let's examine the key updates, new features, and notable fixes introduced in the latest release of this privacy-focused Linux distro and discuss how they will improve the security and usability of your systems. Improved Wi-Fi Hardware Diagnostics One of Tails 6.13's hallmark features is its improved diagnostics for detecting Wi-Fi hardware issues. Linux administrators often experience connectivity issues in environments with various hardware configurations. So the Tor Connection assistant now reports when no Wi-Fi hardware has been detected, helping users identify and troubleshoot compatibility issues more efficiently. Before this update, users might have struggled to quickly identify the cause of connectivity problems, leading to delays and frustration. With this enhancement, Tails now provides clearer feedback, which helps both users and administrators address these issues promptly. This not only improves user experience but also reinforces its reputation as asecure platform that ensures robust privacy measures are met. Up-to-Date Tor Browser and Tor Client Versions Security-minded users rely on Tor for anonymized browsing, making having the latest versions of the Tor Browser and client vital. Tails 6.13 addresses this need by updating the Tor Browser to version 14.0.7 and the Tor client to version 0.4.8.14 , respectively, providing users access to more secure and reliable tools. Tor Browser's update offers several under-the-hood optimizations designed to enhance user safety, such as fixes for known vulnerabilities and enhancements in overall performance. With version 14.0.7, users can browse with greater peace of mind knowing they are protected against emerging threats while enjoying a smoother browsing experience. Tor Client Version 0.4.8.14 provides significant updates that address potential vulnerabilities and optimize stability and efficiency when connecting to Tor. These fixes give Linux admins the confidence in Tails OS's secure communication features to maintain the high standards necessary for privacy-focused operations. Fixes for Persistent Storage Issues Persistent Storage is an invaluable feature of Tails for many users, providing them with secure files, configurations, and additional software across sessions. Tails 6.13 brings essential fixes to this feature that address partitioning errors that might arise during initial setup on new USB sticks. These improvements ensure users can count on their setup working consistently as intended. Tails 6.13 addressed an issue related to correctly creating Persistent Storage when partitioning a new USB stick, which could be particularly challenging for novice users setting up Tails for the first time. By eliminating these failures, setup will go more smoothly for newcomers, demonstrating Tails' dedication to creating an accessible yet highly secure operating environment. An Ongoing Commitment to Security and Privacy Tails OS has long been at the forefront of privacy-centricoperating systems , and with its release, Tails 6.13 marks another step toward improving security and usability. Tails has addressed key concerns like Wi-Fi hardware diagnostics while updating components such as Tor Browser and Client and Persistent Storage to ensure a robust and user-friendly computing environment. We Linux security admins understand the significance of these updates for more than incremental improvement; they represent essential steps towards maintaining the integrity and functionality of the systems we manage. Understanding the Practical Benefits for Linux Admins Linux admins who oversee environments where user anonymity and data protection are paramount will discover many practical benefits from Tails 6.13. Improved Wi-Fi connection diagnostics simplify deployment across various hardware configurations, and less time is wasted troubleshooting connectivity issues, particularly helpful when quick setup time and consistent performance are essential. Staying current with the Tor Browser and Client is essential to mitigating potential security risks. The updates introduced in Tails 6.13 ensure users are shielded from current vulnerabilities while communicating securely. This proactive approach builds trust in the system's ability to protect user data and preserve anonymity. Enhancements to Persistent Storage reliability offer additional benefits by streamlining setup procedures and guaranteeing users can consistently save and access their data across sessions. This reduces setup errors that require troubleshooting efforts, leaving more time for other crucial aspects of system administration. Our Final Thoughts on the Tails 6.13 Release Tails 6.13 provides an impressive suite of updates and features to enhance security and user experience. Linux security admins will find useful tools for hardware diagnostics, software updates, persistent storage needs, and more in this release. By continuously expanding on its solid foundation, Tails OS remains one of the premier optionsfor maintaining privacy and anonymity online. Linux administrators can deploy Tails with greater assurance thanks to its latest upgrades. Tails now provides robust protection against current threats while offering user-friendly features that make it more accessible than ever. Whether troubleshooting connectivity issues, updating security patches, or setting up Persistent Storage for the first time, Tails 6.13 has everything needed for creating and maintaining a safe computing environment. Tails OS provides detailed instructions on how to install, download, or upgrade to Tails 6.13 on its official website. . Tails 6.13 bolsters user security through enhanced data protection, updated Tor integration, and increased dependability of persistent storage for Linux administrators.. Tails OS, Privacy Protection, Network Diagnostics, Software Updates, Persistent Storage. . Brittany Day

Calendar%202 Mar 10, 2025 User Avatar Brittany Day Privacy
210

Google Chrome Update: Addressing Critical Chromium Flaws on Linux

Google Chrome, one of the world's most widely used web browsers, has recently been scrutinized due to the discovery of multiple Chromium vulnerabilities that threaten user safety and privacy. Chromium is the open-source web browser project that is the basis of Chrome and many other widely used browsers. . These issues highlight the struggle between providing user-friendly software and protecting it with robust security measures. I'll explain these recent vulnerabilities in more depth, help you determine if you are at risk, and explain how to update Chrome to protect your privacy and security online. Unpacking These Recent Chromium Vulnerabilities Google released a critical security update to Google Chrome on August 6, 2024, to address a series of vulnerabilities that potentially allowed attackers to install malicious code on users' systems. Linux version 127.0.6533.99 aims to address these flaws. CVE-2024-7532 was identified as the most severe vulnerability involving out-of-bounds memory access in ANGLE (Almost Native Graphics Layer Engine). Considered critical, this flaw could enable attackers to execute arbitrary code, and cause system crashes. Apart from CVE-2024-7532, the update includes resolution for several high-severity issues: CVE-2024-7533 is a use-after-free vulnerability in the Sharing feature. CVE-2024-7550 is a type confusion flaw in the V8 JavaScript engine. CVE-2024-7534 is a heap buffer overflow in the Layout component CVE-2024-7535 represents inappropriate implementation in V8. CVE-2024-7536 involves WebAudio use-after-free vulnerabilities that enable malicious actors to gain unauthorized access, access sensitive data, or inject and execute arbitrary malicious code. Impact and Risk Evaluation Due to Chrome's widespread usage across platforms, these vulnerabilities have far-reaching ramifications. One immediate risk for individual users lies in their privacy and security. If their browser session becomes hijacked, personal andfinancial data could be stolen, and unwanted actions could be taken on their behalf. Organizations that rely heavily on web applications for operations are especially at risk since security flaws in these apps could allow attackers to penetrate organizational networks and steal sensitive data. This risk is especially acute in finance, healthcare, and government services. Any user, small business owner, or large enterprise using unpatched versions of Google Chrome could be susceptible to these vulnerabilities. This includes individual users and businesses without rapid update policies in place. Why Are Timely Updates Essential & How Can I Update Chrome on Linux? These vulnerabilities have been addressed with Google's recent Chrome update . Updating immediately is an essential preventative measure against potential attacks. Google did not reveal specifics regarding each vulnerability to protect against further exploitation. Instead, it is relying on users updating their browsers to protect themselves. Updating Google Chrome on Linux can be an effortless but effective way of protecting against vulnerabilities that exist within it. Here's how to update: Launch Google Chrome: Launching the Chrome browser is the first step in getting Google Chrome up and running. Access the Menu: To open, click on the three-dot menu in your browser's top-right corner. Navigating to Help: Navigate to Google Chrome > About, and your browser will take you directly to a page that displays its current version and checks for updates. Automatic Update: If an update is available, Chrome will begin the update process automatically. Wait for it to download and install before taking action. Restart Chrome: Once the update is installed, the browser must be relaunched to complete it successfully. An icon will remind you when it is ready and to relaunch immediately afterward. Verifying Your Updates: To ensure the update has taken effect, visit Help > About Google Chrome to view its updatedversion number. Our Final Thoughts on These Severe Chromium Bugs Chromium vulnerabilities are a stark reminder of the perils inherent to digital security and highlight the necessity of constant vigilance. Users can significantly mitigate risks by understanding these vulnerabilities and possible repercussions and updating their systems with security patches . Linux users should follow this straightforward update process to safeguard their digital privacy and security. Staying informed and proactive is critical in protecting our digital lives! . Enhance your system's security with Chromium by ensuring that Google Chrome is freshly updated on Linux. Safeguard your privacy and maintain user safety efficiently.. Google Chrome Security, Chromium Update, User Privacy Measures, Cybersecurity Risks. . Brittany Day

Calendar%202 Sep 04, 2024 User Avatar Brittany Day Security Vulnerabilities
78

Tails 4.20 Launch: Enhanced Online Privacy with New Tor Assistant

Tails, the amnesic incognito live system known for the anonymity it provides users online, has been updated to version 4.20 - a release that introduces a brand-new connection wizard for the Tor network. . The biggest change in Tails 4.20 is the brand-new Tor Connection assistant that simplifies the way you connect to the Tor anonymous network from the Tails live system. The new Tor Connection assistant pops up immediately after connecting to a local network. The advantages of the new Tor Connection wizard are many, mostly helping censored users, but it promises to better protect anyone who wants to remain unnoticed when using the Tor network, or those who want to connect to Tor using bridges, as well as first-time users. The link for this article located at 9 to 5 Linux is no longer available. . Discover improved digital privacy with Tails 4.20's updated Tor Connection helper for effortless navigation.. Tails 4.20, Tor Assistant, Anonymous OS, Network Security, Online Privacy. . LinuxSecurity.com Team

Calendar%202 Jul 14, 2021 User Avatar LinuxSecurity.com Team Vendors/Products
81

Insecure Baby Monitors Allow Remote Viewing of Video Streams

New research highlights that cheap baby monitor and security camera vendors prioritize convenience over user security and privacy, building a highly insecure ‘convenience’ feature that allows anyone to remotely view unencrypted video streams into their products. . A new report from Safety Detectives emphasises that cheap baby monitors and security cameras have inbuilt flaws that the vendors will never fix. The flaw allows anyone to remotely view unencrypted video streams. Yes, we have reported recently on the billions of cheap generic video doorbells and security cameras – it is scary, especially if you have one. This new report exposes that hundreds of millions of cheap baby monitors and security cameras have an intentional ‘convenience’ feature that is a huge security flaw. . A recent study uncovers significant vulnerabilities in affordable baby monitoring devices and cameras, jeopardizing user confidentiality due to lack of encryption in data transmission.. remote Access Security, Baby Monitor Security, Camera Privacy Flaws. . LinuxSecurity.com Team

Calendar%202 Feb 22, 2021 User Avatar LinuxSecurity.com Team Privacy
81

Ubuntu 21.04: Home Directories Now Private for Enhanced Security

Until now, users on the same Ubuntu system could access and read the files in the home directory of other users. This is changing from Ubuntu 21.04 - adding a layer of security and privacy to Ubuntu systems. . The development of Ubuntu 21.04 is in progress for its stable release on April 22, 2021. One of the proposed changes in Ubuntu 21.04 is to make the users’ home directories private. I hope you are aware of file permissions. If not, I have written a detailed and easy to understand guide to Linux file permission and I suggest you read that. Most people probably never noticed it but the home directory in Ubuntu has the permission 755 i.e. rwxr-xr-x. . The forthcoming Ubuntu 21.04 prioritizes user privacy with a key update that ensures home directories are kept private, thereby boosting overall security measures.. Ubuntu 21.04, user privacy, home directory permissions. . LinuxSecurity.com Team

Calendar%202 Jan 20, 2021 User Avatar LinuxSecurity.com Team Privacy
81

Chrome Extensions Threat: 33 Million Downloads In Eavesdropping Campaign

Have you heard that Google has removed scores of malicious and fake Chrome extensions being used in a global eavesdropping campaign? . The threat was spotted by Awake Security, which detected 111 of the malicious extensions over the past three months. When it notified Google of the issue last month, it claimed that 79 were present in the Chrome Web Store, where they had been downloaded nearly 33 million times. Figures for the others not in the official marketplace are hard to calculate for obvious reasons. “These extensions can take screenshots, read the clipboard, harvest credential tokens stored in cookies or parameters, grab user keystrokes (like passwords), etc,” it said in a report detailing the investigation. . The discovery of over 33 million downloads of harmful Chrome extensions poses a critical risk to security, underscoring the importance of protecting user privacy.. chrome extensions, malicious software, eavesdropping threats, user privacy. . LinuxSecurity.com Team

Calendar%202 Jun 19, 2020 User Avatar LinuxSecurity.com Team Privacy
78

500 Chrome Extensions Steal User Data: Malvertising Campaign Exposed

Google removed 500 malicious Chrome extensions from its Web Store after they found to inject malicious ads and siphon off user browsing data to servers under the control of attackers. . These extensions were part of a malvertising and ad-fraud campaign that's been operating at least since January 2019, although evidence points out the possibility that the actor behind the scheme may have been active since 2017. The findings come as part of a joint investigation by security researcher Jamila Kaya and Cisco-owned Duo Security, which unearthed 70 Chrome Extensions with over 1.7 million installations. The link for this article located at The Hacker News is no longer available. . Malicious Chrome extensions were part of an extensive ad-fraud campaign impacting 1.7 million users. Learn more here.. google, removed, malicious, chrome, extensions, store, found, inject, malicio. . LinuxSecurity.com Team

Calendar%202 Feb 14, 2020 User Avatar LinuxSecurity.com Team Vendors/Products
67

Senate Judiciary Committee Hearing on Encryption and Law Enforcement Access

The Senate Judiciary Committee recently held ahearingon encryption and “lawful access.” That’s the fanciful idea that encryption providers can somehow allow law enforcement access to users’ encrypted data while otherwise preventing the “bad guys” from accessing this very same data. Learn more: . But the hearing was not inspired by some new engineering breakthrough that might make it possible for Apple or Facebook to build a secure law enforcement backdoor into their encrypted devices and messaging applications. Instead, it followed speeches, open letters, and other public pressure by law enforcement officials in the U.S. and elsewhere to prevent Facebook from encrypting its messaging applications, and more generally to portray encryption as a tool used in serious crimes, including child exploitation. Facebook hassignaledit won’t bow to that pressure. And more than 100 organizations including EFF havecalled on these law enforcement officials to reverse course and avoid gutting one of the most powerful privacy and security tools available to users in an increasingly insecure world. . Senate Intelligence Committee discussions ignite debates over data protection and police access, impacting individual confidentiality.. Encryption Access, Law Enforcement Challenges, Digital Privacy Issues. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2019 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200