LinuxSecurity.com

Syndikovat obsah LinuxSecurity - Security Articles
The central voice for Linux and Open Source security news.
Aktualizace: 25 min 34 sek zpět

SPDX 3.0 Revolutionizes Software Management & Security

17 Duben, 2024 - 13:00
The SPDX 3.0 release marks a significant milestone in software management, particularly for Linux admins, infosec professionals, internet security enthusiasts, and sysadmins. The SPDX community, in collaboration with the Linux Foundation , has evolved the widely used Software Bill of Materials (SBOM) communication format with a comprehensive set of updates, introducing new features and enhancements tailored to modern system use cases.
Kategorie: Hacking & Security

xz-style Attacks Continue to Target Open-Source Maintainers

16 Duben, 2024 - 18:43
Open Source maintainers and developers have been warned about the continued wave of attacks aimed at project maintainers similar to those recently targeting the Linux xz data compression library, XZ Utils . Many believe the attempt to backdoor Linux's xz data compression library might not be an isolated incident. According to the OpenJS Foundation and Open Source Security Foundation (OpenSSF) , there has been a series of suspicious emails that appear targeted at a popular unnamed JavaScript project that the OpenJS Foundation hosts.
Kategorie: Hacking & Security

Protect Your Linux Web Apps and Meet Compliance Standards

16 Duben, 2024 - 00:13
Security is vital for your Linux web apps, but keeping up with the latest exploits and meeting compliance standards can quickly become overwhelming.
Kategorie: Hacking & Security

Threat Actors Are Actively Using Pupy RAT Malware to Attack Linux Systems

15 Duben, 2024 - 19:03
A resurgence of cyberattacks targeting Linux systems in Asian campaigns through the utilization of the Pupy Remote Access Trojan (RAT) has been observed. The malware's multifunctional nature is a notable characteristic, striking a chord with Linux admins, infosec professionals, internet security enthusiasts, and sysadmins who are likely familiar with the potential threat of versatile malware.
Kategorie: Hacking & Security

Ubuntu Linux 24.04 LTS Beta Released with Enhanced Security & Performance

15 Duben, 2024 - 14:23
Canonical has recently announced the Beta release of Ubuntu Linux 24.04 LTS , codenamed "Noble Numbat." This release aims to continue Ubuntu's legacy of incorporating cutting-edge open-source technologies into a user-friendly, high-quality distribution.
Kategorie: Hacking & Security

Severe X.Org Memory Safety, Code Execution Vulns Fixed [Updated]

15 Duben, 2024 - 13:00
After recent heap overflow, out-of-bounds write, and privilege escalation flaws brought X.Org into the spotlight, more severe memory safety, use-after-free, heap buffer overread, and code execution vulnerabilities have been identified in the popular X server. These issues affect the X.Org X11 server.
Kategorie: Hacking & Security

Growth in Open Source Use Among Businesses Analyzed

12 Duben, 2024 - 23:27
The open-source movement has come a long way, from its origins in the 1960s and 1970s to becoming an integral part of organizations worldwide. Recently, its adoption across various industries has increased significantly.
Kategorie: Hacking & Security

Rust-Based Edera: Locking Down Container Security Once and For All

12 Duben, 2024 - 14:50
The Rust-based Edera project demonstrates a unique approach to container security that addresses cloud-native computing challenges. Let's examine this new, innovative approach to container security, which could be a game-changer in the industry!
Kategorie: Hacking & Security

Strategies for Improving Linux Security Through Cross-Browser Compatibility Testing

10 Duben, 2024 - 23:44
In the dynamic landscape of web development , ensuring that applications perform uniformly across various web browsers is a vital aspect of user experience. This becomes increasingly important for Linux systems, where the default browsers and configurations range presents unique challenges. Cross-browser compatibility testing on Linux helps to identify and resolve these discrepancies, thereby enhancing the accessibility and functionality of web applications for all users.
Kategorie: Hacking & Security

Canonical launches Ubuntu Pro for IoT Devices

10 Duben, 2024 - 15:06
Canonical has launched Ubuntu Pro for Devices , a comprehensive offering emphasizing security and compliance for IoT device deployments. This initiative aims to provide 10 years of security maintenance for Ubuntu and thousands of open-source packages, along with device management capabilities through Landscape , a systems management tool by Canonical. Ubuntu Pro also ensures that IoT devices receive reliable security patches from a trusted source.
Kategorie: Hacking & Security

Native Spectre v2 Exploit Uncovered: Implications & Analysis for Linux Security Practitioners

10 Duben, 2024 - 13:00
The recently uncovered "Native Branch History Injection (BHI)" exploit against the Linux kernel marks a significant milestone in the ongoing battle against Spectre v2 vulnerabilities. Researchers have revealed that BHI can bypass existing Spectre v2/BHI mitigations to read sensitive data from the memory of Intel systems.
Kategorie: Hacking & Security

Linux vs. Windows: A Critical Look at Desktop Choices

9 Duben, 2024 - 21:10
There are compelling arguments in favor of Linux over Windows for desktop usage. Let's explore some advantages of choosing Linux over Windows for your desktop OS.
Kategorie: Hacking & Security

Canonical Makes Network Management Simpler and More Secure with Netplan 1.0

9 Duben, 2024 - 14:29
Canonical , the company behind Ubuntu , has introduced Netplan 1.0 , a network configuration tool that simplifies networking configuration on Linux systems. Netplan acts as a control layer above network stacks like systemd-networkd and NetworkManager, allowing administrators to manage and configure them easily.
Kategorie: Hacking & Security

Hacked VMs Reveal New Attack Risks

8 Duben, 2024 - 17:58
Researchers have exposed new and sophisticated types of attacks that endanger the security and confidentiality of virtual machines (VMs). Two variations of Ahoi attacks, Heckler and WeSee, have been identified targeting hardware-based trusted execution environments, specifically AMD's Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) and Intel's Trust Domain Extensions (TDX) technologies.
Kategorie: Hacking & Security

CoCo VMs Will Now Panic If RdRand Is Broken in Linux 6.9

8 Duben, 2024 - 14:33
A significant change has been merged into the x86 fixes for Linux 6.9, requiring the seeding of RNG (Random Number Generation) with RdRand for CoCo (Confidential Computing) environments. The change focuses on CoCo virtual machines , designed to be as isolated as possible, assuming the VM host is untrusted. RdRand is critical as a hardware random number generator instruction for entropy to guest VMs. Security expert and WireGuard developer Jason Donenfeld authored this change.
Kategorie: Hacking & Security

The XZ Utils Linux Backdoor: How It Happened & What We Can Learn

7 Duben, 2024 - 14:43
The alarming discovery of a backdoor in the xz data compression library , which had the potential to compromise Linux systems, has dominated recent security news. While the backdoor did not make its way into production Linux distributions, the incident raises crucial questions about open-source security and the need for vigilance in the face of emerging threats.
Kategorie: Hacking & Security

Latest Ubuntu Beta, Other Linux Distro Releases Delayed by xz-utils Vuln

5 Duben, 2024 - 19:00
The recent security issue with xz-utils has delayed the latest Ubuntu beta release and other major Linux distros. The delay follows the discovery of a critical vulnerability, CVE-2024-3094 , which has prompted developers to push back the release by a week to ensure the safety of the upcoming Ubuntu version, codenamed Noble Numbat.
Kategorie: Hacking & Security

German State Abandons Microsoft for Linux and LibreOffice

5 Duben, 2024 - 14:40
The German state, Schleswig-Holstein, has decided to move away from proprietary software, such as Windows and Office, to open-source alternatives , including Linux and LibreOffice . The move is motivated by the need to "ensure that their data is kept safe with us, and we must ensure that we are always in control of the IT solutions we use and that we can act independently as a state," as stated by Dirk Schr¶dter, the digitalization minister for Schleswig-Holstein.
Kategorie: Hacking & Security

Security Risks of Open-Source Software & Mitigations to Overcome Them

4 Duben, 2024 - 20:40
Open-source software, or OSS , has completely changed the technology sector by enabling developers anywhere to work together and produce creative solutions faster. However, security issues are a significant worry, just like in any digital environment. Therefore, you should take precautions to secure any open-source software you use.
Kategorie: Hacking & Security

New GitHub Actions Enhancements Boost Security & Power

3 Duben, 2024 - 14:45
Recent enhancements have been made to GitHub Actions , a feature of GitHub that enables automation and CI/CD processes for developer teams. The updates focus on boosting security and power for GitHub-hosted runners, virtual machines that execute workflows.
Kategorie: Hacking & Security