Thank you for reading the LinuxSecurity.com weekly security newsletter.
The purpose of this document is to provide our readers with a quick
summary of each week's most relevant Linux security headlines.
|
|
|
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.
|
|
'Hacktivity 2010' tackles computer security (Sep 20) |
|
Caterpillars, roaches and worms crawl on a computer, which represents an infected computer, next to a clean one, in a display that illustrates computer safety at Hacktivity, in Budapest. The major hackers' conference wrapped up in Hungary Sunday after higlighting protection against increasingly sophisticated computer piracy as the Internet becomes ever more present in daily life.
|
|
(Sep 20) |
|
The denizens of 4chan launched a series of distributed denial of service attacks against entertainment industry websites over the weekend, protesting legal actions against torrent tracker website the Pirate Bay.
|
|
Hackers meet in 'geeks' paradise' (Sep 20) |
|
Away from the elegance of Budapest's historic centre, a dingy rock venue has been turned into a geek's paradise. The laptop screens glow in the dim light as fingers flicker quickly over keyboards. Lines of code, incomprehensible to all but the cognoscenti, are typed out.
|
|
Google Is Making Your Account Vastly More Secure With Two-Step Authentication (Sep 20) |
|
"Two-factor authentication" may be the least sexy-sounding feature I've ever written about. But if you've ever worried about being phished or having your password hacked, it could be your best friend -- because it makes it much, much harder for a hacker to break into your account.
|
|
(Sep 17) |
|
A vulnerability in the 32-bit compatibility mode of the current Linux kernel (and previous versions) for 64-bit systems can be exploited to escalate privileges. For instance, attackers can break into a system and exploit a hole in the web server to get complete root (also known as superuser) rights or permissions for a victim's system.
|
|
(Sep 17) |
|
From animated logos to Web videos for hip, independent bands, HTML5 is getting buzz and gaining traction. But concerns about the security of features in the new version of the Web's lingua franca persist.
|
|
Mozilla releases Thunderbird updates (Sep 17) |
|
One day after it released updates for its Firefox web browser, the Mozilla Project has issued versions 3.1.4 and 3.0.8 of Thunderbird, the latest stable and legacy branch updates of its popular open source email client. According to the developers, the latest maintenance updates improve the applications overall stability and address several user experience concerns found in the previous stable branch release.
|
|
Encryption patent battle could hit database security industry (Sep 17) |
|
Data security vendor Protegrity has added new names to a lengthening list of companies it wants to sue over alleged violation of its encryption patents.
|
|
(Sep 17) |
|
Murphy's Law states that: "Anything that can go wrong, will go wrong". It's often used to explain why a piece of toast will generally fall jelly-side down when dropped, but apply it to the field of computer security and you'll realize something much more profound: It implies that your network is bound to be vulnerable for the most trivial of reasons.
|
|
Novell breakup and sale imminent, says report (Sep 16) |
|
Commercial operating system maker Novell is close to selling itself off after breaking it into two bits, according to the is New York Post.
|
|
(Sep 16) |
|
Traditional IT security is buckling and breaking under increasingly sophisticated, high-quality malware attacks, says James Lyne, senior technologist at security firm Sophos.
|
|
Red Hat tops list of hottest IT security certifications (Sep 16) |
|
Interest in IT security certifications is booming, as more U.S. companies tighten up the protection surrounding their critical network infrastructure and as a growing number of employees view security expertise as recession proof.
|
|
Google Chrome 6 Gets Updated for 9 New Flaws (Sep 16) |
|
Google is updating its stable version of the Chrome browser for Linux, Mac, and Windows, fixing at least nine security vulnerabilities. Only one of the vulnerabilities in Chrome 6.0.472.59 is rated by Google as being "critical" -- the highest threat level Google assigns to vulnerabilities -- although six of the fixes carry a "high" rating, the next-most severe level.
|
|
Can privacy be saved? Maybe (Sep 15) |
|
Thanks to the explosion of social networking and all those nifty web apps people use to bank and shop online, the bad guys now have an endless supply of attack vectors to steal personal data. In fact, some security industry experts have declared privacy dead.
|
|
(Sep 15) |
|
A brazen new DDoS-as-a-service offering out of China operates in the open on the Web, adding 10,000 new infected machines as bots per day. Another DDoS botnet has been attacking Web servers worldwide for months at a major clothing retailer, as well as various banks, social networking sites, insurance, and government agencies. And political hacktivism remains alive and well as sites known to be critical of the Malaysian government currently are under a series of DDoS attacks.
|
|
Hacker breaks into ATMs for good, not evil (Sep 15) |
|
I'd just bought Barnaby Jack a pint of Harp when it hit me: Shouldn't he be buying my beer?Jack, as you might know, is the good-guy hacker who figured out a way to digitally hijack ATMs and command them to spit out $20 bills. Not that he would ever do that to buy a columnist a beer - or for any other reason, for that matter.
|
|
(Sep 15) |
|
A security startup will this week show publicly for the first time its proprietary replacement for SSL, as well as a cloud-based login application that helps block phishing attacks.
|
|
DHS Cybersecurity Watchdogs Miss Hundreds of Vulnerabilities on Their Own Network (Sep 15) |
|
The federal agency in charge of protecting other agencies from computer intruders was found riddled with hundreds of high-risk security holes on its own systems, according to the results of an audit released Wednesday.
|
|
NoMachine Ports OpenSSH to Windows (Sep 15) |
|
A final step towards removing Cygwin dependencies, new Win32 port of OpenSSH includes both client and server, implementing a majority of the functionalities found in the original code
|
|
(Sep 14) |
|
Having brought his open-source work and family to the United States from Finland some time ago, Linus Torvalds has marked an important personal milestone by attaining U.S. citizenship. Congratulations, Linus.
|
|
(Sep 14) |
|
Zeus Trojan kit - $3,000. SpyEye Trojan kit - $1,000. Bulletproof hosting - priceless, well not really.According to researchers with EMC's RSA security division, bulletproof hosting goes for between $87 to $179 per month depending on the service level and up to $400 per month for certain infrastructures.
|
|
(Sep 14) |
|
Security researchers are finding more and more malicious things lurking on the Google Code project repository.
|
|
(Sep 14) |
|
Security researchers have unpicked the business plan behind a botnet that serves as the backend for a DDoS-for-hire business.
|
|
Hackers Target and Exploit Pirate Bay Ad Server (Sep 14) |
|
The advertising server of The Pirate Bay has been hacked and exploited to spread viruses and trojans among users of the site. The hackers targeted a vulnerability in the site's software to offload the malicious files, causing sections of The Pirate Bay to be blocked by Google, Firefox and several virus scanners.
|
|
Mozilla starts dropping features from Firefox 4 (Sep 14) |
|
Mozilla, which launched the latest beta of Firefox 4 last week, has started to drop features from the still-under-construction browser.
|
|
Crypto weakness leaves online banking apps open to attack (Sep 14) |
|
Flaws in the way web applications handle encrypted session cookies might leave online banking accounts open to attack. The security risk stems from a cryptographic weakness in web applications developed using Microsoft's ASP.Net framework.
|
|
(Sep 13) |
|
The US-CERT warned Friday of a new mass-mailing worm that contains a link to what looks like a PDF file but instead is a malicious screensaver file that will interfere with security software on Windows-based computers and spread the message to everyone in the e-mail address book.
|
|
Why Security Matters to us All (Sep 13) |
|
Your website may not be as secure as you once thought... Most people take the Internet for granted. When it comes to the Internet as we know it
|