LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Security Week: October 9th, 2017
Linux Advisory Watch: October 6th, 2017
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Accenture left a huge trove of highly sensitive data on exposed servers  10 October 2017 
Source: ZDNet Security - Posted by Alex   
Hacks/Cracks Technology and cloud giant Accenture has confirmed it inadvertently left a massive store of private data across four unsecured cloud servers, exposing highly sensitive passwords and secret decryption keys that could have inflicted considerable damage on the company and its customers.
 
SELinux blocks loading kernel modules  10 October 2017 
Source: Dan Walsh - Posted by Alex   
SELinux The kernel has a feature where it will load certain kernel modules for a process, when certain syscalls are made. For example, loading a kernel module when a process attempts to create a different network socket.
 
Linux Security Week: October 9th, 2017  09 October 2017 
Source: LinuxSecurity Contributors - Posted by Anthony Pell   
Linux Security Week Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.
 
VPN logs helped unmask alleged 'net stalker, say feds  09 October 2017 
Source: The Register UK - Posted by Alex   
Privacy Virtual private network provider PureVPN helped the FBI track down an Internet stalker, by combing its logs to reveal his IP address.
 
Mozilla pilots Cliqz engine in Firefox to slurp user browsing data  09 October 2017 
Source: ZDNet Security - Posted by Alex   
Privacy Mozilla has launched a pilot program using Cliqz technology to pull user browsing data in Firefox.
 
Cyber security as big a challenge as counter-terrorism, says spy chief  09 October 2017 
Source: ZDNet Security - Posted by Dave Wreski   
Latest News Defending against cyber-attacks is as big a challenge for the UK as protecting against terrorism, according to the director of GCHQ.
 
Linux Advisory Watch: October 6th, 2017  06 October 2017 
Source: LinuxSecurity Contributors - Posted by Anthony Pell   
Linux Advisory Watch Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.
 
On encryption, the UK sets a collision course with Europe  06 October 2017 
Source: ZDNet Security - Posted by Anthony Pell   
Cryptography Is encryption a threat to law and order, or an essential tool for staying secure online? Two events this week show how much disagreement there still is about it.
 
Severe flaws in DNS app create hacking risk for routers, smartphones, computers, IoT  06 October 2017 
Source: CSO Online - Posted by Alex   
Hacks/Cracks Google researchers disclosed seven serious flaws in an open-source DNS software package Dnsmasq, which is is commonly preinstalled on routers, servers, smartphones, IoT devices and operating systems such the Linux distributions Ubuntu and Debian. The most severe of the vulnerabilities could be remotely exploited to run malicious code and hijack the device.
 
Another W3C API exposing users to browser snitching  06 October 2017 
Source: The Register UK - Posted by Alex   
Hacks/Cracks Yet another W3C API can be turned against the user, privacy boffin Lukasz Olejnik has warned – this time, it's in how browsers store and check credit card data.
 
Step aside, Windows! Open source and Linux are IT’s new security headache  06 October 2017 
Source: ComputerWorld - Posted by Alex   
Latest News Windows has long been the world’s biggest malware draw, exploited for decades by attackers. It continues today: The Carbon Black security firm analyzed 1,000 ransomware samples over the last six months and found that nearly 99% of them targeted Windows.
 
The Flusihoc Dynasty, A Long Standing DDoS Botnet  05 October 2017 
Source: Arbor Networks - Posted by Alex   
Intrusion Detection Since 2015, ASERT has observed and followed a DDoS Botnet named Flusihoc. To date very little has been published about this family, despite numerous anti-virus and intrusion detection signatures created by various vendors. Flusihoc has remained persistent with multiple variants, over 500 unique samples in our malware zoo, and continued development.
 
Password leak puts online radio stations at risk of hijack  05 October 2017 
Source: ZDNet Security - Posted by Alex   
Hacks/Cracks A password leak vulnerability in a popular broadcast platform could allow hackers to hijack online radio stations. The security flaw allows anyone to reveal the plaintext admin account and password for almost any radio station hosted on SoniXCast, a New York-based online broadcast site, boasting over 50,000 terrestrial and internet radio stations on its network.
 
Keybase launches encryption for git repositories  05 October 2017 
Posted by Dave Wreski   
Cryptography Keybase has launched a new service to encrypt git repositories for free. Keybase, the provider of the Keybase security app for mobile phones and PCs, offers an open-source system supported by public-key cryptography to implement end-to-end encryption across your devices and communication.
 
    
Partner

 

Latest Features
Social Engineering Methods for Penetration Testing
Putting Infosec Principles into Practice
Installing an Apache Web Server with TLS
Essential tools for hardening and securing Unix based Environments
Securing a Linux Web Server
Peter Smith Releases Linux Network Security Online
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Sponsor:

 

Yesterday's Edition
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2017 Guardian Digital, Inc. All rights reserved.