Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
OpenSSF is excited to announce the Alpha-Omega Project to improve the security posture of open source software (OSS) through direct engagement of software security experts and automated security testing. Microsoft and Google are supporting the Alpha-Omega Project with an initial investment of $5 million. . Alan Shimel: Hey, everyone. Welcome to another segment for Techstrong TV. My guest today is Brian Behlendorf. Brian is with the Open Source Security Foundation – that’s the OSSF. The Open Source Security Foundation, of course, is part of the Linux Foundation and it was – it’s a relatively new organization. It was – was it announced at KubeCon – CNCFCon back in, I guess, September, was that, Brian? Brian Behlendorf: We announced kind of the second generation of the project in October. The project has been around for about a year longer than that – actually just over that as a collaboration between some things that Microsoft had started and Google had started. The Linux Foundation said, “Let’s put this in the same pod” and a tremendous community of volunteers stepped up to do all sorts of things and get plates spinning on top of poles. And then, around about October we realized, hey, there’s some places where spending some money would be helpful and here’s a whole bunch of companies willing to come in as sponsors and really fund some of that work. And so, that also freed me up to be able to focus full time on it as well. The link for this article located at Security Boulevard is no longer available. . The Open Source Security Foundation's Alpha-Omega Initiative is designed to bolster OSS protection through the involvement of specialists and thorough assessments.. OpenSSF, Open Source Security, Alpha-Omega Project, Software Security, Automated Testing. . Brittany Day
GitHub Enterprise Server, the self-hosted version of the code shack’s platform, has hit version 3.5. The company said there are over 60 new features, including Dependabot , a service which automatically updates the packages used by a repository. . The packages on which other packages depend are somewhat hidden from the developer, so that security issues or bugs can easily be missed. Dependabot can trigger alerts when a vulnerable dependency is discovered or checked in, and also has an option keep versions up to date automatically. GitHub acquired Dependabot in May 2019 and it has been part of the cloud hosted GitHub for some time, but arrived in public beta in Enterprise Server 3.4 three months ago. . Explore the latest 60 innovations in GitHub Enterprise Server 3.5, featuring improved safety measures with Dependabot.. GitHub Enterprise, Dependabot, Software Security, Package Management. . LinuxSecurity.com Team
Uptycs - a leader in cloud-native security analytics - is helping organizations close security observability gaps across attack surfaces with its Uptycs Security Analytics Platform. Learn how Uptycs is helping a SaaS-based payment processing solution vendor automate their risk analysis and reduction strategy. . As a fast-growing organization processing billions of dollars in transactions, risk reduction is of paramount importance to this payment processing solution vendor. Download our case study to learn how this SaaS based company used the Uptycs Security Analytics Platform to secure over 2,000 macOS workstations and 15,000 Ubuntu Linux servers on AWS . With Uptycs, the company was able to achieve: Security observability at scale Analyze behavioral changes or anomalies Detection-as-code automation The link for this article located at Uptycs is no longer available. . Explore how a payment gateway enhanced its fraud detection by integrating automation with Uptycs Security Insights on Linux systems.. Cloud Native Security, Payment Processor Security, Risk Analysis Automation, Threat Detection, Security Analytics. . LinuxSecurity.com Team
iScanner is free open source tool lets you detect and remove malicious codes and web pages viruses from your Linux/Unix server easily and automatically. This is a neat tool for those who have to do some clean up operation after a mass-exploitation or defacement on a shared web-host.. This tool is programmed by iSecur1ty using Ruby programming language and it The link for this article located at Darknet is no longer available. . Secure your Linux server by identifying and eliminating harmful scripts using iScanner, a robust open source solution designed for enhancing web security.. iScanner Tool, Malware Detection, Open Source Security, Linux Cleanup. . Anthony Pell
IBM and Cisco Systems have expanded a partnership to provide businesses with automated identity and access security to networks. . . .. The two companies announced Thursday that they have integrated IBM's Tivoli network management software with Cisco's networking products to help businesses protect their networks from worms and viruses before employees get on the network. The combined offering sets criteria for users and devices logging on to the network. IBM and Cisco first announced their partnership in February. When someone tries to log on to the network, IBM's Tivoli software scans the machine to ensure that it has all the required security patches, antivirus updates and other software running on it. The update is sent to Cisco's Access Control Server through the Cisco Trust Agent, software that is pre-installed on every user's machine. If the device connecting to the network complies with all the security policies that have been previously set, the person is allowed to log on. If it doesn't, the device is quarantined on a separate virtual LAN (local area network) link and the Tivoli software prompts the person to download the necessary software. . The two companies announced Thursday that they have integrated IBM's Tivoli network management softw. cisco, systems, expanded, partnership, provide, businesses, automated, identity. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.