Linux security professionals spend most of their time on concrete problems. Hardening SSH. Configuring SELinux or AppArmor. Building secure CI/CD pipelines. Managing patches across server fleets. The work is technical, hands-on, and measurable.
...
Google's ChromeOS is a browser-based cloud powered operating system that holds the potential to be more secure than other traditional hard disk powered operating systems. According to research from security firm Whitehat, ChromeOS has its strengths, but it also has a few weaknesses too.
For months we've been reading about hacker groups like Lulz Security who reportedly have no agenda other than to create mayhem and laugh-snort at their own clever online exploits.
The copyright litigation factory known as Righthaven has been exposed as making what the Electronic Frontier Foundation said Monday were bogus claims to judges that it
In the Cabinet War Rooms in Whitehall, London - the bunker where Winston Churchill all but ran the UK's second world war operations - cybersecurity specialists summoned by antivirus firm Symantec today explained their views on defeating computer crime ahead of this week's Infosecurity conference in London.
The first-ever social engineering contest at DefCon in Las Vegas last year went way too well: each contestant was able to successfully social-engineer some piece of information, or "flag," out of their targeted company.
Although Chrome wasn't attacked directly at the contest, Google has released an update for the Windows, Linux and Mac OS X versions of its browser. The update closes a hole in WebKit that was originally exploited in Blackberry devices
The second day of the Pwn2Own competition, organised by the Zero Day Initiative (ZDI) team at security researchers TippingPoint, was devoted to iPhone and BlackBerry. Charlie Miller exploited a vulnerability in the mobile version of the Safari web browser on iOS 4.2.1 to delete the address book when a manipulative website was visited.
When the Pwn2Own contest began in 2007, it was dismissed by some in the industry as nothing more than a publicity stunt meant to inflate the egos of researchers while embarrassing software vendors. But as the fifth edition of the hacker challenge gets underway at the CanSecWest conference here this week, it has evolved into a display of some of the few things that are actually good and right with the security community.
Google's $20,000 was as safe at Pwn2Own Wednesday as if it had been in the bank. The search giant had promised to pay $20,000 to the first researcher who broke into Chrome on the hacking contest's opening day.
The annual Pwn2Own hacking challenge kicks off today, pitting security researchers against web browsers and mobile platforms. The HP TippingPoint sponsored event grows every year to include more platforms, though Linux isn't among them.
The Pwn2Own hacking contest next month will feature its largest-ever crew of contestants, including past winners, a French security firm armed with a bagful of bugs and an iPhone jailbreak expert who has been sued by Sony.
There are more than 450 expo vendors showing wares or hawking programs at the 20th annual RSA Conference now underway in San Francisco. In the weeks leading up to the conference talked with nearly 25 vendors about the announcements they are making today.
A major topic sure to be discussed at RSA Conference 2011 next week is cyber warfare -- specifically, whether or not we're really in the middle of one. Fueling the debate is Stuxnet, a piece of malware widely believed to be the creation of Israel and-or the U.S., designed to attack Iranian nuclear facilities.
The annual RSA Conference, now in its 20th year, will be rocking this month as the security industry gathers in the weeklong extravaganza of product introductions and security experts arguing cloud and mobile computing security issues.
Smartphone security has been a major focus at ShmooCon in the last couple years, with talks about flaws in BlackBerry and iPhone devices. This year, two researchers targeted all their firepower on the Android. Here's what they found.
A Black Hat Conference is nothing if not quirky as security geeks try every stunt possible to show what a clueless world we live in when it comes to security. Anyway, here are some such moments from this week's event: