Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
83

CryptoPHP Backdoor Threat in Pirated Joomla, WordPress, Drupal Themes

Illegal search engine optimization (SEO) is the goal of attackers who are freely distributing pirated Joomla, WordPress and Drupal themes and plugins that are packaged with a backdoor being referred to as CryptoPHP. . Last week Fox-It released a whitepaper on CryptoPHP, and in a Wednesday post the security company revealed that most of the command-and-control domains had been sinkholed or taken down. The link for this article located at SC Magazine is no longer available. . Unauthorized themes and plugins containing hidden backdoors pose a significant risk to the safety of online platforms.. CryptoPHP Backdoor, Web Security Threats, Pirated Themes. . LinuxSecurity.com Team

Calendar%202 Dec 03, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Malicious PNG Files: A Threat of iFrame Injection by Sucuri

Security vendor Sucuri is warning that it's spotted an attack in the wild that embeds malicious code in PNG files. . The iFrame injection attack loaded a valid jquery.js file with very little to alert even the researcher that something else was going on. As the company writes in this blog post, the only red flag in the code was a loadFile() function downloading dron.png into the iFrame. The link for this article located at The Register UK is no longer available. . Uncover the hidden threat of the iFrame exploit that stealthily integrates harmful JPEG scripts, sidestepping security measures and endangering online safety.. iFrame Attack, PNG Malware, Code Injection, Web Threats, Sucuri Security. . LinuxSecurity.com Team

Calendar%202 Feb 05, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

2009 Security Report: Firefox Leads Browser Vulnerabilities at 44%

Application security vendor Cenzic today released its security trends report for the first half of 2009 application. In it, Cenzic claims that the Mozilla's Firefox browser led the field of Web browsers in terms of total vulnerabilities.. According to Cenzic, Firefox accounted for 44 percent of all browser vulnerabilities reported in the first half of 2009. In contrast, Apple's Safari had 35 percent of all reported browser vulnerability, Microsoft's Internet Explorer was third at 15 percent and Opera had just six percent share. The 2009 figures stand in contrast to Cenzic's Q3/Q4 2008 report, where IE accounted for 43 percent of all reported Web browser vulnerabilities and Firefox followed closely at 39 percent. The link for this article located at Internet News is no longer available. . According to Cenzic, Firefox accounted for 44 percent of all browser vulnerabilities reported in the. security, application, vendor, cenzic, today, released, trends, report, first. . LinuxSecurity.com Team

Calendar%202 Nov 09, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
83

Critical XSS Issues Found In Leading Websites Exposing User Data

Eight out of ten Web sites contain common flaws that can allow attackers to steal customer data, create phishing exploits, or craft a variety of other attacks, a security company reported today. WhiteHat Security regularly scans hundreds of "very popular, very high-traffic sites" for its online business customers, says Jeremiah Grossman, the company's founder. "More than likely, you have shopped there, or bank there," he says. Thirty percent of scanned sites contain an urgent vulnerability, such as one that allows direct access to a company database with customer information, he says. . Two out of three scanned sites have one or more cross-site scripting (XSS) flaws, which take advantage of problems with sites' programming and are increasingly used in phishing attacks. A recent eBay scam used a now-fixed XSS hole on the auction site to direct anyone who clicked on a phony car auction to a phishing site. The link for this article located at NetworkWorld is no longer available. . Two out of three scanned sites have one or more cross-site scripting (XSS) flaws, which take advanta. eight, sites, contain, common, flaws, allow, attackers, steal, customer. . LinuxSecurity.com Team

Calendar%202 Apr 23, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Recognizing Flash-Based Phishing Risks Targeting PayPal Users

We've now seen several phishing web sites that are using flash-based content instead of normal HTML. Probably the main to reason to do this is to try to avoid phishing toolbars that analyze page content. Two recent examples, both targeting PayPal: and . . These sites look like the real PayPal front page, but they are actually Flash recreations. The link for this article located at F-Secure is no longer available. . These sites look like the real PayPal front page, but they are actually Flash recreations. The link . we've, phishing, sites, using, flash-based, content, instead, normal. . LinuxSecurity.com Team

Calendar%202 Jan 07, 2007 User Avatar LinuxSecurity.com Team Privacy
77

Exploring Cookie Security Threats and Misconfigurations

Within one week's time, we stumbled across two different sites using cookies the wrong way. While the attack vectors were a bit different, both sites trusted the cookie data to secure their users. Let's break this cookie down so we can understand its intent. First, you can easily tell who the cookie belongs to . Unpack prevalent cookie setup issues and discover methods to manage cookie information securely for enhanced safeguarding.. Web Cookies, Secure Data Handling, Cookie Best Practices, Cybersecurity Risks. . LinuxSecurity.com Team

Calendar%202 Dec 18, 2006 User Avatar LinuxSecurity.com Team Server Security
79

Exploring PHP Honeypot Techniques for Cyber Threat Engagement

PHP HoP is an open source project for: * Application-based low-level interaction honeypot * Dealing with web threats PHP HoP has already been used to : * Fool different kind of web attackers (audit tools, manual hax0rs...) * Create real statistics about the first top10 commands used by an intruder . * Steal malware (PHP, C, Perl) that attackers wanted to upload * Identify evil behaviours and learn about current web threats . The link for this article located at PHP.Hop is no longer available. . The link for this article located at PHP.Hop is no longer available. . source, project, application-based, low-level, interaction, honeypot, dealing. . LinuxSecurity.com Team

Calendar%202 Apr 25, 2006 User Avatar LinuxSecurity.com Team Security Projects
77

Understanding Domain Hijacking and Its Impact on Organizations

Malicious hackers who are able to hijack an organization's Web domain may be able to steal traffic from the legitimate Web site long after the domain has been restored to its owner, according to a recent report.Design flaws in the way Web browsers and proxy servers store data about Web sites allow malicious hackers to continue directing Web surfers to malicious Web pages for days or even months after the initial domain hijacking. . The persistent attack could lead to information or identity theft, according to Amit Klein, a Web application security researcher with the Web Application Security Consortium. The link for this article located at EWeek is no longer available. . Domain takeovers pose significant risks for companies, given that perpetrators can reroute traffic even post-restoration.. Domain Hijacking, Long-Term Threats, Security Risks. . LinuxSecurity.com Team

Calendar%202 Feb 09, 2006 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200