Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 7 articles for you...
79

Janssen Project: New Cloud-Native Identity Management From Linux Foundation

The Linux Foundation has announced a new, secure cloud-native identity and access management software platform - the Janssen Project . . Every time we use an online pay service, manage our finances online, or enter our credit-card information, we're demonstrating our good faith. Now, one organization wants to help us feel even more secure. Today (Dec. 8), the Linux Foundation announced a cloud-native identity and access management software platform that prioritizes security and performance, the Janssen Project, which is based on the Gluu server and features signing and encryption functionalities. The integrity of our connections online is conveyed via identity software, from our devices to a complex web of backend services. Despite assurances and encouragement on this use, which we grow increasingly dependent on, digital identity remains a challenge and is at the very crux of delivering truly trustworthy online security. . Protect your digital exchanges using the innovative cloud-based identity verification system developed by the Linux Foundation.. Cloud-Native Identity Management, Security Solutions, Open Source Software. . LinuxSecurity.com Team

Calendar 2 Dec 09, 2020 User Avatar LinuxSecurity.com Team Security Projects
76

Key Cyber Defense Insights: Lessons From Successful Organizations

Most organizations are very bad at computer security. They don't patch well, and they have short, simple passwords that don't expire. They have dozens to hundreds of people in elevated groups. They don't have a clue who has which permissions in their environment. . Their networks are flat and often wide open to hundreds of contractors, business partners, and vendors. Defenses aren't appropriately prioritized, and they try and fail to accomplish dozens of projects at the same time. My average security audit findings report is well over 100 pages long and often contains dozens and dozens of critical findings. The link for this article located at InfoWorld is no longer available. . Companies face challenges in cybersecurity; insights on software updates, password management, and user permissions can foster enhancements.. Computer Security Best Practices, Cyber Defense Strategies, Access Management Insights. . Alex

Calendar 2 Jun 04, 2014 User Avatar Alex Organizations/Events
82

Understanding NSA Two-Man Controls for Sysadmin Security

In an effort to lock the barn door after the horse has escaped, the NSA is implementing two-man control for sysadmins: NSA chief Keith Alexander said his agency had implemented a "two-man rule," under which any system administrator like Snowden could only access or move key information with another administrator present. With some 15,000 sites to fix, Alexander said, it would take time to spread across the whole agency. . The link for this article located at Schneier on Security is no longer available. . The NSA's two-person control strategy enhances security protocols by requiring dual authorization for critical tasks, reducing insider threats and ensuring accountability.. Two-Man Control, NSA Security Measures, Sysadmin Access Management, Security Strategies. . Dave Wreski

Calendar 2 Jul 24, 2013 User Avatar Dave Wreski Government
81

Managing Privileged Access for Data Security and Compliance

While most attention today is placed on containing complex malware and outside hacking threats, enterprises could significantly improve their risk posture by taking a look at how well they manage the access they give privileged insiders, such as network and database administrators and other IT professionals. What most organizations find is that they don't have a firm enough grip on the access these users have.. To keep sensitive information safe and to maintain regulatory compliance, it's crucial that privileged insider access be properly managed. The link for this article located at CSO Online is no longer available. . To keep sensitive information safe and to maintain regulatory compliance, it's crucial that privileg. while, attention, today, placed, containing, complex, malware, outside, hacking, threats. . LinuxSecurity.com Team

Calendar 2 Dec 23, 2011 User Avatar LinuxSecurity.com Team Privacy
77

DenyHosts: Protect SSH Access From Repeated Attacks and Intrusions

DenyHosts is a tool that observes login attempts to SSH, and if it finds failed login attempts again and again from the same IP address, DenyHosts blocks further login attempts from that IP address by putting it into /etc/hosts.deny. DenyHosts can be run by cron or as a daemon. . From the DenyHosts web site: "DenyHosts is a script intended to be run by Linux system administrators to help thwart ssh server attacks. If you've ever looked at your ssh log (/var/log/secure on Redhat, /var/log/auth.log on Mandrake, etc...) you may be alarmed to see how many hackers attempted to gain access to your server. Hopefully, none of them were successful (but then again, how would you know?). Wouldn't it be better to automatically prevent that attacker from continuing to gain entry into your system? DenyHosts attempts to address the above... " This tutorial is based on a Debian Sarge system, however, it should apply to other distributions with almost no modifications. I want to say first that this is not the only way of setting up such a system. There are many ways of achieving this goal but this is the way I take. I do not issue any guarantee that this will work for you! The link for this article located at HOWTO Forge is no longer available. . Fail2ban mitigates incessant SSH login attempts, reinforcing security measures by disabling dubious IP addresses.. DenyHosts, SSH Security, Dictionary Attack Prevention. . LinuxSecurity.com Team

Calendar 2 Feb 20, 2006 User Avatar LinuxSecurity.com Team Server Security
77

Achieving SOX Compliance on UNIX/Linux Systems Through IAM Solutions

his document addresses how an organization can use identity and access management solutions (IAM) such as Symark's PowerBroker and PowerPassword-UME for UNIX and Linux operating systems to meet Sarbanes-Oxley (SOX) requirements for effectiveness of internal controls for financial reporting requirements. Symark PowerBroker and PowerPassword-UME safely delegate administrative privileges (including root) and provide secure logins and strong password and user management policies, keystroke logging and indelible audit trails. This document demonstrates how Symark PowerPassword-UME and PowerBroker work in tandem to protect the integrity of data across heterogeneous UNIX/Linux systems to help bring your IT systems into compliance especially with the SOX section 404 requirements for internal IT controls. . The link for this article located at BitPipe.com is no longer available. . IAM solutions are vital for Linux networks to comply with the Sarbanes-Oxley Act, ensuring secure access, robust audit trails, and role-based controls. IAM Solutions, UNIX Compliance, Sarbanes-Oxley Act, Data Integrity. . LinuxSecurity.com Team

Calendar 2 Feb 03, 2006 User Avatar LinuxSecurity.com Team Server Security
74

Gartner: Future of Cloud Security Emphasizes Access Management

The network security forecast is cloudy, and that's not a bad thing if you're to believe what analysts are saying at this week's Gartner IT Security Summit. Gartner predicts that by 2008, carriers like AT&T, Verizon, MCI and others will operationalize security functions like firewalls and intrusion detection into routers and switches, leaving enterprises to concentrate on identity and access management and other security duties away from the perimeter. By extending security to the Internet cloud, denial-of-service attacks, for example, never reach the gateway. . "We would take what an MSSP does and mesh that with our infrastructure so that the service provider and carrier becomes one," said AT&T CISO Ed Amoroso. CISOs, meanwhile, will still have network responsibilities like setting policy and aligning policy with an enterprise business model. They'll be alleviated of costly signature updates and license renewals. "Carriers and ISPs will provides these services for you," Gartner research director John Pescatore said. While this boils down to essentially outsourcing these services to carriers, enterprises may be skeptical about doing so until auditors are satisfied. The link for this article located at SearchSecurity is no longer available. . Experts forecast a shift towards cloud-driven security solutions by 2025, emphasizing user authentication and permissions oversight.. Cloud Security, Network Services, Security Outsourcing, Access Management, IT Infrastructure. . Brittany Day

Calendar 2 Jun 07, 2005 User Avatar Brittany Day Network Security
77

Best Practices For Terminating A Systems Administrator Securely

Perhaps one of the most challenging situations in an IT organisation is to let a systems administrator go. This individual has the proverbial keys to the kingdom as a trusted member of your corporate team. If the time comes to part . . . . Perhaps one of the most challenging situations in an IT organisation is to let a systems administrator go. This individual has the proverbial keys to the kingdom as a trusted member of your corporate team. If the time comes to part ways, it's imperative to do a thorough job of removing the employee's physical and logical access to your network and facilities. The first step is to consult with the appropriate legal, human resources and management personnel to ensure a proper basis for the termination or to work out the severance specifics for the layoff. Next you can zero in on the technical and security issues that need to be addressed. The goal is to complete the process with little or no disruption of business processes and to do it in a professional and complete manner. You need to eliminate the employee's access to corporate sites and assets, networks, systems and applications to prevent him from damaging company property and data. Accomplishing this requires inventory, planning, execution and monitoring. What follows are some guidelines for completing the four-step process. . Managing the intricate procedure of dismissing a network engineer while safeguarding data integrity and maintaining functional stability.. employeeTermination, accessManagement, ITSecurity. . LinuxSecurity.com Team

Calendar 2 Dec 22, 2003 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here