Most break-ins on small servers use flaws that already had a fix available. Installing security updates automatically closes that gap without you having to remember.
Ubuntu and Debian: unattended-upgrades
It is installed by default on most Ubuntu servers. Make sure it is on:
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
Answer Yes. This applies security updates daily. Check what it has done:
sudo cat /var/log/unattended-upgrades/unattended-upgrades.log
Some updates, especially the kernel, only take effect after a reboot. When one is waiting, the file /var/run/reboot-required exists. To reboot automatically at a quiet time, set these in /etc/apt/apt.conf.d/50unattended-upgrades:
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
AlmaLinux, Rocky Linux and Fedora: dnf-automatic
sudo dnf install dnf-automatic
Edit /etc/dnf/automatic.conf and set:
[commands]
upgrade_type = security
apply_updates = yes
Then start the timer:
sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers | grep dnf
Check whether a reboot is needed with sudo dnf needs-restarting -r.
What it does not cover
- Software you installed outside the package manager, such as WordPress, its plugins, or apps from Git. Keep those updated separately.
- Major version upgrades of the operating system, which you should plan and test.
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

