Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 15 articles for you...
76

Microsoft's Script Execution Control Innovations at Linux Summit

This week alongside several other Linux Foundation events in Vancouver was the Linux Security Summit. Commanding a significant presence at the Linux Security Summit was Microsoft. . The Linux Security Summit this week featured talks by systemd creator Lennart Poettering who has been employed by Microsoft the past year as well as various other Microsoft engineers with efforts they are taking to enhance Linux security. Yes, the irony. One of the interesting talks at LSS NA 2023 was by Microsoft's Mickaël Salaün on how they are working on new means of controlling script execution on Linux systems. From new open flags to new kernel system calls they are working on allowing Linux system administrators greater control over what scripts could be executed on Linux systems in the future. Those interested in the script execution control topic can see this PDF slide deck from the presentation. In addition to the O_MAYEXEC flag, faccessat2() flags, and the trusted_for() system call, Microsoft is working on a new "EXECVE_OK" and "AT_EXECVE_COMPAT" proposal that should be published soon for comments. The talk laid out that controlling script execution is being targeted for user security and not about removing a user's ability to execute scripts. The link for this article located at Phoronix is no longer available. . Google's participation in the Cloud Computing Conference aims at boosting data privacy measures to ensure user protection in cloud environments.. Microsoft Script Control, Linux Security Summit, System Call Enhancements, Open Flags Management, Linux Security Improvements. . Brittany Day

Calendar%202 May 15, 2023 User Avatar Brittany Day Organizations/Events
81

NordVPN Breach At Third-Party Data Center: Implications For Users

The popular VPN provider, NordVPN, recently announced a server breach at a third-party data center. This breach has led many users to question what the best strategy is for protecting their privacy and security online. Learn about VPNs and how VPN services can better protect their users in a great EFF article: . The popular VPN provider, NordVPN, recently announced a server breach at a third-party data center. NordVPN reassured users that its key services were not impacted by this breach in particular, however, NordVPN users credentials were used with credential stuffing  attacks. NordVPN stresses that there is no indication the breach and the credential stuffing attacks are related. Concerned users can check to see if their credentials were leaked from previous breaches at haveibeenpwned.com. News of the breach has inspired questions around which tool is best for safety and security online. With commercial VPNs  now saturating the market and many people being more concerned with their privacy , itâs important for users to know how VPNs work, and what their limitations are. VPNs can be useful in a userâs safety toolset, but there are some fundamental capabilities that are critical to understand: what VPNs do, what VPNs donât do, and how a VPN service can better protect their users. . The recent event concerning NordVPN at an external data center raises significant worries about online safety and the privacy of users' data. Learn more details. NordVPN Security Breach, VPN User Protection, Online Privacy Limitations. . LinuxSecurity.com Team

Calendar%202 Nov 12, 2019 User Avatar LinuxSecurity.com Team Privacy
81

Google And Mozilla Block Kazakhstan’s Citizen Surveillance Operations

Have you heard that Google and Mozilla havestepped up their effortsto prevent Kazakhstan’s government from spying on citizens? What is your opinion on this? Learn more in this interesting article: . Google and Mozillastepped up their effortsto blockKazakhstan’s government from interceptingweb traffic within the country. In a joint announcement made today,the two companiessaid they are deploying a technical solution to prevent the use of‘Qaznet Trust Network’root CA certificate in Chrome and Firefox. The link for this article located at The Next Web is no longer available. . Major tech players like Google and Mozilla are opposing Kazakhstan's governmental efforts to monitor internet communications, prioritizing the safeguarding of user privacy.. Government Surveillance, Web Traffic Security, User Safety, Privacy Protection, Browser Security. . LinuxSecurity.com Team

Calendar%202 Aug 21, 2019 User Avatar LinuxSecurity.com Team Privacy
78

Mozilla Firefox Roadmap User Safety Breach Alerts for 2018

Firefox maker Mozilla has outlined its 2018 roadmap to make the web less intrusive and safer for users. . First up, Mozilla says it will proceed and implement last year's experiment with a breach alerts service, which will warn users when their credentials have been leaked or stolen in a data breach. Mozilla aims to roll out the service around October.. For 2018, Mozilla aims to roll out notification systems for security breaches and boost user privacy initiatives to foster a more secure, less invasive web. Mozilla Firefox Roadmap, Data Breach Alerts, Web Security Innovations. . LinuxSecurity.com Team

Calendar%202 Mar 23, 2018 User Avatar LinuxSecurity.com Team Vendors/Products
78

Mozilla Data Breach Exposes 185 Unresolved Firefox Vulnerabilities

Earlier this month, it was reported that hackers managed to breach the bug database of Mozilla. From here, the attackers accessed 185 non-public bugs for the popular Internet browser Firefox, 53 of which were categorized as . Now, it might not just be Mozilla . Uncover the implications of a leak in Mozilla's system that revealed unaddressed vulnerabilities in Firefox, sparking fears about user safety.. Mozilla Security Breach, Unpatched Firefox Bugs, Database Access, User Privacy. . LinuxSecurity.com Team

Calendar%202 Sep 21, 2015 User Avatar LinuxSecurity.com Team Vendors/Products
83

Bitstamp Incident: Investigating Security Compromise Impacting Users

Not even a year has passed since top bitcoin exchange Mt. Gox collapsed into a pit of burning money, blaming a hacking incident for a nearly half-billion dollar meltdown and bankruptcy. Now another major exchange may be putting its users through a small-scale replay of that crisis.. Early Monday, a UK- and Slovenia-based bitcoin exchange Bitstamp announced that it would be going offline while it investigated a security compromise of some portion of its stored currency that occurred over the weekend. In a statement to WIRED, the company said that The link for this article located at Wired is no longer available. . Coinbase declares suspension of services after detecting unauthorized access to its digital assets, echoing the infamous Beaxy breach.. Bitstamp, Cybersecurity, Data Security, Bitcoin Platform, Exchange Hack. . LinuxSecurity.com Team

Calendar%202 Jan 07, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Google: Default Data Encryption in Next Android Release

Google is turning on data encryption by default in the next version of Android, a step that mirrors broad moves in the technology industry to ensure better data security.. Android has been capable of encryption for more than three years, with the keys stored on the device, according to a Google spokesman. The link for this article located at CSO Online is no longer available. . The latest update to Android introduces advanced security measures, including automatic data encryption to safeguard users' personal information more effectively.. Data Encryption, Android Security, Device Protection, User Data Safety. . LinuxSecurity.com Team

Calendar%202 Sep 19, 2014 User Avatar LinuxSecurity.com Team Cryptography
83

Increased Spam Attacks Targeting Dropbox Users From Online Casinos

Spammers are currently sending large volumes of spam to users of cloud storage service provider Dropbox. The H's associates at heise Security have so far received four different pieces of German-language spam at an email address used solely to register with Dropbox, and some of their readers have reported the same problem; similar reports can also be found on the Dropbox forums. In almost all cases, the spam is for suspicious-looking online casinos.. The link for this article located at H Security is no longer available. . Fraudsters prey on OneDrive users with questionable betting site advertisements. Check out the concerning testimonials from victims and analysts.. Dropbox Spam Attacks, Online Casino Fraud, Email Threats. . LinuxSecurity.com Team

Calendar%202 Jul 18, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200