Security News

Sudo Bug Opens Root Access on Linux Systems
2019-10-15 15:55

The bug allows users to bypass privilege restrictions to execute commands as root.

Sudo? More like Su-doh: There's a fun bug that gives restricted sudoers root access (if your config is non-standard)
2019-10-14 21:14

All it takes is -u#-1 ... Wh%& t#e fsck*? It's only Monday, and we already have a contender for the bug of the week.…

Sudo Flaw Lets Linux Users Run Commands As Root Even When They're Restricted
2019-10-14 18:34

Attention Linux Users! A vulnerability has been discovered in Sudo—one of the most important, powerful, and commonly used utilities that comes as a core command installed on almost every UNIX and...

I Have a New Book: We Have Root
2019-10-11 19:34

I just published my third collection of essays: We Have Root. This book covers essays from 2013 to 2017. (The first two are Schneier on Security and Carry On.) There is nothing in this book is...

Four words from Cisco to strike fear into the most hardened techies: Guest account as root
2019-09-26 12:44

Now is a very good time to patch your estate Cisco has doled out yet more security updates for its IOS and IOS XE network operating systems, which, we are obliged to remind you, is its scheduled...

Exim Vulnerability Allows Remote Code Execution as Root
2019-09-06 14:16

Exim mail servers are vulnerable to attacks due to a security hole that allows a local or remote attacker to execute arbitrary code with root privileges. read more

Exim TLS Flaw Opens Email Servers to Remote 'Root' Code Execution Attacks
2019-09-06 13:04

A critical remote code execution vulnerability has been discovered in the popular open-source Exim email server software, leaving at least over half a million email servers vulnerable to remote...

Exim marks the spot… of remote code execution: Patch due out today for 'give me root' flaw in mail server
2019-09-06 10:00

Install incoming update to avoid having your boxes hijacked The widely used Exim email server software is due to be patched today to close a critical security flaw that can be exploited to...

Google and Mozilla Block Kazakhstan’s Root CA Certificates to Prevent Spying
2019-08-21 11:03

In a move to protect its users based in Kazakhstan from government surveillance, Google and Mozilla finally today came forward and blocked Kazakhstan's government-issued root CA certificate within...

How to change a root password in a Docker image
2019-08-13 18:30

If you deploy Docker containers based on an official imagine, you might want to set a root password for heightened security.