<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:webfeeds="http://webfeeds.org/rss/1.0" version="2.0">
  <channel>
    <title>LinuxSecurity - Security Articles</title>
    <link>https://linuxsecurity.com/</link>
    <description>The central voice for Linux and Open Source security news.</description>
    <language>en-us</language>
    <copyright>1999-2026 Guardian Digital, Inc. All rights reserved</copyright>
    <managingEditor>dave@linuxsecurity.com (Dave Wreski)</managingEditor>
    <pubDate>Fri, 04 Sep 2026 20:11:30 +0000</pubDate>
    <lastBuildDate>Fri, 04 Sep 2026 20:11:30 +0000</lastBuildDate>
    <generator>generate_indexes-linuxsecurity-v451-validation-scope-fix.php</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <atom:link href="https://linuxsecurity.com/static-content/linuxsecurity_articles.xml" rel="self" type="application/rss+xml" />
    <ttl>20</ttl>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-trends/exploring-ai-integration-in-business-operations</guid>
      <link>https://linuxsecurity.com/news/security-trends/exploring-ai-integration-in-business-operations</link>
      <title>AI Integration: Enhancing Business Automation and Cybersecurity Solutions</title>
      <description>Artificial Intelligence in business is slowly becoming the norm and necessary in the competitive struggle. Today, it is a powerful tool for developing companies, solving business problems, performing deep analytics, and automating processes. </description>
      <pubDate>Sat, 17 Aug 2024 18:05:34 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-trends</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/why-tails-os-is-changing-linux-security-updates</guid>
      <link>https://linuxsecurity.com/news/why-tails-os-is-changing-linux-security-updates</link>
      <title>Why Tails OS Is Changing How a Linux Distro Ships Security Updates</title>
      <description>Tails OS is changing the speed of its entire Linux distribution because one of its most security-sensitive applications is tied to the system image. Tails 7.12 is the first release on a new two-week cadence, following Firefox and Tor Browser.</description>
      <pubDate>Thu, 03 Sep 2026 22:20:02 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>news</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-security-roundup-september-3-2026</guid>
      <link>https://linuxsecurity.com/features/linux-security-roundup-september-3-2026</link>
      <title>Linux Security Roundup: Remote Access, PostgreSQL, and Sandbox Fixes to Prioritize Now</title>
      <description>The Linux security news from August 27 through September 3 brought serious fixes for remote access software, PostgreSQL, sandboxing tools, local system services, and software that processes untrusted files.</description>
      <pubDate>Thu, 03 Sep 2026 22:00:24 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/hackscracks/kestra-vulnerability-linux-container-rce</guid>
      <link>https://linuxsecurity.com/news/hackscracks/kestra-vulnerability-linux-container-rce</link>
      <title>CISA Flags Exploited Kestra Flaw That Lets Attackers Run Commands in Linux Containers</title>
      <description>A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026, turning an already serious authentication bypass into a current incident-response concern.</description>
      <pubDate>Thu, 03 Sep 2026 21:25:59 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>hackscracks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ai-linux-kernel-vulnerabilities-exploit-chains</guid>
      <link>https://linuxsecurity.com/features/ai-linux-kernel-vulnerabilities-exploit-chains</link>
      <title>AI Is Learning to Turn Linux Kernel Vulnerabilities Into Exploit Chains</title>
      <description>A kernel crash tells defenders that something went wrong. It does not show whether an attacker can turn that failure into a useful capability, combine several capabilities, and reach a security goal. That gap is one of the hardest parts of Linux kernel exploit development.</description>
      <pubDate>Thu, 03 Sep 2026 21:20:41 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/virtualizor-bgp-hijack-malicious-linux-updates</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/virtualizor-bgp-hijack-malicious-linux-updates</link>
      <title>Internet Routing Attack Sent Malicious Updates to Linux Servers</title>
      <description>Virtualizor has confirmed that a BGP hijack redirected traffic for part of its update infrastructure and allowed an attacker-controlled server to deliver a malicious update package to a small number of installations. The company disclosed the incident on August 31, 2026, after the routing diversion ran across two periods between August 28 and August 30.</description>
      <pubDate>Thu, 03 Sep 2026 13:06:36 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-logging-bottleneck-bind9-intrusion-prevention</guid>
      <link>https://linuxsecurity.com/features/linux-logging-bottleneck-bind9-intrusion-prevention</link>
      <title>Why DNS Attacks Can Outrun Linux Security Monitoring</title>
      <description>A Linux host intrusion prevention system can fail even when the protected server still has spare CPU. If its logging path cannot record and move events as quickly as an attacker creates them, the control loses the evidence it needs to block the source.</description>
      <pubDate>Thu, 03 Sep 2026 13:00:17 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/linux-kernel-llc-state-machine-out-of-bounds-read</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/linux-kernel-llc-state-machine-out-of-bounds-read</link>
      <title>Linux Patch Addresses Network Code Bug That Reads Past Memory</title>
      <description>A Linux kernel patch series submitted on Sep 1, 2026, stops an out-of-service Logical Link Control socket from indexing below two connection-state tables. The bug produced Kernel Address Sanitizer and Undefined Behavior Sanitizer reports for a global out-of-bounds read.</description>
      <pubDate>Thu, 03 Sep 2026 12:52:35 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/continuous-linux-security</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/continuous-linux-security</link>
      <title>Continuous Linux Security: Why a Hardening Checklist Is Not Enough</title>
      <description>A Linux server can be carefully hardened before it reaches production and still become less secure over time. Hardening means reducing unnecessary services, accounts, permissions, and other ways into the system. That work matters, but it describes the server at one point in time. Six months later, a new application may be installed, a firewall port opened for troubleshooting, an administrator given sudo access to run commands with elevated privileges, or a software update may have changed a c...</description>
      <pubDate>Thu, 03 Sep 2026 12:39:58 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/linux-security-foundations-operations</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/linux-security-foundations-operations</link>
      <title>Linux Security Foundations &amp; Operations</title>
      <description>A sustainable Linux security program depends on more than individual hardening settings, scanners, and monitoring tools. Those controls matter, but they only remain useful when teams understand what they operate, define what secure behavior should look like, assign responsibility, and revisit their assumptions as systems change.</description>
      <pubDate>Tue, 18 Aug 2026 13:17:52 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/network-security/why-patched-servers-fail-pentest</guid>
      <link>https://linuxsecurity.com/news/network-security/why-patched-servers-fail-pentest</link>
      <title>Why Patched Linux Servers Still Fail a Penetration Test</title>
      <description>A patched Linux server can still fail a penetration test because patch status cannot show whether an attack path remains open.</description>
      <pubDate>Wed, 02 Sep 2026 23:55:50 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>network-security</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/prevent-dns-leak-secure-proxy-credentials</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/prevent-dns-leak-secure-proxy-credentials</link>
      <title>How to Prevent DNS Leaks and Secure Proxy Credentials on Linux Systems</title>
      <description>Using a proxy on Linux changes how web traffic reaches its destination, but it does not automatically protect every part of the connection. DNS requests may still leave through the system’s normal resolver, while proxy usernames and passwords can remain exposed in scripts or local files.</description>
      <pubDate>Wed, 02 Sep 2026 23:25:07 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/linux-crypto-api-sa2ul-stack-overflow-ipsec</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/linux-crypto-api-sa2ul-stack-overflow-ipsec</link>
      <title>Linux IPsec Bug Can Trigger a Stack Overflow on Some TI Hardware</title>
      <description>A version 2 Linux kernel patch posted on August 31 fixes a stack overflow in the SA2UL hardware crypto driver. The Kernel Address Sanitizer, or KASAN, detected a one-byte write past a local buffer while strongSwan’s charon-systemd process was configuring an IPsec transform.</description>
      <pubDate>Wed, 02 Sep 2026 04:30:21 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/rxrpc-linux-namespace-teardown-race</guid>
      <link>https://linuxsecurity.com/features/rxrpc-linux-namespace-teardown-race</link>
      <title>Linux Network Cleanup Bug Can Trigger a Kernel Use-After-Free</title>
      <description>RxRPC is a Linux kernel transport for remote procedure calls. A teardown race reported in August shows that its network namespace cleanup can still reach a peer after that peer has been freed. The failure was caught by the Kernel Address Sanitizer, or KASAN, during automated testing.</description>
      <pubDate>Wed, 02 Sep 2026 04:15:22 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/ebpf-security-landlock-policy-objects-linux-exec</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/ebpf-security-landlock-policy-objects-linux-exec</link>
      <title>New Linux Security Patch Could Lock Down Programs Before They Start</title>
      <description>A version 2 Linux kernel patch series posted on August 31 proposes a new eBPF security interface for applying Landlock policy during program execution. The 15-patch set introduces generic Linux Security Module policy objects, lets privileged BPF programs retain those objects in maps, and adds a helper that can apply a selected policy during exec processing.</description>
      <pubDate>Wed, 02 Sep 2026 02:15:19 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ebpf-security-research-attack-surface-gap</guid>
      <link>https://linuxsecurity.com/features/ebpf-security-research-attack-surface-gap</link>
      <title>Most Linux eBPF Security Studies Overlook eBPF’s Own Risks</title>
      <description>An eBPF security system can produce precise Linux telemetry while leaving a harder question unanswered: what happens if the eBPF layer itself is misconfigured, vulnerable, or trusted too broadly?</description>
      <pubDate>Mon, 31 Aug 2026 20:30:19 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/linux-cpu-hotplug-regmap-irq-use-after-free</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/linux-cpu-hotplug-regmap-irq-use-after-free</link>
      <title>Linux CPU Hotplug Bug Can Trigger a Kernel Use-After-Free</title>
      <description>Linux interrupt maintainer Thomas Gleixner traced a Kernel Address Sanitizer report to incomplete regmap IRQ cleanup on Aug 30, 2026. The crash appeared while Linux was taking a CPU offline, but the stale pointer was created earlier when a device’s interrupt setup failed.</description>
      <pubDate>Mon, 31 Aug 2026 20:12:07 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/linux-gpu-security-drm-fence-uaf-read</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/linux-gpu-security-drm-fence-uaf-read</link>
      <title>Linux GPU Bug Can Read Freed Kernel Memory Across Multiple Drivers</title>
      <description>Jonghyuk Kim submitted a Linux Direct Rendering Manager scheduler patch series on Aug 28, 2026 that targets a use-after-free read shared by several GPU drivers. The proposed change caches a fence’s timeline name while its scheduler is still alive.</description>
      <pubDate>Mon, 31 Aug 2026 20:00:12 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-proxy-servers</guid>
      <link>https://linuxsecurity.com/features/linux-proxy-servers</link>
      <title>Everything You Need to Know About Linux Proxy Servers (2026 Guide)</title>
      <description>A linux proxy server has been around for years, but in 2026, it’s become baseline infrastructure. Privacy demands are higher, compliance rules are stricter, and the hybrid cloud has blurred the edge of the network.</description>
      <pubDate>Thu, 27 Nov 2025 19:14:03 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-kernel-tracing-reader-trace-instance-lifetime</guid>
      <link>https://linuxsecurity.com/features/linux-kernel-tracing-reader-trace-instance-lifetime</link>
      <title>Linux Kernel 7.1-rc5 Tracing Reader Use-After-Free Bug Discovery</title>
      <description>Removing a Linux trace instance should end its lifetime. An open tracefs reader can currently keep using that instance after another task removes it, creating a kernel use-after-free path in the tracing subsystem.</description>
      <pubDate>Fri, 28 Aug 2026 19:15:53 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ebpf-security-state-aware-syscall-filtering</guid>
      <link>https://linuxsecurity.com/features/ebpf-security-state-aware-syscall-filtering</link>
      <title>eBPF Security Research Adds State-Aware Syscall Filtering</title>
      <description>A Linux service may need broad system-call access while it starts, then only a smaller set while it handles requests. A single policy loaded before startup often has to keep every required call available for the service's entire lifetime.</description>
      <pubDate>Fri, 28 Aug 2026 19:05:19 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/kubecap-linux-capabilities-kubernetes-workloads</guid>
      <link>https://linuxsecurity.com/features/kubecap-linux-capabilities-kubernetes-workloads</link>
      <title>KubeCap Finds Excess Linux Capabilities in Kubernetes Workloads</title>
      <description>A Kubernetes workload can run with more Linux capabilities than its code needs. When capability settings are missing or broad, that excess authority may remain invisible because the application still works.</description>
      <pubDate>Fri, 28 Aug 2026 19:45:46 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/linux-patching-best-practices</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/linux-patching-best-practices</link>
      <title>Linux Patching Best Practices: Designing a Patch Validation Workflow</title>
      <description>Patch work often gets declared finished at the package manager. The update installs, version inventory changes, the service restarts, and the ticket begins moving toward closed. That sequence is clean. Production rarely is.</description>
      <pubDate>Thu, 27 Aug 2026 20:35:55 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-security-roundup-august-27-2026</guid>
      <link>https://linuxsecurity.com/features/linux-security-roundup-august-27-2026</link>
      <title>Linux Kernel Vulnerability News: Linux Security Roundup</title>
      <description>Linux kernel vulnerability news dominated the security updates published from August 20 through August 27. Ubuntu, Debian, Fedora, Mageia, Oracle Linux, Rocky Linux, SUSE, and openSUSE released fixes for standard kernels, cloud kernels, real-time kernels, hardware-specific builds, and live-patch streams.</description>
      <pubDate>Thu, 27 Aug 2026 14:03:51 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>linuxsecurity-com-must-read-articles</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/apparmor-credential-update-linux-security-hooks</guid>
      <link>https://linuxsecurity.com/features/apparmor-credential-update-linux-security-hooks</link>
      <title>AppArmor Credential Fix Prevents In-Hook Use-After-Free Risk</title>
      <description>A Linux security hook should be able to check a task without invalidating the identity data that surrounding kernel code is still using. AppArmor broke that expectation when a policy update made the task's current label stale: code inside widely used hooks could replace the task's credentials before the caller had finished with them.</description>
      <pubDate>Thu, 27 Aug 2026 12:36:43 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/linux-nfs-client-rpc-pipefs-use-after-free</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/linux-nfs-client-rpc-pipefs-use-after-free</link>
      <title>NFS Client Cleanup Fix Removes Orphaned rpc_pipefs Files</title>
      <description>Linus Torvalds merged a Linux NFS client update on Aug 26, 2026, that includes a fix for rpc_pipefs files left attached to an RPC client after the client object was freed. Opening one of those leftover files could trigger a kernel use-after-free.</description>
      <pubDate>Thu, 27 Aug 2026 12:23:03 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/ipmi-security-rcu-grace-period</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/ipmi-security-rcu-grace-period</link>
      <title>IPMI Security Patch Restores a Lost Linux RCU Grace Period</title>
      <description>The Linux IPMI maintainer accepted a patch on Aug 26, 2026 that restores an RCU grace period before command-receiver objects are freed. The one-line change addresses a use-after-free condition in the kernel's Intelligent Platform Management Interface message handler.</description>
      <pubDate>Thu, 27 Aug 2026 07:10:59 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-uevent-leak-synaptics-rmi4</guid>
      <link>https://linuxsecurity.com/features/linux-uevent-leak-synaptics-rmi4</link>
      <title>Linux Uevent Leak Exposes Freed Memory in Synaptics RMI4</title>
      <description>A Linux uevent can carry bytes from freed kernel memory when one object survives longer than the allocation behind its name. A new Synaptics RMI4 patch demonstrates that path during device removal and a probe failure.</description>
      <pubDate>Thu, 27 Aug 2026 06:41:37 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/software-supply-chain-security-workflows</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/software-supply-chain-security-workflows</link>
      <title>Linux Software Supply Chain &amp; Security Workflows</title>
      <description>A Linux system can be hardened, monitored, and carefully administered while still receiving untrusted code through a package, dependency, container image, build runner, or deployment pipeline. The risk often begins before the software reaches the host.</description>
      <pubDate>Wed, 26 Aug 2026 15:44:38 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/incident-response-recovery</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/incident-response-recovery</link>
      <title>Linux Incident Response &amp; Recovery</title>
      <description>An alert suggests that a Linux server may be compromised. The first impulse is often to reboot it, stop a process, delete a suspicious file, or patch the visible weakness. During Linux incident response, those actions can erase the evidence needed to determine what happened and whether the attacker reached anything else.</description>
      <pubDate>Wed, 26 Aug 2026 15:38:26 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/hardening-architecture-isolation</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/hardening-architecture-isolation</link>
      <title>Linux Hardening, Architecture &amp; Isolation</title>
      <description>Linux hardening is not the act of enabling every restrictive setting a distribution provides. It is the work of reducing unnecessary exposure, limiting what users and processes can do, separating workloads, and confirming that those controls remain effective as the system changes.</description>
      <pubDate>Tue, 25 Aug 2026 13:47:39 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/visibility-logging-detection</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/visibility-logging-detection</link>
      <title>Linux Security Monitoring, Logging &amp; Detection</title>
      <description>Linux security monitoring is useful only when it helps a team explain what happened. Collecting more events does not automatically provide better visibility, especially when nobody knows which records matter, how long they should be retained, or what the evidence can actually prove.</description>
      <pubDate>Thu, 20 Aug 2026 15:32:19 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/identity-privilege-administrative-access</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/identity-privilege-administrative-access</link>
      <title>Linux Identity, Privilege &amp; Administrative Access</title>
      <description>Access to a Linux system involves several connected decisions. The system must determine who or what is requesting access, verify that identity, decide which resources it may use, and control whether it can gain additional privilege.</description>
      <pubDate>Wed, 19 Aug 2026 19:18:48 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/howtos/learn-tips-and-tricks/linux-security-howto</guid>
      <link>https://linuxsecurity.com/howtos/learn-tips-and-tricks/linux-security-howto</link>
      <title>LinuxSecurity HOWTO: The Modern Linux Security Operations Playbook</title>
      <description>Linux security problems rarely stay in one place. An authentication issue can lead to unexpected privilege. A container problem can reach the host. Missing logs can make it difficult to determine whether an incident is contained or still active.</description>
      <pubDate>Mon, 17 Aug 2026 14:03:59 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>howtos</category>
      <category>learn-tips-and-tricks</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-security-howto-start-here</guid>
      <link>https://linuxsecurity.com/features/linux-security-howto-start-here</link>
      <title>Why LinuxSecurity Is Rebuilding the Linux Security HOWTO</title>
      <description>Linux security no longer lives on one server.</description>
      <pubDate>Mon, 17 Aug 2026 13:58:52 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/linux-dm-integrity-writeback-checksum-mismatch</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/linux-dm-integrity-writeback-checksum-mismatch</link>
      <title>Linux dm-integrity Patch Targets Writeback Checksum Mismatches</title>
      <description>A Linux dm-integrity patch posted on Aug 24, 2026 targets a writeback race that can leave stored data with the wrong integrity tag after a crash. Chen Cheng proposed requiring stable writes when dm-integrity generates internal hashes in direct, bitmap, or inline mode.</description>
      <pubDate>Tue, 25 Aug 2026 22:30:55 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-rds-rdma-path-count-memory-corruption</guid>
      <link>https://linuxsecurity.com/features/linux-rds-rdma-path-count-memory-corruption</link>
      <title>Linux RDS Bug Lets an RDMA Peer Overrun Kernel Path Storage</title>
      <description>Linux RDS can accept a path count that is larger than the storage allocated for an InfiniBand connection. A peer on the same Remote Direct Memory Access, or RDMA, fabric can then make receive-side kernel code walk beyond that allocation, producing an out-of-bounds write and a system crash.</description>
      <pubDate>Tue, 25 Aug 2026 22:15:05 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/bpf-congestion-control-linux-tcp-use-after-free</guid>
      <link>https://linuxsecurity.com/features/bpf-congestion-control-linux-tcp-use-after-free</link>
      <title>BPF Congestion Control Exposed Two Linux TCP Use-After-Free Paths</title>
      <description>A Linux TCP query can touch congestion-control memory after a concurrent BPF update has freed it. Two new use-after-free reports show how an ordinary read path inherited a lifetime assumption that no longer holds when BPF makes congestion-control objects dynamically replaceable.</description>
      <pubDate>Mon, 24 Aug 2026 12:34:56 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/ebpf-security-link-update-cgroup-lsm-hooks</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/ebpf-security-link-update-cgroup-lsm-hooks</link>
      <title>eBPF Security Patch Expands Link Checks Across Cgroup and LSM Hooks</title>
      <description>A Linux BPF patch posted on August 21, 2026, expands validation for program replacement across cgroup and Linux Security Module hooks. Version 3 addresses cases where two programs share a broad type but expect different runtime contexts or return rules.</description>
      <pubDate>Mon, 24 Aug 2026 12:30:00 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-projects/linux-7-3-ima-policy-measurement-tpm-timing</guid>
      <link>https://linuxsecurity.com/news/security-projects/linux-7-3-ima-policy-measurement-tpm-timing</link>
      <title>Linux 7.3 Development Changes IMA Measured Boot Evidence and TPM Timing</title>
      <description>Code merged for the Linux 7.3 development cycle changes the measured boot evidence produced by the Integrity Measurement Architecture, or IMA. The kernel now records the raw policy rules that decide what the system measures, closing a gap that could leave remote verifiers without a complete picture of how the evidence was created.</description>
      <pubDate>Mon, 24 Aug 2026 12:22:53 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-projects</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/kata-containers-genpolicy-mount-source-vulnerability</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/kata-containers-genpolicy-mount-source-vulnerability</link>
      <title>Kata Containers Flaw Weakens Container Security With Host-Chosen Mounts</title>
      <description>A flaw in Kata Containers weakened container security in some Confidential Containers deployments. It allowed a malicious host operator to make the protected guest use attacker-chosen files or content at approved mount locations.</description>
      <pubDate>Fri, 21 Aug 2026 23:40:42 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/vendors-products/ad-blockers-for-linux-browsers</guid>
      <link>https://linuxsecurity.com/news/vendors-products/ad-blockers-for-linux-browsers</link>
      <title>Ad Blockers for Linux Browsers in 2026: Privacy, Performance, and Security Considerations</title>
      <description>A good ad blocker is one of those browser additions you stop noticing once it’s working. Pages settle down. Autoplay boxes disappear. News sites stop shifting under your cursor while three ad slots load. On a slower laptop, the difference can be surprisingly obvious. But “blocks ads” isn’t a useful buying criterion anymore. Plenty of extensions do that.</description>
      <pubDate>Thu, 20 Aug 2026 18:40:46 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>vendors-products</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/network-security/what-is-kali-linux</guid>
      <link>https://linuxsecurity.com/news/network-security/what-is-kali-linux</link>
      <title>What Is Kali Linux? How Security Professionals Use It</title>
      <description>A penetration tester can build a security workstation on almost any Linux distribution. The problem is the amount of setup that comes with it. Scanners, packet-analysis tools, web testing software, password-auditing utilities, and forensic packages all have to be installed and kept working together. Kali Linux does much of that work in advance. It is a Debian-based distribution built around penetration testing, security auditing, digital forensics, and related security work. That does not mak...</description>
      <pubDate>Tue, 04 Nov 2025 21:33:20 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>network-security</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/cloud-security/cloud-security-posture-management</guid>
      <link>https://linuxsecurity.com/news/cloud-security/cloud-security-posture-management</link>
      <title>Everything You Need to Know About Cloud Security Posture Management</title>
      <description>Many companies are transitioning from physical servers to cloud operations, but this transformation brings new challenges. Cloud Security Posture Management (CSPM) can help protect your data in this virtual realm.</description>
      <pubDate>Mon, 14 Oct 2024 15:00:43 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>cloud-security</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ebpf-security-beyond-kernel-verifier</guid>
      <link>https://linuxsecurity.com/features/ebpf-security-beyond-kernel-verifier</link>
      <title>eBPF Security Is Moving Beyond the Kernel Verifier</title>
      <description>eBPF security is often summarized in one sentence: Linux loads an eBPF program only after the kernel verifier accepts it under the safety checks the verifier performs. That description is useful, but it covers only one part of a larger system.</description>
      <pubDate>Sat, 22 Aug 2026 00:05:39 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/kvm-intel-tdx-enforcement-gap</guid>
      <link>https://linuxsecurity.com/features/kvm-intel-tdx-enforcement-gap</link>
      <title>KVM’s TDX Control-Plane Blind Spot: When “Enabled” Does Not Mean Enforced</title>
      <description>Recent KVM work exposed a gap between what Linux says a TDX protection supports and what the TDX-specific code actually enforces.</description>
      <pubDate>Fri, 21 Aug 2026 22:50:24 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/cryptography/shieldzfs-confidential-vm-storage-freshness</guid>
      <link>https://linuxsecurity.com/news/cryptography/shieldzfs-confidential-vm-storage-freshness</link>
      <title>Linux ShieldZFS Adds Freshness Proofs for Confidential Computing</title>
      <description>Confidential computing can protect sensitive workloads even when the cloud host cannot be fully trusted. Confidential virtual machines can shield memory and CPU state from the hypervisor. Disk encryption can also stop the host from reading stored data. But how does the virtual machine know the disk state it received is the newest?</description>
      <pubDate>Fri, 21 Aug 2026 17:32:53 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>cryptography</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/server-security/secure-remote-access-linux-servers</guid>
      <link>https://linuxsecurity.com/news/server-security/secure-remote-access-linux-servers</link>
      <title>Securing Remote Access to Linux Servers: Best Practices for 2026</title>
      <description>Linux runs the internet. More than 96% of the world’s top one million web servers operate on Linux-based systems. That makes every linux server a target by default. Attackers do not go where defenses are strongest; they go where the infrastructure is exposed.</description>
      <pubDate>Wed, 13 May 2026 13:11:26 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>server-security</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/network-security/xnet-xdp-traffic-sampling-ids-visibility</guid>
      <link>https://linuxsecurity.com/news/network-security/xnet-xdp-traffic-sampling-ids-visibility</link>
      <title>XNET Uses XDP Traffic Sampling to Preserve Suricata Visibility at 100 Gbps</title>
      <description>During a live academic-network deployment, the Linux traffic-sampling system cut the stream sent to the sensor by 78 to 84 percent. In a separate test, it preserved 99.6 percent of baseline Suricata alerts.</description>
      <pubDate>Thu, 20 Aug 2026 15:25:43 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>network-security</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/news/security-vulnerabilities/bpf-disassembler-out-of-bounds</guid>
      <link>https://linuxsecurity.com/news/security-vulnerabilities/bpf-disassembler-out-of-bounds</link>
      <title>Linux Kernel BPF Disassembler Out-of-Bounds Access Advisory Alert</title>
      <description>Linux kernel fuzzing service syzbot has reported an out-of-bounds array access in print_bpf_insn(), a routine used to turn BPF instructions into readable verifier output.</description>
      <pubDate>Thu, 20 Aug 2026 15:21:06 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>news</category>
      <category>security-vulnerabilities</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
  </channel>
</rss>
